Zero Trust
A security model that assumes no user or device should be trusted by default, requiring continuous verification for every access request.
Definition
Zero trust is a security model built on the principle of never trust, always verify, meaning no user, device, or application is automatically trusted based on its location inside or outside the network. Every access request is continuously authenticated, authorized, and validated against policy before access to any resource is granted.
Traditional security models treated the corporate network as a trusted perimeter, so once a user or device was inside, it was largely trusted to move freely. Zero trust replaces this with continuous verification: every request to access an application or data, whether from an employee at head office or working remotely, is checked against identity, device health, and context each time, not just once at login. This typically combines strong identity verification, device compliance checks, and granular access policies that grant only the minimum access needed for a specific task.
Zero trust matters because modern work no longer happens inside a single office network, and a compromised credential or device should not automatically grant broad access simply because it is inside the corporate perimeter. For organizations in Indonesia adopting hybrid and remote work, along with cloud services accessed from many locations, zero trust reduces the blast radius of a single compromised account, since gaining one set of credentials no longer means unrestricted lateral movement. It is increasingly referenced in regulatory and industry guidance as a maturity benchmark for cybersecurity programs.
Implementing zero trust is a gradual journey rather than a single product purchase, typically starting with strong identity and multi-factor authentication, followed by micro-segmentation of networks and applications, and continuous monitoring of user and device behavior. Least privilege access is a foundational building block of zero trust, since verification is only meaningful if the access being granted is already scoped tightly. Organizations should prioritize their most sensitive systems and data first when phasing in zero trust controls, rather than attempting an all at once transformation.
At a glance
- Type
- Security model
- Also known as
- Never trust, always verify
How it works
- 1
Identity verification: every user and device is authenticated, not just trusted because it is on the network.
- 2
Continuous checks: each access request is validated against identity, device health, and context every time.
- 3
Micro-segmentation: networks and applications are divided so a compromised credential cannot move freely.
- 4
Least privilege access: only the minimum access needed for a specific task is granted.
- 5
Ongoing monitoring: user and device behavior is continuously observed for signs of compromise.
Key points
- No user, device, or application is automatically trusted based on network location
- It replaces the older idea of a trusted perimeter with continuous verification
- A compromised credential no longer grants unrestricted lateral movement
- Implementation is a gradual journey, not a single product purchase
- Least privilege is a foundational building block of zero trust
Best practices
- Start with strong identity verification and multi-factor authentication
- Add micro-segmentation of networks and applications over time
- Continuously monitor user and device behavior for anomalies
- Prioritize the most sensitive systems and data first when phasing in controls
- Pair zero trust with least privilege so verified access is also minimally scoped
Real-world example
A bank rolling out remote work adopts zero trust so that an employee working from home is verified on every request to the core banking application, not just once at login. When an employee's laptop is later stolen, the attacker cannot reuse an old session to reach sensitive systems, since each request is re-verified against device health and identity.
How Claro helps
Claro's human risk management approach complements zero trust by continuously assessing user-level risk, such as phishing susceptibility, information that can inform adaptive access policies alongside device and identity signals.
Frequently asked questions
What does never trust, always verify actually mean in practice?
It means no user, device, or application is trusted automatically just because it is inside the corporate network. Every access request is checked against identity, device health, and policy each time.
Is zero trust a single product an organization can buy?
No. It is a gradual approach typically starting with strong identity and MFA, followed by micro-segmentation and continuous monitoring, prioritized around the most sensitive systems first.
How does zero trust relate to least privilege?
Least privilege is a foundational building block of zero trust, since verification is only meaningful if the access being granted is already scoped tightly to what is needed.
Why is zero trust relevant to hybrid and remote work?
Modern work no longer happens inside a single office network, so zero trust reduces the blast radius of a compromised account by requiring continuous verification regardless of location.
Related terms
Least Privilege
The security principle of granting a user, account, or process only the minimum access needed to perform its function, and nothing more.
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Insider Threat
A security risk that originates from within an organization, such as an employee, contractor, or partner who misuses their legitimate access.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo