This is an example of a simple banner

What Vendors Won’t Tell You About Zero Trust

Zero Trust is not a product you install. It is a method you apply. Here is what vendors leave out of the pitch, and where a Swiss SME should actually begin.

Is your company ready for Zero Trust?

Five questions to locate your starting point, before opening any vendor catalogue.

1 / 5 — Is multi-factor authentication active for everyone?

Table of Contents

  1. The perimeter is gone, your VPN has not noticed
  2. Zero Trust: three principles, no product
  3. VPN or ZTNA: what really changes
  4. Where to start when IT is two people
  5. Five mistakes that derail the project
  6. What the Swiss context adds
  7. The skills that are missing most
  8. Conclusion
  9. FAQ

IT security team gathered around a wall of notes in a bright Swiss office

Search for “zero trust” and look at the results. The first ten belong to security vendors. Moreover, they all tell the same story: the traditional model is dead, their platform replaces it, a demo is waiting. That story is not wrong. However, it is incomplete, and the omission proves expensive.

Zero Trust cannot be bought. In fact, it is decided first, then built. Furthermore, it usually runs on tools you already own. On the ground, the hard part is rarely technical. It is almost always organisational. Consequently, here is the article no vendor will write, because it does not end with a purchase order.

The perimeter is gone, your VPN has not noticed

employee working remotely from a Swiss train with her laptop

For twenty years, security rested on one simple idea. There is an inside and an outside. Specifically, the firewall marks the border and the VPN acts as the drawbridge. After that, anything past the bridge counts as legitimate. Meanwhile, that model held only while data stayed in the server room.

That geography has disappeared. Your files live in Microsoft 365. Accounting runs on an application hosted in Ireland. Your sales team, in turn, connects from a train between Geneva and Zurich. In other words, the perimeter no longer separates anything. Therefore the right question changes: should this person reach this specific file, right now, from this device?

Swiss figures illustrate the shift. Indeed, in its 2026/1 semi-annual report, the Federal Office for Cybersecurity notes a rise in phishing reports tied to Microsoft 365. Attackers take over a corporate mailbox. Then they impersonate the IT helpdesk or a senior manager and trigger payments. As a result, no firewall stops the attack: the account is genuine, and the VPN waves it through.

Zero Trust: three principles, no product

identity verification with a badge at a glass office door

The term sounds intimidating. Nevertheless, it covers a blunt idea: trust nothing by default, not even what sits inside your walls. The reference remains NIST SP 800-207, published in 2020. It describes an architecture, not a product line. Three principles sum it up.

  • Verify explicitly. The system weighs every request against several signals: identity, device, location, sensitivity of the resource. Therefore yesterday’s successful login is not today’s authorisation.
  • Grant the minimum. People receive the rights their task requires, for the duration of that task. Consequently, the permanent admin account becomes the exception.
  • Assume compromise. You start from the assumption that an account has already fallen. The whole design therefore limits what an attacker reaches from that foothold.

Notice that none of these principles names a product. In practice, an SME running Microsoft 365 already owns most of the building blocks: multi-factor authentication, conditional access, device management. The work is to switch them on and configure them properly. Above all, someone must decide who gets access to what. No vendor will make that call for you.

It is worth stating what this approach does not do. It replaces neither your backups, nor your antivirus, nor staff awareness. Nor does it make phishing impossible. In contrast, it sharply reduces what an intruder obtains once inside. In other words, Zero Trust works on the consequences of a compromise rather than its likelihood. Ultimately, that nuance changes how you measure success: you stop counting blocked attacks and start measuring how far an intruder can travel.

VPN or ZTNA: what really changes

ZTNA, short for Zero Trust Network Access, is the component gradually replacing the corporate VPN. The difference fits in one sentence. Put simply, a VPN opens the network, whereas ZTNA opens a single application. The table below sums up the practical gaps.

CriterionTraditional VPNZTNA
Scope of accessThe whole internal networkOne specific application
When checks happenAt connection timeContinuously, on every request
Signals assessedUsername and passwordIdentity, device, context, risk
Lateral movementPossible once connectedStrongly contained
Visibility on usageLimitedLogging per application
User experienceManual login, latencySeamless when well configured

Beware of a common shortcut, though. Installing ZTNA does not make you Zero Trust. Do you still keep shared admin accounts, passwords without a second factor and rights piled up over ten years? You will simply have swapped one tunnel for another. In reality, the gain comes from the clean-up done beforehand, not from the technology layered on top.

Where to start when IT is two people

system administrators taking inventory of access in a server room

Vendor documentation describes eighteen-month programmes run by dedicated teams. In a hundred-seat company with two people in IT, that approach stays theoretical. Here is a realistic sequence instead, step by step. Each stage delivers a measurable benefit, even if the next one waits.

Step 1: regain control of identities

Start with multi-factor authentication for everyone, with no exception for the management team or for service accounts. Next, inventory privileged accounts. Indeed, most audits uncover admin rights still assigned to people who left long ago. This clean-up costs nothing but time, and it closes the most commonly used door.

Step 2: make access conditional on context

Once identities are in order, define conditional access rules. An unmanaged device does not reach sensitive data. Similarly, a login from a country where you have no operations triggers an extra check. Mind the catch, though: conditional access requires a Microsoft Entra ID P1 licence, included in Microsoft 365 Business Premium and E3 but absent from Business Basic and Standard. On the Google Workspace side, the equivalent comes with the higher editions. Moreover, these rules stay widely underused even by those who already own them.

Step 3: segment before replacing the VPN

Many teams want the VPN gone within the first few weeks. Take the time to identify your critical applications first, then isolate them from one another. In other words, microsegmentation comes before the big swap. As a result, you cut risk immediately, and moving to ZTNA becomes a formality.

How to pace the work without exhausting the team

A small team advances in quarterly steps. The first quarter absorbs multi-factor authentication and the account inventory. Conditional access follows, starting with a pilot group rather than the entire company. In the third quarter, you tackle segmentation of the most sensitive applications. This way, each step stays reversible if the business pushes back. Above all, budget time for internal communication: an access denial without explanation generates more tickets than an outage.

Five mistakes that derail the project

team meeting about mistakes in an IT security project

Zero Trust projects rarely fail on a technical flaw. In practice, they fail because a step was skipped. These are the ones that come up most often.

  • Buying before mapping. Without an inventory of applications and flows, you cannot know what to protect first. Consequently, the licence sits unused in a drawer.
  • Forgetting external partners. Accountants, IT providers, agencies, temporary staff: their access often escapes internal rules. Yet it remains a classic entry point.
  • Ignoring user experience. An overly rigid policy breeds workarounds. Staff then switch to personal email, and you lose all visibility.
  • Treating it as an IT project. Deciding who accesses what is a business call. Without arbitration from leadership, the IT team stalls.
  • Stopping at go-live. Rights drift and headcount changes. Without periodic reviews, the architecture quietly decays.

What the Swiss context adds

executives discussing cybersecurity in a Geneva office overlooking the lake

The Zero Trust debate reaches us from the United States, where federal requirements did much to popularise it. In Switzerland, however, two elements change the picture.

First, mandatory reporting. Since 1 April 2025, operators of critical infrastructure must report any cyberattack to the federal cybersecurity office within 24 hours of detection. Moreover, a fines regime has applied since October of that year. The obligation covers cantonal and municipal administrations, transport companies and energy suppliers. Yet reporting within 24 hours assumes you know what happened. An architecture that logs access per application answers that question. An opaque VPN does not.

Second, sheer volume. The federal office received 27,128 voluntary reports and 200 mandatory notifications in the first half of 2026. In addition, it recorded 79 ransomware cases over the same period. The threat therefore does not target large groups alone. It hits mid-sized organisations, often through one compromised mailbox. Our articles on protecting your business against ransomware and on the NIS2 directive round out the picture.

Data protection pushes the same way

Finally, the revised Swiss data protection act, known as the nFADP, points in the same direction. It requires you to know who accesses personal data and to document those activities. Yet a flat network, where every connected employee reaches every share, makes that demonstration impossible. Conversely, an architecture that grants the minimum and logs access produces the evidence naturally. Zero Trust therefore serves two goals at once: it limits the blast radius of an intrusion, and it documents your access for the regulator.

The skills that are missing most

A successful Zero Trust architecture rests on one specific profile. You need someone who can turn a business requirement into an access rule, then verify that the rule holds over time. This is neither a classic systems administrator nor a governance consultant. It is an architect. Unfortunately, that profile stays rare and hard to recruit.

Two areas therefore deserve a training investment. The first is design: modelling flows, defining an identity strategy, balancing security against usability. Daily operations form the second, namely access reviews and alert handling. The Microsoft SC-100 certification addresses the first area precisely, with an architecture approach that goes beyond tool configuration.

Microsoft Cybersecurity Architect SC-100 training

If your team starts further back, working through the fundamentals of IT security beats diving straight into architecture. In short, consolidate the basics before stacking concepts on a fragile base.

Conclusion

Zero Trust is not a checkbox, and certainly not a line on an invoice. Rather, it reframes an old question. Who accesses what, on what basis, and how do we verify it continuously? Companies that succeed begin with an inventory and with cleaning up identities. They do not begin with a tender.

In other words, clear the room before buying furniture. To begin with, enable multi-factor authentication everywhere. Then remove dormant rights. Finally, segment your critical applications. The first two cost nothing but time, and they already deliver most of the gain. Check your edition, however, before counting on conditional access. The rest follows naturally, including the VPN replacement.

FAQ

Does Zero Trust suit a 50-person company?
Yes, and often better than a large group. The application landscape is quicker to map, and access decisions are easier to make.

Must the VPN go for Zero Trust to work?
No. In practice, the VPN coexists well during the transition. Reduce what it exposes, then verify every application access.

How long does a realistic rollout take?
Expect six to twelve months for identities and conditional access in a mid-sized organisation. Network segmentation takes longer.

Does Zero Trust stop ransomware?
It does not prevent entry. However, it sharply limits spread, since one compromised account no longer opens the whole network.

Which certification suits this kind of project?
SC-100 covers security architecture, including Zero Trust strategy. It does assume prior experience with Microsoft 365 or Azure.

Facebook
Twitter
LinkedIn
Email
About the author

ITTA is the leader in IT training and project management solutions and services in French-speaking Switzerland.

Our latest posts

Subscribe to the newsletter

Confirmed training courses

Consult our confirmed trainings and sessions

MS-102T00
Intermédiaire
5
jours
Présentiel, Virtuel
Dès CHF 3'650.-
SC-300T00
Intermédiaire
4
jours
Présentiel, Virtuel
Dès CHF 3'000.-
SC-900T00
Fondamental
1
jour
Présentiel, Virtuel
Dès CHF 850.-
COM-203
Avancé
5
jours
Présentiel, Virtuel
Dès CHF 3'750.-

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday
8:30 AM to 6:00 PM
Tel. 058 307 73 00

Contact-us

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Make a request

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday, from 8:30 am to 06:00 pm.

Contact us

Your request