# Zero trust

> A security model that trusts nothing by default — every request is verified by identity and context, even inside the network.

The old model was a castle: hard perimeter, soft interior, and anyone past the firewall was trusted. Zero trust drops the perimeter assumption — a request is judged by who is asking, from what device, for what resource, every time. 'Inside the network' stops being a permission.

In practice it is a direction rather than a product: identity-first access, least-privilege roles, segmented systems, continuous verification. For a small business it mostly means refusing the habits that assume trust — shared admin accounts, flat networks, VPN-equals-access — in favour of per-person, per-resource access.

## Related terms

- https://dfieldsolutions.com/en/glossary/least-privilege.md
- https://dfieldsolutions.com/en/glossary/mfa.md
- https://dfieldsolutions.com/en/glossary/threat-model.md

---

Source: https://dfieldsolutions.com/en/glossary/zero-trust
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
