Every security vendor now sells a “Zero Trust” solution. Every conference talk mentions it. Every CISO job description requires it. But what does Zero Trust actually mean for a 20-person company with a single office and cloud-based tools?
At Metaluxo we design security architectures for SMEs. Zero Trust is a valuable framework, but only when applied proportionately. This post separates the principles from the marketing.
What Zero Trust actually means
Zero Trust is not a product. It is a set of principles:
- Never trust, always verify. Every access request is authenticated and authorised, regardless of where it comes from.
- Assume breach. Design your systems as if an attacker is already inside the network.
- Least privilege. Users and systems get the minimum access they need, for the minimum time.
- Verify explicitly. Use multiple signals (identity, device health, behaviour) to make access decisions.
These principles are sound. The problem is that vendors have turned them into a product category that requires enterprise budgets and dedicated teams to implement.
What Zero Trust looks like for an SME
An SME does not need a Zero Trust Architecture with capital letters. It needs the principles applied practically:
| Enterprise Zero Trust | SME Proportionate Equivalent |
|---|---|
| Micro-segmentation with software-defined perimeters | VLANs and firewall rules between office and production |
| Continuous adaptive risk and trust assessment | MFA + device management + conditional access on cloud apps |
| Privileged access management (PAM) platform | Separate admin accounts with hardware keys |
| Security orchestration, automation and response (SOAR) | Documented incident response plan with a 24-hour contact |
| Network access control (NAC) | Guest WiFi separate from corporate network |
The SME equivalent is not a lesser version. It is the right version for the risk profile and budget.
The performative trap
The biggest mistake SMEs make with Zero Trust is buying enterprise tools they cannot configure or maintain. A poorly configured SIEM generates alerts that nobody reads. An over-engineered network segment breaks workflows and drives users to bypass controls.
The right approach:
- Start with identity — MFA on every account, admin accounts separate
- Add device context — managed devices for work, no personal devices on corporate resources
- Segment by data sensitivity — customer data on restricted systems, public marketing content on open systems
- Monitor what matters — failed logins, data exports, privilege escalation
- Review quarterly — access rights, device compliance, network rules
At Metaluxo we design proportionate security architectures for SMEs. If Zero Trust vendors are telling you what you need to buy but not what you actually need to do, book a free 30-minute consultation and we will design an architecture that fits your size.