Wethaq ICT | وثاق
Get a Quote
Insights

Zero Trust in practice: a phased approach for regulated bodies

GovernmentBanks & finance

Traditional perimeter security assumed that anything inside the network could be trusted. Remote work, cloud services, third-party access and lateral-movement attacks have made that assumption unsafe: once an attacker holds one valid account or one compromised laptop, a flat internal network does the rest. Zero Trust is often sold as a product, but it is an architecture and a set of decisions. NIST SP 800-207 describes it as moving defences away from static network perimeters towards users, assets and resources, with no implicit trust granted because of network location.

The core ideas are simple: verify explicitly, grant least privilege, and assume breach. In SP 800-207 terms, every access request is evaluated by a policy decision point using identity, device state and context, and enforced by a policy enforcement point. For regulated organisations the practical question is not whether to adopt it, but in what order.

Phase 1: identity first

Identity is the new perimeter, and it is the cheapest place to start because most attacks rely on stolen or abused credentials. Begin with these steps:

  • Consolidate onto a small number of authoritative identity providers and retire shared, generic and stale accounts.
  • Enforce multi-factor authentication for all remote access, administrators and privileged roles first, then extend it to every user. For administrators and high-risk roles, prefer phishing-resistant methods such as FIDO2 security keys over SMS codes.
  • Introduce privileged access management with just-in-time elevation, session recording and separate administrative accounts.
  • Apply conditional access so that sign-ins from unusual locations, impossible travel or risky devices trigger stronger checks or are blocked.

Do not forget service accounts and machine identities. They rarely support MFA, so inventory them, limit their scope, rotate their secrets and monitor their behaviour.

Phases 2 and 3: device posture, segmentation and application access

Know which devices are managed. Build an inventory and use signals such as EDR presence, patch level, disk encryption and configuration compliance as inputs to access decisions. An unmanaged or non-compliant device should receive reduced access, for example browser-only access to low-risk applications and no access to sensitive systems.

Flat networks let attackers move freely, so segmentation comes next. Start with coarse zones: users, servers, management interfaces, payment or core systems, and any operational technology. Then move to micro-segmentation around the assets that matter most, such as core banking platforms, databases, domain controllers and administrative consoles. Two practical rules help here:

  • Map real traffic flows in monitor-only mode before enforcing any deny rule, otherwise you will break production and lose stakeholder support.
  • Where feasible, replace broad VPN access with per-application access, and encrypt internal traffic between tiers.

Phase 4: continuous monitoring and common pitfalls

Zero Trust decisions are only as good as the telemetry behind them. Feed identity, device and network logs into your SOC, detect anomalies such as unusual privilege use or new lateral connections, and review policies regularly. Validate the design with attack simulation, not just configuration reviews. NIST CSF 2.0 and the CIS Controls provide a useful way to express progress to management and auditors.

Watch for the mistakes we see most often:

  • Big-bang rollouts. Start with one business unit or one critical application and learn from it.
  • Ignoring legacy systems. Systems that cannot support modern authentication need compensating controls such as jump hosts, tight segmentation and enhanced monitoring.
  • No exception process. Without a documented and time-limited exception path, staff will find workarounds that defeat the policy.
  • Treating it as a product purchase. Tools help, but the policies, ownership and processes are what make Zero Trust work.

How Wethaq ICT helps

Wethaq ICT helps banks and government bodies turn Zero Trust into a realistic roadmap. We assess your current identity, device and network posture, prioritise phases against your risk and regulatory obligations, design segmentation and access policies, and support rollout and monitoring so that each phase delivers measurable risk reduction without disrupting operations.

Back to insights

Let’s build a secure foundation for your digital future

It starts with a free consultation: we learn your challenges and goals, then propose a service package tailored to your needs and budget.