{"id":254705,"date":"2026-09-15T11:28:35","date_gmt":"2026-09-15T09:28:35","guid":{"rendered":"https:\/\/www.itta.net\/?p=254705"},"modified":"2026-09-16T17:42:56","modified_gmt":"2026-09-16T15:42:56","slug":"what-vendors-wont-tell-you-about-zero-trust","status":"publish","type":"post","link":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/","title":{"rendered":"What Vendors Won&#8217;t Tell You About Zero Trust"},"content":{"rendered":"<em>Zero Trust is not a product you install. It is a method you apply. Here is what vendors leave out of the pitch, and where a Swiss SME should actually begin.<\/em>\r\n\r\n    <div class=\"quiz-ia-box\" id=\"quiz-ia\" data-lang=\"en\" data-read-label=\"Read the dedicated section\" data-color=\"#00B0AE\" data-color-light=\"#e6f9f9\" style=\"background:linear-gradient(135deg,#f8fcfc 0%,#f0fafa 100%);border-radius:12px;padding:32px 36px;margin:32px 0;border-left:6px solid #00B0AE;font-family:Montserrat,Arial,sans-serif;\">\r\n\r\n        <p style=\"font-size:1.5vw;font-weight:700;color:#00B0AE;margin:0 0 6px;line-height:1.4;\">Is your company ready for Zero Trust?<\/p>\r\n                    <p style=\"font-size:15px;color:#555;margin:0 0 24px;\">Five questions to locate your starting point, before opening any vendor catalogue.<\/p>\r\n        \r\n                <div class=\"quiz-step\" data-step=\"1\" style=\"display:block;\">\r\n            <p style=\"font-size:16px;font-weight:700;color:#111;margin:0 0 14px;\">1 \/ 5 &mdash; Is multi-factor authentication active for everyone?<\/p>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q1\" value=\"2\" style=\"margin-right:10px;accent-color:#00B0AE;\">Yes, no exception, management included            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q1\" value=\"1\" style=\"margin-right:10px;accent-color:#00B0AE;\">Yes, except a few legacy accounts            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q1\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">Only for administrators            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:0;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q1\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">Not deployed yet            <\/label>\r\n            \r\n            <div class=\"quiz-nav\" style=\"display:flex;justify-content:flex-end;margin-top:16px;gap:8px;\">\r\n                                                    <button class=\"quiz-next\" data-next=\"2\" style=\"background:#00B0AE;color:#fff;border:none;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:opacity .15s;\">Next<\/button>\r\n                            <\/div>\r\n        <\/div>\r\n                <div class=\"quiz-step\" data-step=\"2\" style=\"display:none;\">\r\n            <p style=\"font-size:16px;font-weight:700;color:#111;margin:0 0 14px;\">2 \/ 5 &mdash; Do you know who holds admin rights today?<\/p>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q2\" value=\"2\" style=\"margin-right:10px;accent-color:#00B0AE;\">Yes, the list is maintained and reviewed            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q2\" value=\"1\" style=\"margin-right:10px;accent-color:#00B0AE;\">Yes, but it is several months old            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q2\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">Roughly, with nothing documented            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:0;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q2\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">No, nobody has taken inventory            <\/label>\r\n            \r\n            <div class=\"quiz-nav\" style=\"display:flex;justify-content:space-between;margin-top:16px;gap:8px;\">\r\n                                    <button class=\"quiz-prev\" data-prev=\"1\" style=\"background:#fff;color:#333;border:2px solid #ddd;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:border-color .15s;\">Previous<\/button>\r\n                                                    <button class=\"quiz-next\" data-next=\"3\" style=\"background:#00B0AE;color:#fff;border:none;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:opacity .15s;\">Next<\/button>\r\n                            <\/div>\r\n        <\/div>\r\n                <div class=\"quiz-step\" data-step=\"3\" style=\"display:none;\">\r\n            <p style=\"font-size:16px;font-weight:700;color:#111;margin:0 0 14px;\">3 \/ 5 &mdash; How do external providers access your systems?<\/p>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q3\" value=\"2\" style=\"margin-right:10px;accent-color:#00B0AE;\">Named accounts, limited rights, temporary access            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q3\" value=\"1\" style=\"margin-right:10px;accent-color:#00B0AE;\">Named accounts, but broad rights            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q3\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">One shared account per provider            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:0;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q3\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">I am not entirely sure            <\/label>\r\n            \r\n            <div class=\"quiz-nav\" style=\"display:flex;justify-content:space-between;margin-top:16px;gap:8px;\">\r\n                                    <button class=\"quiz-prev\" data-prev=\"2\" style=\"background:#fff;color:#333;border:2px solid #ddd;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:border-color .15s;\">Previous<\/button>\r\n                                                    <button class=\"quiz-next\" data-next=\"4\" style=\"background:#00B0AE;color:#fff;border:none;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:opacity .15s;\">Next<\/button>\r\n                            <\/div>\r\n        <\/div>\r\n                <div class=\"quiz-step\" data-step=\"4\" style=\"display:none;\">\r\n            <p style=\"font-size:16px;font-weight:700;color:#111;margin:0 0 14px;\">4 \/ 5 &mdash; Are your critical applications isolated from each other?<\/p>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q4\" value=\"2\" style=\"margin-right:10px;accent-color:#00B0AE;\">Yes, segmentation is in place            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q4\" value=\"1\" style=\"margin-right:10px;accent-color:#00B0AE;\">Partly, on the most sensitive ones            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q4\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">No, the internal network is flat            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:0;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q4\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">We have not mapped our applications            <\/label>\r\n            \r\n            <div class=\"quiz-nav\" style=\"display:flex;justify-content:space-between;margin-top:16px;gap:8px;\">\r\n                                    <button class=\"quiz-prev\" data-prev=\"3\" style=\"background:#fff;color:#333;border:2px solid #ddd;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:border-color .15s;\">Previous<\/button>\r\n                                                    <button class=\"quiz-next\" data-next=\"5\" style=\"background:#00B0AE;color:#fff;border:none;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:opacity .15s;\">Next<\/button>\r\n                            <\/div>\r\n        <\/div>\r\n                <div class=\"quiz-step\" data-step=\"5\" style=\"display:none;\">\r\n            <p style=\"font-size:16px;font-weight:700;color:#111;margin:0 0 14px;\">5 \/ 5 &mdash; Could you tell what a compromised account accessed?<\/p>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q5\" value=\"2\" style=\"margin-right:10px;accent-color:#00B0AE;\">Yes, access is logged per application            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q5\" value=\"1\" style=\"margin-right:10px;accent-color:#00B0AE;\">Partly, with some analysis work            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:8px;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q5\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">Hardly, the VPN details nothing            <\/label>\r\n                        <label style=\"display:block;padding:12px 16px;margin-bottom:0;background:#fff;border:2px solid #ddd;border-radius:8px;cursor:pointer;font-size:15px;color:#333;transition:border-color .15s,background .15s;\">\r\n                <input type=\"radio\" name=\"q5\" value=\"0\" style=\"margin-right:10px;accent-color:#00B0AE;\">No, we would have no visibility            <\/label>\r\n            \r\n            <div class=\"quiz-nav\" style=\"display:flex;justify-content:space-between;margin-top:16px;gap:8px;\">\r\n                                    <button class=\"quiz-prev\" data-prev=\"4\" style=\"background:#fff;color:#333;border:2px solid #ddd;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:border-color .15s;\">Previous<\/button>\r\n                                                    <button id=\"quiz-ia-submit\" style=\"background:#00B0AE;color:#fff;border:none;padding:12px 24px;border-radius:8px;font-size:15px;font-weight:700;cursor:pointer;font-family:Montserrat,Arial,sans-serif;transition:opacity .15s;\">See my result<\/button>\r\n                            <\/div>\r\n        <\/div>\r\n        \r\n        <div id=\"quiz-ia-result\" style=\"display:none;\"><\/div>\r\n\r\n    <\/div>\r\n    \r\n\r\n<h2 id=\"contents\">Table of Contents<\/h2>\r\n<ol>\r\n<li><a href=\"#perimeter\">The perimeter is gone, your VPN has not noticed<\/a><\/li>\r\n<li><a href=\"#principles\">Zero Trust: three principles, no product<\/a><\/li>\r\n<li><a href=\"#vpn-ztna\">VPN or ZTNA: what really changes<\/a><\/li>\r\n<li><a href=\"#start\">Where to start when IT is two people<\/a><\/li>\r\n<li><a href=\"#mistakes\">Five mistakes that derail the project<\/a><\/li>\r\n<li><a href=\"#switzerland\">What the Swiss context adds<\/a><\/li>\r\n<li><a href=\"#skills\">The skills that are missing most<\/a><\/li>\r\n<li><a href=\"#conclusion\">Conclusion<\/a><\/li>\r\n<li><a href=\"#faq-zero-trust\">FAQ<\/a><\/li>\r\n<\/ol>\r\n\r\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/zero-trust-securite-entreprise.webp\" alt=\"IT security team gathered around a wall of notes in a bright Swiss office\" width=\"1584\" height=\"672\" loading=\"lazy\" \/><\/p>\r\n\r\n<p>Search for &#8220;zero trust&#8221; and look at the results. The first ten belong to security vendors. Moreover, they all tell the same story: the traditional model is dead, their platform replaces it, a demo is waiting. That story is not wrong. However, it is incomplete, and the omission proves expensive.<\/p>\r\n\r\n<p>Zero Trust cannot be bought. In fact, it is decided first, then built. Furthermore, it usually runs on tools you already own. On the ground, the hard part is rarely technical. It is almost always organisational. Consequently, here is the article no vendor will write, because it does not end with a purchase order.<\/p>\r\n\r\n<h2 id=\"perimeter\">The perimeter is gone, your VPN has not noticed<\/h2>\r\n\r\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/acces-distant-teletravail-vpn.webp\" alt=\"employee working remotely from a Swiss train with her laptop\" width=\"1584\" height=\"672\" loading=\"lazy\" \/><\/p>\r\n\r\n<p>For twenty years, security rested on one simple idea. There is an inside and an outside. Specifically, the firewall marks the border and the VPN acts as the drawbridge. After that, anything past the bridge counts as legitimate. Meanwhile, that model held only while data stayed in the server room.<\/p>\r\n\r\n<p>That geography has disappeared. Your files live in Microsoft 365. Accounting runs on an application hosted in Ireland. Your sales team, in turn, connects from a train between Geneva and Zurich. In other words, the perimeter no longer separates anything. Therefore the right question changes: should this person reach this specific file, right now, from this device?<\/p>\r\n\r\n<p>Swiss figures illustrate the shift. Indeed, in its <a href=\"https:\/\/www.bacs.admin.ch\/fr\/hjb-26-1-fr\" target=\"_blank\" rel=\"noopener\">2026\/1 semi-annual report<\/a>, the Federal Office for Cybersecurity notes a rise in phishing reports tied to Microsoft 365. Attackers take over a corporate mailbox. Then they impersonate the IT helpdesk or a senior manager and trigger payments. As a result, no firewall stops the attack: the account is genuine, and the VPN waves it through.<\/p>\r\n\r\n<h2 id=\"principles\">Zero Trust: three principles, no product<\/h2>\r\n\r\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/verification-identite-acces.webp\" alt=\"identity verification with a badge at a glass office door\" width=\"1584\" height=\"672\" loading=\"lazy\" \/><\/p>\r\n\r\n<p>The term sounds intimidating. Nevertheless, it covers a blunt idea: trust nothing by default, not even what sits inside your walls. The reference remains <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/207\/final\" target=\"_blank\" rel=\"noopener\">NIST SP 800-207<\/a>, published in 2020. It describes an architecture, not a product line. Three principles sum it up.<\/p>\r\n\r\n<ul>\r\n<li><strong>Verify explicitly.<\/strong> The system weighs every request against several signals: identity, device, location, sensitivity of the resource. Therefore yesterday&#8217;s successful login is not today&#8217;s authorisation.<\/li>\r\n<li><strong>Grant the minimum.<\/strong> People receive the rights their task requires, for the duration of that task. Consequently, the permanent admin account becomes the exception.<\/li>\r\n<li><strong>Assume compromise.<\/strong> You start from the assumption that an account has already fallen. The whole design therefore limits what an attacker reaches from that foothold.<\/li>\r\n<\/ul>\r\n\r\n<p>Notice that none of these principles names a product. In practice, an SME running Microsoft 365 already owns most of the building blocks: multi-factor authentication, conditional access, device management. The work is to switch them on and configure them properly. Above all, someone must decide who gets access to what. No vendor will make that call for you.<\/p>\r\n\r\n<p>It is worth stating what this approach does not do. It replaces neither your backups, nor your antivirus, nor staff awareness. Nor does it make phishing impossible. In contrast, it sharply reduces what an intruder obtains once inside. In other words, Zero Trust works on the consequences of a compromise rather than its likelihood. Ultimately, that nuance changes how you measure success: you stop counting blocked attacks and start measuring how far an intruder can travel.<\/p>\r\n\r\n<h2 id=\"vpn-ztna\">VPN or ZTNA: what really changes<\/h2>\r\n\r\n<p>ZTNA, short for Zero Trust Network Access, is the component gradually replacing the corporate VPN. The difference fits in one sentence. Put simply, a VPN opens the network, whereas ZTNA opens a single application. The table below sums up the practical gaps.<\/p>\r\n\r\n<div style=\"overflow-x:auto;-webkit-overflow-scrolling:touch;max-width:100%;width:100%;margin:1rem 0 0.5rem 0;\"><table style=\"min-width:550px;width:max-content;\">\r\n<thead><tr><th>Criterion<\/th><th>Traditional VPN<\/th><th>ZTNA<\/th><\/tr><\/thead>\r\n<tbody>\r\n<tr><td>Scope of access<\/td><td>The whole internal network<\/td><td>One specific application<\/td><\/tr>\r\n<tr><td>When checks happen<\/td><td>At connection time<\/td><td>Continuously, on every request<\/td><\/tr>\r\n<tr><td>Signals assessed<\/td><td>Username and password<\/td><td>Identity, device, context, risk<\/td><\/tr>\r\n<tr><td>Lateral movement<\/td><td>Possible once connected<\/td><td>Strongly contained<\/td><\/tr>\r\n<tr><td>Visibility on usage<\/td><td>Limited<\/td><td>Logging per application<\/td><\/tr>\r\n<tr><td>User experience<\/td><td>Manual login, latency<\/td><td>Seamless when well configured<\/td><\/tr>\r\n<\/tbody>\r\n<\/table><\/div>\r\n\r\n<p>Beware of a common shortcut, though. Installing ZTNA does not make you Zero Trust. Do you still keep shared admin accounts, passwords without a second factor and rights piled up over ten years? You will simply have swapped one tunnel for another. In reality, the gain comes from the clean-up done beforehand, not from the technology layered on top.<\/p>\r\n\r\n<h2 id=\"start\">Where to start when IT is two people<\/h2>\r\n\r\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/inventaire-comptes-administrateurs.webp\" alt=\"system administrators taking inventory of access in a server room\" width=\"1584\" height=\"672\" loading=\"lazy\" \/><\/p>\r\n\r\n<p>Vendor documentation describes eighteen-month programmes run by dedicated teams. In a hundred-seat company with two people in IT, that approach stays theoretical. Here is a realistic sequence instead, step by step. Each stage delivers a measurable benefit, even if the next one waits.<\/p>\r\n\r\n<h3>Step 1: regain control of identities<\/h3>\r\n\r\n<p>Start with multi-factor authentication for everyone, with no exception for the management team or for service accounts. Next, inventory privileged accounts. Indeed, most audits uncover admin rights still assigned to people who left long ago. This clean-up costs nothing but time, and it closes the most commonly used door.<\/p>\r\n\r\n<h3>Step 2: make access conditional on context<\/h3>\r\n\r\n<p>Once identities are in order, define conditional access rules. An unmanaged device does not reach sensitive data. Similarly, a login from a country where you have no operations triggers an extra check. Mind the catch, though: conditional access requires a Microsoft Entra ID P1 licence, included in Microsoft 365 Business Premium and E3 but absent from Business Basic and Standard. On the Google Workspace side, the equivalent comes with the higher editions. Moreover, these rules stay widely underused even by those who already own them.<\/p>\r\n\r\n<h3>Step 3: segment before replacing the VPN<\/h3>\r\n\r\n<p>Many teams want the VPN gone within the first few weeks. Take the time to identify your critical applications first, then isolate them from one another. In other words, microsegmentation comes before the big swap. As a result, you cut risk immediately, and moving to ZTNA becomes a formality.<\/p>\r\n\r\n<h3>How to pace the work without exhausting the team<\/h3>\r\n\r\n<p>A small team advances in quarterly steps. The first quarter absorbs multi-factor authentication and the account inventory. Conditional access follows, starting with a pilot group rather than the entire company. In the third quarter, you tackle segmentation of the most sensitive applications. This way, each step stays reversible if the business pushes back. Above all, budget time for internal communication: an access denial without explanation generates more tickets than an outage.<\/p>\r\n\r\n<h2 id=\"mistakes\">Five mistakes that derail the project<\/h2>\r\n\r\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/erreurs-projet-securite.webp\" alt=\"team meeting about mistakes in an IT security project\" width=\"1584\" height=\"672\" loading=\"lazy\" \/><\/p>\r\n\r\n<p>Zero Trust projects rarely fail on a technical flaw. In practice, they fail because a step was skipped. These are the ones that come up most often.<\/p>\r\n\r\n<ul>\r\n<li><strong>Buying before mapping.<\/strong> Without an inventory of applications and flows, you cannot know what to protect first. Consequently, the licence sits unused in a drawer.<\/li>\r\n<li><strong>Forgetting external partners.<\/strong> Accountants, IT providers, agencies, temporary staff: their access often escapes internal rules. Yet it remains a classic entry point.<\/li>\r\n<li><strong>Ignoring user experience.<\/strong> An overly rigid policy breeds workarounds. Staff then switch to personal email, and you lose all visibility.<\/li>\r\n<li><strong>Treating it as an IT project.<\/strong> Deciding who accesses what is a business call. Without arbitration from leadership, the IT team stalls.<\/li>\r\n<li><strong>Stopping at go-live.<\/strong> Rights drift and headcount changes. Without periodic reviews, the architecture quietly decays.<\/li>\r\n<\/ul>\r\n\r\n<h2 id=\"switzerland\">What the Swiss context adds<\/h2>\r\n\r\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cybersecurite-entreprise-suisse.webp\" alt=\"executives discussing cybersecurity in a Geneva office overlooking the lake\" width=\"1584\" height=\"672\" loading=\"lazy\" \/><\/p>\r\n\r\n<p>The Zero Trust debate reaches us from the United States, where federal requirements did much to popularise it. In Switzerland, however, two elements change the picture.<\/p>\r\n\r\n<p>First, mandatory reporting. Since 1 April 2025, operators of critical infrastructure must <a href=\"https:\/\/www.bacs.admin.ch\/fr\/25-mp2-fr\" target=\"_blank\" rel=\"noopener\">report any cyberattack to the federal cybersecurity office within 24 hours<\/a> of detection. Moreover, a fines regime has applied since October of that year. The obligation covers cantonal and municipal administrations, transport companies and energy suppliers. Yet reporting within 24 hours assumes you know what happened. An architecture that logs access per application answers that question. An opaque VPN does not.<\/p>\r\n\r\n<p>Second, sheer volume. The federal office received 27,128 voluntary reports and 200 mandatory notifications in the first half of 2026. In addition, it recorded 79 ransomware cases over the same period. The threat therefore does not target large groups alone. It hits mid-sized organisations, often through one compromised mailbox. Our articles on <a href=\"https:\/\/www.itta.net\/en\/blog\/ransomware-protect-your-business\/\" target=\"_blank\" rel=\"noopener\">protecting your business against ransomware<\/a> and on <a href=\"https:\/\/www.itta.net\/en\/blog\/nis2-directive-companies-2026\/\" target=\"_blank\" rel=\"noopener\">the NIS2 directive<\/a> round out the picture.<\/p>\r\n\r\n<h3>Data protection pushes the same way<\/h3>\r\n\r\n<p>Finally, the revised Swiss data protection act, known as the nFADP, points in the same direction. It requires you to know who accesses personal data and to document those activities. Yet a flat network, where every connected employee reaches every share, makes that demonstration impossible. Conversely, an architecture that grants the minimum and logs access produces the evidence naturally. Zero Trust therefore serves two goals at once: it limits the blast radius of an intrusion, and it documents your access for the regulator.<\/p>\r\n\r\n<h2 id=\"skills\">The skills that are missing most<\/h2>\r\n\r\n<p>A successful Zero Trust architecture rests on one specific profile. You need someone who can turn a business requirement into an access rule, then verify that the rule holds over time. This is neither a classic systems administrator nor a governance consultant. It is an architect. Unfortunately, that profile stays rare and hard to recruit.<\/p>\r\n\r\n<p>Two areas therefore deserve a training investment. The first is design: modelling flows, defining an identity strategy, balancing security against usability. Daily operations form the second, namely access reviews and alert handling. The Microsoft SC-100 certification addresses the first area precisely, with an architecture approach that goes beyond tool configuration.<\/p>\r\n\r\n\r\n<figure class=\"wp-block-image size-large itta-cta-banner\" style=\"margin:2.75rem 0\"><a href=\"https:\/\/www.itta.net\/en\/trainings\/it-pro\/audit-and-cybersecurity\/microsoft-cybersecurity-architect\/\" target=\"_blank\" rel=\"noopener\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1810\" height=\"768\" src=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cta-microsoft-cybersecurity-architect-en.png\" alt=\"Microsoft Cybersecurity Architect SC-100 training\" class=\"wp-image-254703\" srcset=\"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cta-microsoft-cybersecurity-architect-en.png 1810w, https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cta-microsoft-cybersecurity-architect-en-300x127.png 300w, https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cta-microsoft-cybersecurity-architect-en-1024x434.png 1024w, https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cta-microsoft-cybersecurity-architect-en-768x326.png 768w, https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cta-microsoft-cybersecurity-architect-en-1536x652.png 1536w, https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/cta-microsoft-cybersecurity-architect-en-600x255.png 600w\" sizes=\"(max-width: 1810px) 100vw, 1810px\" \/><\/a><\/figure>\r\n\r\n\r\n<p>If your team starts further back, working through <a href=\"https:\/\/www.itta.net\/en\/trainings\/it-pro\/audit-and-cybersecurity\/\" target=\"_blank\" rel=\"noopener\">the fundamentals of IT security<\/a> beats diving straight into architecture. In short, consolidate the basics before stacking concepts on a fragile base.<\/p>\r\n\r\n<h2 id=\"conclusion\">Conclusion<\/h2>\r\n\r\n<p>Zero Trust is not a checkbox, and certainly not a line on an invoice. Rather, it reframes an old question. Who accesses what, on what basis, and how do we verify it continuously? Companies that succeed begin with an inventory and with cleaning up identities. They do not begin with a tender.<\/p>\r\n\r\n<p>In other words, clear the room before buying furniture. To begin with, enable multi-factor authentication everywhere. Then remove dormant rights. Finally, segment your critical applications. The first two cost nothing but time, and they already deliver most of the gain. Check your edition, however, before counting on conditional access. The rest follows naturally, including the VPN replacement.<\/p>\r\n\r\n<h2 id=\"faq-zero-trust\">FAQ<\/h2>\r\n\r\n<p><strong>Does Zero Trust suit a 50-person company?<\/strong><br \/>\r\nYes, and often better than a large group. The application landscape is quicker to map, and access decisions are easier to make.<\/p>\r\n\r\n<p><strong>Must the VPN go for Zero Trust to work?<\/strong><br \/>\r\nNo. In practice, the VPN coexists well during the transition. Reduce what it exposes, then verify every application access.<\/p>\r\n\r\n<p><strong>How long does a realistic rollout take?<\/strong><br \/>\r\nExpect six to twelve months for identities and conditional access in a mid-sized organisation. Network segmentation takes longer.<\/p>\r\n\r\n<p><strong>Does Zero Trust stop ransomware?<\/strong><br \/>\r\nIt does not prevent entry. However, it sharply limits spread, since one compromised account no longer opens the whole network.<\/p>\r\n\r\n<p><strong>Which certification suits this kind of project?<\/strong><br \/>\r\nSC-100 covers security architecture, including Zero Trust strategy. It does assume prior experience with Microsoft 365 or Azure.<\/p>\r\n\r\n\r\n","protected":false},"excerpt":{"rendered":"<p>Zero Trust is not a product you install. It is a method you apply. Here is what vendors leave out of the pitch, and where a Swiss SME should actually begin. Table of Contents The perimeter is gone, your VPN has not noticed Zero Trust: three principles, no product VPN or ZTNA: what really changes [&hellip;]<\/p>\n","protected":false},"author":112,"featured_media":254694,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[2938,2944],"tags":[],"class_list":["post-254705","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-informatique","category-it-pro"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.5 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Zero Trust: what vendors won&#039;t tell you<\/title>\n<meta name=\"description\" content=\"Zero Trust is not a product. Where to start in a Swiss SME, and the five mistakes that derail the project.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Damien Crocq\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/\"},\"author\":{\"name\":\"Damien Crocq\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#\\\/schema\\\/person\\\/ca875e6c61a8f6f224901d4b48e1494f\"},\"headline\":\"What Vendors Won&#8217;t Tell You About Zero Trust\",\"datePublished\":\"2026-09-15T09:28:35+00:00\",\"dateModified\":\"2026-09-16T15:42:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/\"},\"wordCount\":1894,\"publisher\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/zero-trust-editeurs-miniature.webp\",\"articleSection\":[\"Informatique\",\"IT Pro\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/\",\"url\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/\",\"name\":\"Zero Trust: what vendors won't tell you\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/zero-trust-editeurs-miniature.webp\",\"datePublished\":\"2026-09-15T09:28:35+00:00\",\"dateModified\":\"2026-09-16T15:42:56+00:00\",\"description\":\"Zero Trust is not a product. Where to start in a Swiss SME, and the five mistakes that derail the project.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/zero-trust-editeurs-miniature.webp\",\"contentUrl\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/zero-trust-editeurs-miniature.webp\",\"width\":1376,\"height\":768,\"caption\":\"zero trust en entreprise, la frontiere reseau traditionnelle laisse place aux acces individuels\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/blog\\\/what-vendors-wont-tell-you-about-zero-trust\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.itta.net\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Vendors Won&rsquo;t Tell You About Zero Trust\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.itta.net\\\/en\\\/\",\"name\":\"ITTA\",\"description\":\"Formations &amp; Certifications en Suisse Romande\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.itta.net\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":[\"Organization\",\"EducationalOrganization\"],\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#organization\",\"name\":\"ITTA\",\"alternateName\":\"IT TRAINING ACADEMY SA\",\"url\":\"https:\\\/\\\/www.itta.net\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/Logo-transparent.png\",\"contentUrl\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2023\\\/02\\\/Logo-transparent.png\",\"width\":1500,\"height\":623,\"caption\":\"ITTA\"},\"image\":{\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/people\\\/ITTA\\\/100063747262936\\\/\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/1001738\",\"https:\\\/\\\/www.instagram.com\\\/itta_suisse\\\/\"],\"contactPoint\":{\"@type\":\"ContactPoint\",\"telephone\":\"+41 58 307 73 00\",\"contactType\":\"customer service\",\"availableLanguage\":[\"French\",\"English\"],\"areaServed\":[{\"@type\":\"Country\",\"name\":\"Switzerland\"},{\"@type\":\"Country\",\"name\":\"France\"}]},\"location\":[{\"@type\":\"Place\",\"name\":\"ITTA Geneve\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Route des Jeunes 35\",\"addressLocality\":\"Carouge\",\"postalCode\":\"1227\",\"addressRegion\":\"GE\",\"addressCountry\":\"CH\"},\"geo\":{\"@type\":\"GeoCoordinates\",\"latitude\":46.18274,\"longitude\":6.12922}},{\"@type\":\"Place\",\"name\":\"ITTA Lausanne\",\"address\":{\"@type\":\"PostalAddress\",\"streetAddress\":\"Rue des Cotes-de-Montbenon 16\",\"addressLocality\":\"Lausanne\",\"postalCode\":\"1003\",\"addressRegion\":\"VD\",\"addressCountry\":\"CH\"},\"geo\":{\"@type\":\"GeoCoordinates\",\"latitude\":46.52111,\"longitude\":6.62734}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/en\\\/#\\\/schema\\\/person\\\/ca875e6c61a8f6f224901d4b48e1494f\",\"name\":\"Damien Crocq\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/damien-bio-1-100x100.jpg\",\"url\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/damien-bio-1-100x100.jpg\",\"contentUrl\":\"https:\\\/\\\/www.itta.net\\\/wp-content\\\/uploads\\\/2024\\\/04\\\/damien-bio-1-100x100.jpg\",\"caption\":\"Damien Crocq\"},\"description\":\"Damien est un professionnel dynamique, passionn\u00e9 par le marketing digital et le r\u00e9f\u00e9rencement naturel. Dipl\u00f4m\u00e9 d'un master en Web Marketing, il a acquis une solide exp\u00e9rience en e-commerce et a enseign\u00e9 sur des th\u00e9matiques de marketing digital. Aujourd'hui, il occupe le poste de sp\u00e9cialiste en marketing digital chez ITTA. Toujours curieux et innovant, Damien reste avant tout un passionn\u00e9 des technologies \u00e9mergentes, de l'informatique, de l'IA et du r\u00e9f\u00e9rencement naturel.\",\"sameAs\":[\"https:\\\/\\\/www.itta.net\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/damien-crocq\\\/?originalSubdomain=fr\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Zero Trust: what vendors won't tell you","description":"Zero Trust is not a product. Where to start in a Swiss SME, and the five mistakes that derail the project.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/","twitter_misc":{"Written by":"Damien Crocq","Estimated reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/#article","isPartOf":{"@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/"},"author":{"name":"Damien Crocq","@id":"https:\/\/www.itta.net\/en\/#\/schema\/person\/ca875e6c61a8f6f224901d4b48e1494f"},"headline":"What Vendors Won&#8217;t Tell You About Zero Trust","datePublished":"2026-09-15T09:28:35+00:00","dateModified":"2026-09-16T15:42:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/"},"wordCount":1894,"publisher":{"@id":"https:\/\/www.itta.net\/en\/#organization"},"image":{"@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/#primaryimage"},"thumbnailUrl":"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/zero-trust-editeurs-miniature.webp","articleSection":["Informatique","IT Pro"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/","url":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/","name":"Zero Trust: what vendors won't tell you","isPartOf":{"@id":"https:\/\/www.itta.net\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/#primaryimage"},"image":{"@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/#primaryimage"},"thumbnailUrl":"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/zero-trust-editeurs-miniature.webp","datePublished":"2026-09-15T09:28:35+00:00","dateModified":"2026-09-16T15:42:56+00:00","description":"Zero Trust is not a product. Where to start in a Swiss SME, and the five mistakes that derail the project.","breadcrumb":{"@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/#primaryimage","url":"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/zero-trust-editeurs-miniature.webp","contentUrl":"https:\/\/www.itta.net\/wp-content\/uploads\/2026\/09\/zero-trust-editeurs-miniature.webp","width":1376,"height":768,"caption":"zero trust en entreprise, la frontiere reseau traditionnelle laisse place aux acces individuels"},{"@type":"BreadcrumbList","@id":"https:\/\/www.itta.net\/en\/blog\/what-vendors-wont-tell-you-about-zero-trust\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.itta.net\/en\/"},{"@type":"ListItem","position":2,"name":"What Vendors Won&rsquo;t Tell You About Zero Trust"}]},{"@type":"WebSite","@id":"https:\/\/www.itta.net\/en\/#website","url":"https:\/\/www.itta.net\/en\/","name":"ITTA","description":"Formations &amp; Certifications en Suisse Romande","publisher":{"@id":"https:\/\/www.itta.net\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.itta.net\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":["Organization","EducationalOrganization"],"@id":"https:\/\/www.itta.net\/en\/#organization","name":"ITTA","alternateName":"IT TRAINING ACADEMY SA","url":"https:\/\/www.itta.net\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.itta.net\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.itta.net\/wp-content\/uploads\/2023\/02\/Logo-transparent.png","contentUrl":"https:\/\/www.itta.net\/wp-content\/uploads\/2023\/02\/Logo-transparent.png","width":1500,"height":623,"caption":"ITTA"},"image":{"@id":"https:\/\/www.itta.net\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/people\/ITTA\/100063747262936\/","https:\/\/www.linkedin.com\/company\/1001738","https:\/\/www.instagram.com\/itta_suisse\/"],"contactPoint":{"@type":"ContactPoint","telephone":"+41 58 307 73 00","contactType":"customer service","availableLanguage":["French","English"],"areaServed":[{"@type":"Country","name":"Switzerland"},{"@type":"Country","name":"France"}]},"location":[{"@type":"Place","name":"ITTA Geneve","address":{"@type":"PostalAddress","streetAddress":"Route des Jeunes 35","addressLocality":"Carouge","postalCode":"1227","addressRegion":"GE","addressCountry":"CH"},"geo":{"@type":"GeoCoordinates","latitude":46.18274,"longitude":6.12922}},{"@type":"Place","name":"ITTA Lausanne","address":{"@type":"PostalAddress","streetAddress":"Rue des Cotes-de-Montbenon 16","addressLocality":"Lausanne","postalCode":"1003","addressRegion":"VD","addressCountry":"CH"},"geo":{"@type":"GeoCoordinates","latitude":46.52111,"longitude":6.62734}}]},{"@type":"Person","@id":"https:\/\/www.itta.net\/en\/#\/schema\/person\/ca875e6c61a8f6f224901d4b48e1494f","name":"Damien Crocq","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.itta.net\/wp-content\/uploads\/2024\/04\/damien-bio-1-100x100.jpg","url":"https:\/\/www.itta.net\/wp-content\/uploads\/2024\/04\/damien-bio-1-100x100.jpg","contentUrl":"https:\/\/www.itta.net\/wp-content\/uploads\/2024\/04\/damien-bio-1-100x100.jpg","caption":"Damien Crocq"},"description":"Damien est un professionnel dynamique, passionn\u00e9 par le marketing digital et le r\u00e9f\u00e9rencement naturel. Dipl\u00f4m\u00e9 d'un master en Web Marketing, il a acquis une solide exp\u00e9rience en e-commerce et a enseign\u00e9 sur des th\u00e9matiques de marketing digital. Aujourd'hui, il occupe le poste de sp\u00e9cialiste en marketing digital chez ITTA. Toujours curieux et innovant, Damien reste avant tout un passionn\u00e9 des technologies \u00e9mergentes, de l'informatique, de l'IA et du r\u00e9f\u00e9rencement naturel.","sameAs":["https:\/\/www.itta.net","https:\/\/www.linkedin.com\/in\/damien-crocq\/?originalSubdomain=fr"]}]}},"permalink_manager":null,"_links":{"self":[{"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/posts\/254705","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/users\/112"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/comments?post=254705"}],"version-history":[{"count":5,"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/posts\/254705\/revisions"}],"predecessor-version":[{"id":254846,"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/posts\/254705\/revisions\/254846"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/media\/254694"}],"wp:attachment":[{"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/media?parent=254705"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/categories?post=254705"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itta.net\/en\/wp-json\/wp\/v2\/tags?post=254705"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}