Security · 1 min · Jun 25, 2026

Practical zero trust for SMBs

Zero trust without the buzzwords - what to actually turn on, in what order, this quarter.

By franklin

Zero trust gets sold like a product. It is closer to a posture. Here is a practical, 90-day plan we run with mid-market clients.

Week 1-2: identity hygiene

  • MFA for everyone, including service accounts
  • Conditional access from compliant devices only
  • Privileged accounts move to PIM with just-in-time elevation

Week 3-4: device hardening

  • Encrypt every endpoint
  • Standard baseline via Intune or Jamf
  • Disable local admin by default

Week 5-8: segmentation and monitoring

  • Segment guest, IoT, BYOD, corporate, server traffic
  • EDR on every endpoint with central queue
  • Egress filtering and DNS protection

Week 9-12: prove it

  • Tabletop a credential-theft scenario
  • Restore a critical app from backup
  • Document the runbook the team actually uses
Nothing here is novel. Done in this order, it produces an environment most attackers will skip.