What Is Zero Trust Security? A Guide for NZ Businesses

Zero trust security is an approach that checks access to business systems using identity, device condition and the access being requested. Being inside the office network does not automatically make a connection trustworthy, and access is limited to what is needed.

 

The office has a firewall. The files are in Microsoft 365, the accounts system is a browser tab, two staff work from home on their own laptops and the bookkeeper logs in from Auckland. The wall is still there, but a lot of the work now happens outside it.

This guide explains what zero trust security means for a New Zealand business, how it works alongside a VPN and the tools you already have, what government guidance says, and where to start.

What is zero trust security?

Zero trust security is an approach that checks access to business systems using identity, device condition and the access being requested, rather than trusting a connection because of where it comes from. Access is limited to what is needed and reassessed as relevant information changes.

For a business, that means knowing who can reach each system, protecting their sign-ins, checking the devices they use and removing access that is no longer needed. It is an approach put into practice through policies, processes and tools, rather than one product.

The New Zealand government’s own definition is a useful one. The NZISM describes zero trust as “a security architecture centered on the concept that organisations should not automatically trust anything inside or outside its perimeters and instead must verify anything and everything trying to connect to its systems before granting access”. It adds that trust “is continuously earned through verifying factors, such as identity, context and activity”.

Continuously does not mean a fresh sign-in for every click. It means access decisions can be re-evaluated when something relevant changes, such as a device falling out of policy or a sign-in from an unexpected place. How that works depends on the application and how it is set up.

An example of zero trust security in practice

A staff member needs the payroll system from home. The access policy checks their account, how they signed in and whether their device meets the required conditions. Passing those checks gives them payroll, not every internal system. If the conditions change, the policy may ask for another check or restrict access.

Illustrative zero trust example: a staff member at home passes account, MFA and device checks and reaches payroll, while other internal systems stay closed

What are the core principles of zero trust security?

This guide uses four practical principles to summarise the approach. They draw on the NZISM, the NCSC’s modern defensible architecture guidance and NIST Special Publication 800-207, which sets out its own seven tenets in more detail.

  • Verify explicitly. Access decisions use current signals: identity, how someone signed in, device condition, location and the sensitivity of what is being reached.
  • Use least privilege. People and systems get the access the task needs, and no more. This is NCSC Critical Control 9 and Minimum Cyber Security Standard 7 in its own right.
  • Assume breach. Design as though somebody already has a foothold. Segmentation, application-level access and monitoring follow from that assumption.
  • Reassess access. Access already granted can be tightened or ended as the signals change, where the application supports it.

 

Least privilege is a good place to start the internal conversation about zero trust security, because it stands on its own in New Zealand guidance: a Critical Control the NCSC recommends to everyone, and a Minimum Standard that mandated government agencies are required to implement. It can also be the hardest conversation, because trimming access from people who have it is unpopular in a small business where everybody knows everybody.

Where should a New Zealand small business start with zero trust security?

Start with the systems that matter most and the people and accounts that can reach them. The order below is a practical sequence, but priorities should follow your exposure and business impact rather than a fixed checklist.

  • Identify important systems and who uses them. List the people, devices and service accounts that reach each one. A first review can turn up admin rights nobody needs, old service accounts and logins that were never disabled.
  • Strengthen sign-ins and reduce privileges. Use multi-factor authentication for people, with a phishing-resistant method where the platform supports one, and protection suited to service and workload accounts. Our guide to multi-factor authentication covers the options and where each one breaks down.
  • Pilot access policies and device requirements. Test conditional access with a small group first, keep an emergency-access route, and review the effect before enforcing it for everyone.
  • Test application access and segmentation. Move from broad network access to access for specific applications where it suits, then segment what remains. Our network security services cover segmentation and remote access.
  • Monitor and review exceptions. Check what the policies are blocking, which exceptions have been granted and whether they are still needed.

 

A practical order for zero trust security: identify key systems, strengthen sign-ins and trim access, pilot policies, test application access and segmentation, then monitor and review

Cloud workloads follow the same logic with different mechanics, which our cloud security page covers, and which is also where the NZISM puts one of its zero trust controls. Device requirements depend on devices being enrolled and protected, which our endpoint security service covers.

The NZISM’s own starting advice is modest. It suggests factoring zero trust principles into the digital roadmap, asking suppliers whether they are zero trust ready when investing in an IT solution, and talking to current suppliers about how they might begin.

Does zero trust security replace your VPN?

Not necessarily. Zero trust does not automatically require replacing your VPN. You can strengthen identity, device checks and access restrictions around the remote access you already have.

NZISM control 16.5.12.C.02 says agencies should use zero trust principles “alongside the use of VPN connections to enhance the security posture”. NIST expects most organisations to run a mix of zero trust and perimeter-based approaches for an indefinite period.

The risk to manage is broad access. A VPN set up to give every user reach across the whole network works against least privilege, but a VPN can also be restricted and combined with other controls. Access to specific applications may suit some systems, while a VPN remains the right tool for others. Some environments will need a planned migration and others will not, so choose the arrangement around the applications and access people need.

What does New Zealand government guidance say about zero trust security?

The New Zealand Information Security Manual, version 3.9, carries three numbered controls that name zero trust. All three are a SHOULD, meaning recommended practice. The table shows those selected controls, not the full set of obligations an organisation may have.

The NZISM is written for government agencies and for the vendors, contractors and consultants who provide services to them, and other organisations are encouraged to use it. For a private business it is a useful benchmark for zero trust security. It is also worth checking your contracts, including any government contracts, for security requirements that apply to you.

Selected NZISM controls that name zero trust Control
Agencies should design and implement zero trust principles and architecture to strengthen identification management 16.1.25.C.01, SHOULD
Agencies should use zero trust principles alongside the use of VPN connections to enhance the security posture 16.5.12.C.02, SHOULD
Agencies intending to adopt public cloud technologies or services should incorporate zero trust philosophies and concepts 2.3.26.C.01, SHOULD

 

The controls sit in identity, remote access and cloud. The manual also says the GCSB recommends zero trust “as the approach agencies should take”, which is a strong endorsement.

There is a second New Zealand source worth knowing about. In October 2025 the National Cyber Security Centre published guidance on modern defensible architecture, jointly with its counterparts in Australia, Canada, Germany, Japan, Korea and Czechia. It is not branded as a zero trust document, but zero trust sits inside it as a named component, described as the principles of “never trust, always verify”, assume breach and verify explicitly.

Where zero trust sits in the NCSC’s lists

Zero trust is not one of the NCSC’s ten Critical Controls or its ten Minimum Cyber Security Standards, and the NCSC notes that the standards “do not cover the entire cyber security spectrum”. Both lists do name multi-factor authentication and the principle of least privilege, two of the foundations zero trust security builds on.

Can you buy zero trust security?

No. This matters commercially, because products can be sold as zero trust security when they cover one component of it.

The NZISM is direct about it. Its rationale for the cloud control states: “Zero Trust is a set of principles and outcomes, not an architecture or a solution. You cannot ‘buy’ Zero Trust.”

The United States standard agrees. NIST Special Publication 800-207, published in August 2020, says that “Implementing a ZTA is a journey rather than a wholesale replacement of infrastructure or processes”, and that transitioning “cannot simply be accomplished with a wholesale replacement of technology”.

NIST also sets a realistic expectation about the destination: “Most enterprises will continue to operate in a hybrid zero-trust/perimeter-based mode for an indefinite period.” A proposal that promises a finished state in one project is describing something neither standard expects. A project can still deliver a defined outcome, such as multi-factor authentication for every staff account, while the wider approach continues.

What about the Privacy Act and insurers?

The Privacy Act 2020 does not prescribe a named zero trust programme. Information privacy principle 5 asks that personal information be protected “by such security safeguards as are reasonable in the circumstances to take”, and it names no technology or framework. That does not settle which safeguards are reasonable for a particular business, which depends on the information held and the risks involved.

The Privacy Commissioner’s guidance on security and access controls names multi-factor authentication and role-based access using least privilege, two components of zero trust security described in their own right.

The same goes for insurance. What your policy asks for is a question for your own broker and your own proposal form, not something to infer from a general market claim.

Zero trust security drawn as the principles behind four products rather than a product itself

What does zero trust security cost?

Before buying anything labelled zero trust security, check the features and licences you already have. In Microsoft 365, for example, Conditional Access requires Microsoft Entra ID P1, which Business Premium includes, and risk-based policies require Entra ID P2. Plans and add-ons differ, so the licence check comes first.

Costs also depend on application compatibility, device enrolment, cleaning up existing access, testing, staff support and ongoing management. Where monitoring is part of the plan, our managed detection and response service covers analyst investigation and response around those signals.

Zero trust security mistakes worth avoiding

Four mistakes are worth knowing about before you start.

  • Buying a product and calling it done. The NZISM says you cannot buy zero trust. Vendors sell components, and a component bought without the principles behind it becomes another console nobody opens.
  • Attempting the whole model at once. The layers depend on each other, so one large project can stall with the identity work half finished.
  • Skipping identity for something more visible. Identity is the layer the others read from, and zero trust security built on weak identity does not hold.
  • Ignoring what it feels like to use. Prompting people at every turn produces fatigue, and fatigued people approve things. Good design lets low-risk access through quietly and saves the friction for requests that warrant it.

 

Multi-factor fatigue is a documented attack technique, which is why the design of the checks matters as much as having them.

Frequently Asked Questions

What is zero trust security in simple terms?

Zero trust security is an approach that checks access to business systems using identity, device condition and the access being requested. Being inside the office network does not automatically make a connection trustworthy. Access is limited to what is needed and reassessed as relevant information changes.

Is zero trust required in New Zealand?

There is no single zero trust programme that every NZ business must adopt. Government guidance recommends zero trust principles, and particular controls may be required by your contracts or other obligations. Focus on the access safeguards your business needs rather than whether a product carries the label.

Does the Privacy Act require zero trust?

The Privacy Act 2020 does not name zero trust. Information privacy principle 5 requires security safeguards that are reasonable in the circumstances, and what is reasonable depends on the information you hold and the risks. The Privacy Commissioner names multi-factor authentication and role-based access with least privilege among the safeguards to consider.

Can you buy zero trust security as a product?

No. The New Zealand Information Security Manual describes zero trust as a set of principles and outcomes rather than a product you can buy. Vendors sell components such as identity, device management, application access and monitoring, and each can be worth buying, but none of them is the whole approach.

How is zero trust different from traditional security?

Traditional security defines a perimeter and trusts what is inside it. Zero trust security removes that automatic trust and checks access using identity, device condition and the request itself, wherever it comes from. The shift matters because staff work from anywhere, applications sit in the cloud, and contractors connect into systems that used to be internal.

What are the four principles of zero trust?

This guide summarises zero trust in four practical principles: verify explicitly using current signals, use least privilege, assume breach, and reassess access as signals change. They draw on the NZISM, NCSC guidance and NIST Special Publication 800-207, which sets out seven tenets in more detail.

Does zero trust replace a VPN?

Not necessarily. You can strengthen identity, device checks and access restrictions around existing remote access. Access to specific applications may suit some systems, while a VPN remains appropriate for others, so the arrangement should follow the applications and access people need.

How long does zero trust take to implement?

It depends on the systems, devices and applications involved. A defined piece of work, such as multi-factor authentication for every staff account, can be completed as a project while the wider approach continues. NIST describes implementation as a journey and expects most organisations to run a mix of zero trust and perimeter security for an indefinite period.

Is zero trust suitable for a small business?

Yes. A smaller business can have less legacy to work around, and the principles apply at any size. Check which features your existing licences include, then start with the systems that matter most and the people who reach them.

What does zero trust security cost?

It depends on the licences you already hold, application compatibility, device enrolment, access clean-up, testing, staff support and ongoing management. In Microsoft 365, Conditional Access requires Entra ID P1, which Business Premium includes, and risk-based policies require P2. Check what you already have before choosing additional tools.

Where should we start with zero trust?

Identify your important systems and who uses them, then strengthen sign-ins and remove access that is no longer needed. Pilot access policies and device requirements with a small group before enforcing them for everyone. After that, test application access and segmentation, and review exceptions as you go.

Does zero trust mean we stop trusting our staff?

No, and the name does the approach no favours. Zero trust security is about not granting standing trust to a connection or device, which is a technical decision rather than a judgement about people. Designed well, a known person on a managed device in a normal location gets through quietly, and extra checks appear when something looks unusual.

NEXT STEP

Need help applying zero trust security principles?

Talk to Exodesk about the access controls, device requirements and monitoring your business needs. For a broader starting point, an IT assessment looks at your systems, access and licences, whether or not you work with us. We support businesses in Christchurch, Dunedin and across New Zealand.

Or read more about our cyber security services.

Start typing and press Enter to search

One person and a team both connected to the same business computer, showing the outsourcing choiceA door that needs a password and a phone to open, beside a password on its own that opens nothing Call Us Now