Zero Trust
Zero Trust is an architecture, not a product: every request is checked against who is asking, from what device, for what, and under what conditions. We help you get there in practical steps, starting with what you already own.
- Security & compliance
- Zero Trust
- Covers
- Architecture and roadmap, identity, device and network controls, monitoring
- Serves
- Onsite in New Mexico; remote engineering nationwide
Four Directions helps design and implement technology that supports security and compliance objectives. We do not provide legal advice, and we do not assess or certify compliance.
What changes
Traditional networks trust whatever is inside the perimeter. Once an attacker, or a compromised laptop, is inside, it can usually reach far more than it should. Zero Trust removes that implicit trust: access is granted per request, to one resource, based on identity, device health and context, and it’s re-evaluated as conditions change.
The pillars
CISA’s Zero Trust Maturity Model and DoD’s Zero Trust strategy both organize the work into pillars. In practice:
Identity
One identity per person, phishing-resistant multifactor authentication, least privilege and just-in-time administrative access.
Devices
Only managed, healthy devices reach company resources, and device health is part of every access decision.
Applications and workloads
Access per application rather than per network, secure configurations and strong authentication between services.
Data
Know where sensitive data lives, label it, and control sharing and downloads.
Networks
Segment so that one compromised system can’t reach everything, encrypt traffic, and replace broad VPN access where it makes sense.
Infrastructure
Hardened servers, hypervisors and cloud accounts, with administrative access separated and monitored.
Visibility and analytics
Central logs and alerts that someone actually reviews.
Automation and orchestration
Policies enforced consistently by tools rather than by memory.
Where to start
- Inventory People, devices, applications and where sensitive data lives.
- Strong identity Multifactor authentication everywhere, phishing-resistant for administrators, and no shared accounts.
- Device trust Manage and assess devices, and require healthy devices for sensitive applications.
- Least privilege Separate administrator accounts and remove standing access nobody needs.
- Segment and monitor Break up flat networks, log centrally and review what you collect.
Most organizations already own part of what they need, in Microsoft 365, in their firewall or in their endpoint tools. We start there before recommending anything new.
What Zero Trust isn’t
- A single product you can buy. Vendors sell components; the architecture is how they work together.
- A one-time project. Policies and signals keep evolving with your business.
- Only for large enterprises. Small organizations often get further faster, because they have fewer systems.
- A replacement for compliance requirements. It supports frameworks such as NIST SP 800-171, but doesn’t replace them.
Questions we hear
Do we have to replace our VPN?
Not necessarily, and not first. Many organizations keep a VPN for some uses while moving important applications behind identity- and device-aware access. Where a broad VPN gives everyone access to everything, narrowing it is often a quick win.
How long does it take?
The first steps, such as multifactor authentication everywhere and separate administrator accounts, usually take weeks. A full Zero Trust architecture is a multi-year roadmap for most organizations, delivered in useful stages.
Does Zero Trust help with CMMC?
Many Zero Trust practices, including multifactor authentication, least privilege, device management, segmentation and logging, also support NIST SP 800-171 requirements. They’re complementary, and we design them together.
What standards do you follow?
NIST SP 800-207 defines Zero Trust architecture, and CISA’s Zero Trust Maturity Model describes stages of progress. We use them as references, scaled to the size of your organization.
Sources: NIST SP 800-207, Zero Trust Architecture; CISA Zero Trust Maturity Model.
Discuss a Zero Trust roadmap
Tell us what you run today and what worries you most. We’ll suggest the first practical steps.