Skip to content
L&M Cybersecurity

Architecture

Zero trust beyond the buzzword: a realistic 90-day path

Zero trust programmes fail when they start as an architecture diagram. Here is the sequence that survives contact with a real organisation.

L&M Advisory 9 min read

Zero trust is not a product you buy, and it is not a project you finish. It is a set of assumptions applied progressively: no implicit trust from network location, verification on every request, least privilege by default.

Days 1–30: see what you have

Nothing works without an accurate identity inventory. Enumerate every human account, service account, API key and integration. Map which of them can reach production data. In almost every assessment, this stage alone finds accounts nobody can explain — usually with more privilege than the people asking about them.

Days 31–60: harden the front door

Migrate to phishing-resistant authentication for administrators first, then all staff. Implement conditional access with device compliance as a signal. Kill legacy authentication protocols that bypass your policies. Expect this to be the politically hardest phase; it touches everyone.

Days 61–90: reduce the blast radius

Introduce just-in-time elevation so standing admin rights disappear. Segment your highest-value systems so that a compromised workstation reaches a wall rather than a database. Begin access reviews with real owners rather than a rubber-stamp workflow.

What comes after

Ninety days does not finish zero trust — it establishes the foundation the rest depends on. Micro-segmentation, continuous authorisation and data-centric controls all become viable once identity is trustworthy. Attempting them first is why so many programmes stall in year two.

Seeing something similar in your environment?

Talk to our team

Next step

Find out what an attacker sees before they show you.

Book a scoping call with a senior consultant. No sales engineer, no slide deck — a technical conversation about your actual exposure.