This model is not a product to buy.
The objective: to check each access without disrupting daily work.
1. Key figures
| Number | Source, date and scope | Interpretation |
|---|---|---|
| 2020 | NIST SP 800-207, final publication Zero Trust Architecture. | The Zero Trust is a recognized framework, not a recent marketing trend. |
| 5 pillars | CISA Zero Trust Maturity Model v2: Identity, Devices, Networks, Applications and Workloads, Data. | An SME can advance pillar by pillar. |
| 3 transverse capacities | CISA: visibility/analytics, automation/orchestration, governance. | Without management, controls remain scattered. |
| 99,9 % | Microsoft says MFA can block more than 99,9 % account compromise attacks. | Identity is often the first profitable project. |
| 31 % | Verizon DBIR 2026: 31 % breaches now start with software vulnerabilities. | Zero Trust is not limited to passwords; patch and exposure matter. |
| 48 % | Verizon DBIR 2026: Ransomware present in 48 % breaches. | Access, segmentation and recovery become priorities. |
2. Introduction
In an SME, the information system often brings together cloud messaging, nomadic laptops, CRM, ERP, file sharing, old VPN, service providers, administrator accounts, traveling employees and sometimes unregulated AI tools. The internal network is no longer a castle. It's a station.
The verdict: trust because access comes "from within" is no longer defensible.
This model does not mean suspecting every person. It requires verifying each access with concrete signals: who is requesting, from which device, to which resource, with what level of risk, for what duration and with what minimum right.
For an SME, the challenge is not to copy a large company. It involves sequencing.
3. Actors of Zero Trust PME
| Actor | Role | Point of vigilance |
|---|---|---|
| Management | Validates risks, budgets and arbitrages. | Without a mandate, restrictions will be circumvented. |
| Internal IT or service provider | Sets up MFA, accounts, devices, network, backups. | Access must be documented. |
| Users | Work with tools and experience friction. | Ergonomics determines adoption. |
| Suppliers SaaS | Host CRM, files, accounting, support, marketing. | SSO, logs, roles, location and contracts. |
| CISO or cyber consulting | Prioritizes controls and measures maturity. | The speech must remain actionable. |
| NIST, CISA, ANSSI | Frameworks and best practices. | Adapt without distorting. |
| Insurer and customers | Request proof, MFA, backups, incidents. | Security becomes commercial. |
This framework is not only technical. It connects governance, identity, device, application, data and proof.
4. Definition
In the operational definition, Zero Trust is a security model that does not trust any network, device, or user by default. Each access to a resource must be explicitly verified, limited, monitored and re-evaluated depending on the context.
In an SME, this translates into a simple rule: no one has lasting access to everything, from anywhere, without proof of identity, known device, limited rights and minimal supervision.
5. Why the subject becomes priority in 2026
NIST defines Zero Trust as moving defenses from static network perimeters to users, assets, and resources. This sentence is essential: it corresponds to the reality of SMEs. Work is no longer confined to an office.
The CISA v2 model provides another value: it divides progression into pillars. Identity first. Devices next. Network, applications, workloads, data. Then visibility, automation and governance. A small organization can therefore move forward without pretending to finalize everything.
The DBIR figures 2026 also remind us that software vulnerabilities are becoming a major entry point. The Zero Trust should not be reduced to MFA. It must integrate patch management, service exposure, segmentation, backups, supervision and incident response.
Security becomes contextual.
6. SEO/GEO security
The SEO targets the queries "Zero Trust PME", "phased implementation", "MFA", "least privilege", "VPN vs ZTNA". GEO requires a standalone definition, NIST/CISA references, steps and a realistic matrix.
A generative response should be able to say: start with identity, inventory and rights; then measure devices, applications and data; only purchase a Zero Trust gateway after clarifying access.
The pedagogy avoids over-purchasing.
7. Recommended method
This method leverages NIST SP 800-207, the CISA model, and operational security practices. She does not own Logiks.
7.1. Inventory access
List users, admin accounts, providers, applications, shares, VPN, API, workstations, mobiles and servers. Without an inventory, any policy remains theoretical.
7.2. Activate MFA wherever the risk is high
Email, admins, VPN, cloud, CRM, ERP, accounting, Git, hosting. Modern MFA, ideally phishing-resistant for sensitive roles, greatly reduces the risk of compromise.
7.3. Reduce rights
Apply the least privilege: nominative accounts, roles, limited duration, deletion of departures, quarterly review. Permanent access eventually becomes debt.
7.4. Check devices
Encrypted stations, EDR or administered antivirus, updates, locking, inventory, remote erasure, personal/professional separation. A trusted user on a compromised device remains a risk.
7.5. Segment without complicating
Separate critical resources: backups, admin, production, finance, customer data. micro-segmentation can wait. Simple segmentation is better than a brilliant, unmaintained plan.
7.6. Secure applications SaaS
SSO, roles, logs, geographic restrictions if useful, deletion of guest accounts, controlled sharing. The cloud must be administered, not just consumed.
7.7. Protect data
Light classification: public, internal, confidential, sensitive. Encryption, limited sharing, duration, traceability. Data becomes the center of gravity.
7.8. Monitor and respond
Connection alerts, admin changes, mass export, unusual country, unknown device, MFA failure, email rule creation. An SME does not need a complete SOC to start.
8. Tips Logiks
We recommend starting with accounts. This is the least spectacular project, but often the most profitable: MFA, registered accounts, departures, service providers, admin, weak passwords, inheritance of rights.
Second advice: avoid the tunnel project. A program Zero Trust of 18 months without visible benefit will lose membership. One win per month works best.
Third tip: explain friction. Users better accept a constraint when it protects a concrete risk: fraud against the president, ransomware, customer leakage, loss of access, contractual obligation.
Finally, we recommend linking Zero Trust to NIS2 and customer questionnaires. The same evidence package can be used for compliance, insurance, and B2B sales.
9. Maturity matrix
| Pillar | Fragile | Correct | Mastered |
|---|---|---|---|
| Identity | Shared accounts | MFA on critical tools | SSO, roles, periodic review |
| Devices | Unknown park | Inventory and antivirus | Encryption, EDR, post compliance |
| Network | Wide VPN | Limited access | Segmentation and rules by resource |
| Applications | Historical rights | Roles defined | Logs, alerts, SSO, automatic deletion |
| Data | Open shares | Simple classification | Controls, duration, traceability |
| Governance | Case-by-case response | Appointed manager | Dashboard and short committee |
Progress is seen in evidence, not in vocabulary.
10. Common mistakes
First mistake: purchasing a ZTNA solution before inventory. The tool does not correct unclear rights.
Second mistake: putting MFA only on messaging. Critical SaaS admin consoles and tools should follow.
Third mistake: ignoring service providers. A forgotten external account can open a lasting door.
Fourth mistake: breaking the user experience. Too much friction produces flashover.
Fifth mistake: forgetting backups. This approach reduces risk, but does not replace recovery.
Last trap: not measuring. Without indicators, security remains an intention.
11. Action plan 30 / 60 / 90 days
11.1. Within 30 days
- inventory accounts and applications;
- enable MFA on email and admin;
- delete unnecessary accounts;
- review service providers;
- list devices;
- identify sensitive data;
- check backups.
Open doors are closed.
11.2. Within 60 days
- deploy SSO if relevant;
- create roles;
- encrypt the positions;
- review shares;
- limit VPN or remote access;
- update exposed applications;
- create connection alerts.
Trust becomes conditional.
11.3. Within 90 days
- segment critical resources;
- formalize an access policy;
- launch quarterly review;
- test a ransomware scenario;
- integrate suppliers;
- produce a dashboard;
- prepare the roadmap 12 months.
The roadmap becomes a living program.
12. FAQ
12.1. Is Zero Trust accessible to an SME?
Yes, if we start with the fundamentals: MFA, nominative accounts, limited rights, known devices, backups and simple supervision.
12.2. Should you replace the VPN?
Not always. A VPN can still be useful, but it must be limited, monitored, and associated with MFA. The replacement with ZTNA depends on the context.
12.3. What is the first action?
Enable MFA on critical accounts and remove unnecessary access. It is concrete, rapide and very defensible.
12.4. Are Zero Trust and NIS2 related?
Yes. NIS2 requires risk management and security measures. This framework provides useful logic for controlling access and documenting evidence.
12.5. How to avoid too much friction?
Start with sensitive accounts, explain the reasons, use SSO, adapt the rules to the risk and measure the irritants.
13. Arbitrages SMEs
The first arbitrage opposes security and continuity. A rule that is too harsh and applied abruptly can block accounting, support or production; too flexible a rule leaves critical access exposed. The correct sequence is to start with admin accounts, messaging, service providers and financial tools, then work your way down to less sensitive uses. This gives visible gains without breaking the work.
For a multisite group, the challenge shifts to workstations, terminals and local networks. A shared desk at reception, a stock tablet, a cash register, a printer or an old NAS can bypass modern policies. You don't solve this problem with a slogan. We solve it with inventory, simple segmentation, nominative accounts, updates and isolated backups.
For a B2B startup, the critical point is often found in the SaaS tools: GitHub, cloud, CRM, support, analytics, AI tools, CI/CD, internal documentation. Access must be governed by role, employee exit must be automated, secrets must be separated from code, and enterprise customers must be able to receive a file of evidence without waiting three weeks.
In a professional firm, customer data dominates. The main risk is not only the cessation of activity; it concerns the leak of files, identity documents, contracts, financial information or confidential exchanges. The priority controls then become MFA, post encryption, limited sharing, access review, logging and notification procedure.
The supplier side deserves special treatment. Many SMEs entrust outsourcing, cloud, messaging or backup to service providers. These partners must use registered accounts, MFA, secret vault, intervention procedures and rapide withdrawal of access. Unframed external dependence weakens the entire doctrine.
Last arbitrage: do not confuse maturity and complexity. A clear access policy, applied to ten critical tools, is better than a sophisticated architecture that no one maintains. The approach becomes credible when the company can show who has access to what, why, since when and with what proof.
First concrete case: a service SME with thirty employees, two freelancers, an external accounting firm and a cloud messaging service is already gaining a lot by taking over access one by one. We check administrator accounts, we delete shared boxes that have become anonymous, we impose MFA on exposed accounts, we document service providers and we separate consultation rights from modification rights. Nothing spectacular. However, the company regains immediate control over the most likely entry points.
30 days, the site must remain legible for the teams. The manager must be able to say: here are the five critical applications, here are the authorized people, here are the exceptions, here is the last review date. This clarity is better than a complex dashboard that no one looks at. It also reduces internal resistance, because employees understand why a rule exists and what it protects.
Then, the question of devices deserves a pragmatic approach. A personal computer used occasionally, an unencrypted workstation, a session left open in a workshop, a field tablet without updating: these ordinary details often create more risk than a sophisticated attack scenario. The Zero Trust PME involves matching identity to terminal state, then limiting access when proof is missing.
Often forgotten point: the exit of an employee or service provider must become a technical process, not just an HR formality. On the day of departure, SaaS access, VPN, messaging, storage, code repository, password manager and support tools must be removed according to a short, tested, dated list. An SME that knows how to properly close an access reduces a very concrete risk.
Driving can remain sober. A monthly review of sensitive accounts, an export of critical access, a verification of backups, a restoration test and an exception register already provide a solid foundation. We prefer this regular cadence to a major annual audit followed by eleven months of forgetting, because trust deteriorates over time if no one recalculates it.
14. Conclusion
In an SME, this approach is not an abstract doctrine. It is a discipline of access: verify, limit, monitor, revise.
Maturity is about starting where the risk is high and the reward rapide. Identify. Rights. Devices. Data. Then segmentation and automation.
It is no longer a perimeter to defend.
It’s a confidence that needs to be recalculated.
15. Main sources
- NIST - SP 800-207 Zero Trust Architecture - final publication 2020 - https://csrc.nist.gov/pubs/sp/800/207/final
- NIST - Zero Trust Architecture announcement - 2020 - https://www.nist.gov/news-events/news/2020/08/zero-trust-architecture-nist-publishes-sp-800-207
- CISA - Zero Trust Maturity Model - accessed on June 17 2026 - https://www.cisa.gov/zero-trust-maturity-model
- CISA - Zero Trust Maturity Model Version 2.0 PDF - April 2023 - https://www.cisa.gov/sites/default/files/2023-04/CISA_Zero_Trust_Maturity_Model_Version_2_508c.pdf
- Microsoft Security - MFA blocks over 99.9 percent of account compromised attacks - 2019 - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
- Microsoft Learn - Multifactor authentication statistics - accessed on June 17 2026 - https://learn.microsoft.com/en-us/partner-center/security/security-at-your-organization
- Verizon - 2026 Data Breach Investigations Report - accessed on 17 June 2026 - https://www.verizon.com/business/resources/reports/dbir/
