
Roadmap to Zero Trust: A Practical Guide
Most organisations know that perimeter security is no longer fit for purpose. That model “build a strong edge, keep attackers out, trust what’s inside” was designed for offices, fixed networks, and a private data centre-hosted application estate.
That world has gone.
Now, users work anywhere, applications sit across data centres, cloud, and the public internet, and more and different end points keep joining the party.
So, if the world has changed, the strategy needs to change too. For an increasing number of organisations, the strategy of the future is Zero Trust -assume breach, and design to limit the damage, and a network designed for Zero Trust is the crucial foundation for that strategy.
What is Zero Trust?
Zero Trust can be summarised as “never trust, always and continuously verify”. The core idea is simple: don’t automatically trust people, devices, apps, or even security controls – instead, verify them, and keep verifying. This means that access decisions should be based on multiple points of verification such as identity, device, location, and behaviour, rather than using assumptions like “they’re an employee” or “they’re on the corporate network”.
But here’s the key shift: the network becomes the enforcement point for those decisions.
Here at TNC, we’ve boiled this down to three key principles:
- People and machines get the access they need – nothing more
- The network stops being a place you “join” and becomes a fabric that enforces access decisions
- Users/devices should only see the applications and data they’re allowed to use
In other words, the network needs to change from being a broad access domain to a policy-driven, identity-aware control layer.
Why This Matters
Zero Trust delivers well understood benefits, but many of them rely directly on how the network is designed and operated:
Simpler to manage
Traditional models added layers of firewalls and inspection points. A Zero Trust-aligned network simplifies this by embedding policy enforcement directly into the network fabric.
Reduced blast radius
By using the network to broker connections to specific applications, rather than exposing large segments, compromise is contained by design.
Consistent security across environments
Whether traffic flows across campus, WAN, or cloud, the network becomes the consistent enforcement plane for policy.
No implicit trust from “being inside”
The network no longer grants access, it enforces verification. Being connected provides no inherent advantage.
Better visibility and auditability
When access flows are brokered and controlled at the network level, every connection becomes observable, measurable, and attributable.
A foundation for modern access
As SaaS adoption grows and identity becomes central, the network evolves to support dynamic, context-aware connectivity rather than static access paths.
A Practical Roadmap
Zero Trust is not just a security strategy – it’s a network architecture transformation.
As always, the first step is defining a clear target state and aligning stakeholders. But with Zero Trust, this alignment must explicitly include network architecture, because the network is what ultimately delivers enforcement.
Once aligned, the focus shifts to execution, delivering incremental changes that reshape how the network handles access.
Key elements of the roadmap include:
Treat Identity as the Control Plane, But Deliver It Through the Network
Identity defines who should get access.
The network enforces how that access is delivered.
Authentication, roles, and conditional policies must be tightly integrated with network paths so that connectivity decisions reflect identity in real time.
Make Device Posture a Network Input
A verified identity alone isn’t enough.
Device health signals need to feed directly into network enforcement, ensuring that connectivity is dynamically adjusted based on risk.
This is where the network becomes adaptive, not just connective.
Move from Network Access to Network-Brokered Application Access
This is the critical shift.
Instead of giving users network-level access (VPNs, flat connectivity), the network should:
- Broker connections
- Restrict paths to specific applications
- Prevent lateral movement by design
The network evolves from a transport layer into a policy enforcement layer.
Handle Legacy and Non-Identity-Aware Systems with Network Controls
Not everything supports modern identity.
This is where traditional network capabilities such as segmentation, NAC, controlled egress, become essential.
In a Zero Trust model, the network compensates where identity cannot.
Reduce Exposure Through Network Design
A mature Zero Trust architecture removes unnecessary inbound connectivity.
Instead:
- Applications sit behind controlled access points
- Connectivity is initiated outbound where possible
- The network acts as a gatekeeper, validating every session before it is established
Operate the Network as a Policy Platform
Zero Trust only works if signals, policies, and enforcement stay aligned.
That means the network must:
- Ingest telemetry
- Enforce dynamic policies
- Provide continuous visibility
This is a shift from static infrastructure to a continuously tuned system.
What makes it hard, and how can you avoid the pitfalls?
As is often the case with transformative technologies, Zero Trust can sound like an endless list of benefits, but the reality is that transformation will be hard, and there are many specific challenges you’ll need to address:
Policy complexity becomes network complexity
Defining access policies is one thing, enforcing them consistently across network paths is another.
Siloed teams slow progress
Network, security, and endpoint teams must operate as one. Otherwise, enforcement gaps emerge.
Legacy systems rely heavily on network controls
Where identity falls short, the network must compensate, often increasing design complexity.
Hybrid states are unavoidable
VPNs and traditional network access will coexist with Zero Trust models for some time. The network must support both, securely.
Ownership can be unclear
Zero Trust often sits with security leadership, but delivery depends heavily on network architecture and operations.
If you’re starting now: a simple 90-day plan
Define the target state
Include not just principles, but how the network will enforce them
Map current network access paths
Understand how connectivity actually works today—including hidden or legacy routes
Select three use cases
Focus on network-delivered improvements:
- Replace a VPN flow with application-brokered access
- Enforce device posture through network controls
- Restrict access to a sensitive application via network-based policy
Define the operating model
Clarify who owns policy vs. who owns network enforcement
Communicate the roadmap
Emphasise that this is a phased transformation of both security and network architecture
Conclusions
Zero Trust isn’t a rollout, it’s a transformation in how access is delivered and controlled. While identity defines intent, the network delivers enforcement. Therefore, the end state is not a network that disappears, but one that becomes:
- Identity-aware
- Policy-driven
- Application-focused
- Continuously adaptive
The route to get there must be pragmatic: define the target state, modernise identity and device signals, and critically, evolve the network into the platform that makes Zero Trust real.
