The old model was a castle: hard perimeter, soft interior, and anyone past the firewall was trusted. Zero trust drops the perimeter assumption — a request is judged by who is asking, from what device, for what resource, every time. 'Inside the network' stops being a permission.
In practice it is a direction rather than a product: identity-first access, least-privilege roles, segmented systems, continuous verification. For a small business it mostly means refusing the habits that assume trust — shared admin accounts, flat networks, VPN-equals-access — in favour of per-person, per-resource access.
Related terms
Least privilege
Every user, service and process gets only the access the job requires — nothing more, so a compromise has a small blast radius.
MFA / 2FA
Multi-factor authentication — proving identity with something you know plus something you have, so a leaked password alone cannot log in.
Threat model
A written answer to who would attack this, what they would want, and what would actually stop them.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
