Zero Trust Security Architecture
Zero Trust vs Traditional Security: Key Differences
Traditional security trusts the internal network and defends the perimeter (castle-and-moat). Zero trust trusts nothing and verifies everything. Key differences: trust model (implicit inside perimeter vs never implicit), access control (network-based vs identity-and-context-based), lateral movement (unrestricted internally vs micro-segmented), verification (one-time at perimeter vs continuous), and scope (network-centric vs identity-and-data-centric). Zero trust is more effective for cloud, remote work, and modern threats.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
Two Fundamentally Different Models
Traditional security and zero trust represent fundamentally different approaches to the same question: how do you protect organizational resources from unauthorized access?
Traditional Perimeter Security
The Model
Traditional security divides the world into two zones:
- Untrusted zone. The internet and external networks. Threats come from here.
- Trusted zone. The internal network. Users and devices here are considered safe.
Security controls focus on the boundary between these zones: firewalls filter traffic, VPNs authenticate remote users into the trusted zone, intrusion detection monitors perimeter traffic.
How Access Works
- User connects to the corporate network (physically or via VPN)
- Firewall/VPN authenticates the connection
- User gains broad network access to internal resources
- Internal traffic is largely unmonitored and unrestricted
Strengths
- Simple conceptual model
- Well-understood by IT teams
- Effective when all resources and users are on-premises
- Mature technology ecosystem
Weaknesses
- Lateral movement. Once inside, attackers move freely. The 2020 SolarWinds breach demonstrated how attackers with internal access operated undetected for months.
- Cloud doesn't fit. Cloud workloads aren't behind the firewall. Extending the perimeter to the cloud creates complexity and VPN bottlenecks.
- Remote work breaks it. Remote users VPN into the trusted zone and then access cloud resources — routing traffic through the data center instead of directly to the cloud. Inefficient and brittle.
- Implicit trust is dangerous. Insider threats, compromised credentials, and supply chain attacks all exploit the assumption that internal = trusted.
- All-or-nothing access. VPN grants broad network access rather than granular, resource-specific access.
Zero Trust Security
The Model
Zero trust eliminates the concept of a trusted zone. Every access request — regardless of source — is verified based on identity, device, context, and risk.
How Access Works
- User requests access to a specific resource
- Identity is verified with strong authentication (MFA)
- Device health is assessed (patched, managed, encrypted)
- Context is evaluated (location, time, behavior patterns)
- Access is granted to the specific resource only — not the network
- Session is continuously monitored for anomalies
- Access can be revoked mid-session if risk signals change
Strengths
- Works everywhere. Cloud, on-premises, hybrid, remote — the model is the same
- Limits blast radius. Compromised credentials grant access to specific resources, not the entire network
- Continuous verification. Anomalies detected mid-session can trigger re-authentication or access revocation
- Granular control. Access decisions consider identity, device, location, behavior, and data sensitivity
- Supports modern architecture. Designed for cloud, microservices, and distributed workforces
Weaknesses
- Complexity. More components, more policies, more integration points
- Implementation effort. Requires changes to architecture, processes, and culture
- User experience. More verification can mean more friction (mitigated by adaptive authentication)
- Legacy systems. Older applications may not support modern authentication
Side-by-Side Comparison
| Aspect | Traditional | Zero Trust |
|---|---|---|
| Trust model | Trust the network | Trust nothing |
| Verification | Once, at the perimeter | Continuous |
| Access scope | Broad network access | Specific resource access |
| Lateral movement | Unrestricted internally | Micro-segmented |
| Cloud support | Requires extension (VPN) | Native |
| Remote work | VPN-dependent | Location-independent |
| Threat assumption | Threats are external | Threats are everywhere |
| Data protection | Network-based controls | Data-centric controls |
| Monitoring | Perimeter-focused | Everywhere |
| Breach response | Find and contain | Already contained (micro-segmented) |
When to Transition
Zero trust is not all-or-nothing. Organizations typically transition incrementally:
- Start with identity. Deploy MFA everywhere. This single step addresses the most common attack vector regardless of architecture.
- Add device trust. Assess device health before granting access. Block or restrict access from unmanaged or unhealthy devices.
- Implement conditional access. Make access decisions based on context — location, device, risk level.
- Micro-segment critical resources. Isolate the most sensitive systems so they require explicit authorization regardless of network position.
- Expand progressively. Apply zero trust controls to additional resources, eventually covering the entire environment.
The goal is not to eliminate the firewall — it's to stop relying on it as the primary security control.
How SeqOps fits
Zero trust starts with knowing where you're exposed. SeqOps gives you that view for your cloud accounts and servers: misconfigurations, excessive access and unpatched software, ranked by severity. It doesn't enforce access policies.