A security model that assumes no implicit trust, even inside the network, and verifies each access according to identity and context.
Zero trust architecture is a security model that breaks with the traditional fortress approach, which protected a perimeter and trusted, by default, everything inside it. Starting from the observation that the perimeter has dissolved, with the cloud, remote work and the proliferation of devices, the guiding principle becomes never trust, always verify. Every request to access a resource is authenticated, authorized and assessed according to the user's identity, the state of their device and the context, regardless of position in the network. The aim is to limit an attacker's lateral movement, that is, their ability, once inside somewhere, to move freely toward sensitive resources. Network microsegmentation and the application of least privilege are key components of it. For insurance, adopting a zero trust approach is a strong signal of security maturity, which reduces the potential scale of a loss by compartmentalizing access, even though its full implementation remains demanding and progressive rather than a state one would reach in one go.
In a zero trust organization, an attacker who manages to compromise an employee's workstation cannot thereby reach the critical servers, because each new access requires a verification that their stolen credentials are not enough to pass.
zero trust, zéro confiance, architecture zéro confiance