
Sanjeev Shukla at Accenture shares some tips on building a true zero-trust environment
Business’ IT environments used to resemble a castle – thick walls, a moat and a drawbridge to ensure that those you trusted could be let in, but anyone up to no good was kept firmly out. And once you were in the castle, you were mostly free to roam around as you pleased.
The past several years have seen a change to the ‘castle-like’ defence paradigm. Businesses of all sizes – from the independent small office to the world’s largest companies – have had to adapt the way they worked, creating a rapid shift to the cloud and an increased use of SaaS.
Now, IT environments resemble something more like the London Underground, with thousands of entry points and interconnected tunnels.
It’s thanks to this that the idea of ‘zero-trust’ has recently created a real buzz across the security industry. However, it’s an overused and often misunderstood term. CISO Role have latched on, some even repackaging old gear as an answer to ‘zero-trust’ security.
Most companies that are interested in zero-trust may be stuck in the planning or strategy phase. Why? The reality is that achieving true zero-trust is an incredibly complex journey.
Zero trust is a term for an evolving set of cybersecurity paradigms that move defences from static, network-based perimeters to focus on users, assets, and resources, rather than network connections and traffic.
The model assumes no implicit trust is granted to a device or a user based solely on their physical or network location (i.e., local area networks versus the internet) or based on device ownership (enterprise or personally owned).
Each access request to a particular resource is assessed with the context of a user’s entitlements, their device and connection. Based on such a dynamic assessment, a user is trusted to access specific resources for a limited period. There is no implicit trust based on static attributes.
The model assumes that threat landscape is constantly changing, and attack surface remains vulnerable so nothing can be permanently trusted. It is a mindset shift for IT and Security professionals, who are used the castle-like defences. Understanding this is important for security leaders looking to achieve zero-trust.
Many security providers have presumably jumped on the bandwagon, rushing to release products that promise to create a zero-trust environment. It’s not hard to see why, as the benefits of zero trust environments are obvious.
However, implementing a zero-trust environment may prove to be an extremely complex and not as easy as plugging in a tool.
The reality is that trust needs to be refactored across both at network and application level. Adding to the complexity is that existing enterprise software is also often built on pre-written trust paradigms that may not be be easily recoded. Front-runners in the space have custom-coded everything from the ground up vs. using commercially off-the shelf (COTS) applications, but this isn’t necessarily a possibility for the vast majority without the time, resources, or skills at their disposal.
Many organisations are now possibly getting to an inflection point where they’re realising that if they do need to refactor their systems then they must do it before it’s too late to turn back – but they might need help understanding when and how, and whether it’s worth it for them.
Unfortunately, as far as we are aware, there is no one simple plug-in solution for implementing zero-trust across an organisation, and it shouldn’t be viewed in that way. It requires a mind-set shift and agility. While there may not be one simple solution, there are some basic, fundamental principles that need to be in place to create a truly agile, zero-trust environment:
The need for zero-trust approach has arisen due to the complex cyber security landscape organisations now find themselves in. This landscape itself keeps evolving and adapting by the day, so simple plug-in one-stop solutions will not work.
Organisations need to design an approach that works for their business; an approach robust enough to withstand bad actors, yet agile enough to evolve as required.
Sanjeev Shukla is security lead for financial services at Accenture in the UK. Article copyright © 2022 Accenture. All rights reserved. Accenture, and its logo are trademarks of Accenture.
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543