All Posts

Best Practices

7 min read

 read

Zero Trust Security: Why Perimeter Defense Is No Longer Enough

Traditional perimeter-based security is failing modern organizations. Discover why Zero Trust is the new standard and how to implement it effectively.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Published

01 Mar 2026

Aktualisiert

29 Sep 2026

Introduction

The concept of a secure network perimeter, a hard shell protecting a soft interior, has been the cornerstone of enterprise security for decades. But in today's world of cloud services, remote work, and sophisticated threat actors, that model is fundamentally broken.

Zero Trust architecture operates on a simple but powerful principle: never trust, always verify. Every user, device, and connection must be authenticated and authorized, regardless of where it originates.

Key Takeaways

  • Perimeter-based security is no longer sufficient for modern hybrid environments.
  • Zero Trust requires continuous verification of every user and device.
  • Implementation should be phased, starting with critical assets.
  • Identity is the new perimeter in a Zero Trust model.

Why the traditional perimeter no longer holds

The castle-and-moat approach assumed everything inside the network was safe. Anyone who cleared the outer wall counted as trusted. That held up while people worked at fixed desks, applications ran in your own data center, and external access was the exception.

None of those conditions apply now. People work from home, applications sit with cloud providers, and external service providers maintain systems remotely. The perimeter has not disappeared; it has become permeable. And it stops protecting you at exactly the moment it matters: an attacker who gets in on stolen credentials moves freely inside the trusted zone. That lateral movement is what turns one compromised account into a full outage.

Two architectures side by side: on the left the traditional perimeter, where every device inside the boundary is automatically trusted; on the right Zero Trust, where each user, device and request is verified individually
Traditional perimeter vs. Zero Trust architecture

Core principles of Zero Trust

Zero Trust is built on three foundational pillars:

  • Verify explicitly: Authenticate and authorize based on every available signal – identity, device posture, location, time, and the sensitivity of the target system.
  • Use least privilege access: Limit access with just-in-time and just-enough-access principles. The principle of least privilege is the part of Zero Trust that erodes fastest in day-to-day operations.
  • Assume breach: Minimize blast radius, segment access, and verify end-to-end encryption.

Zero Trust is not a product you can buy; it is an architectural decision. An organization that procures a single tool and considers the matter closed has not shrunk its attack surface, only improved its documentation.

Zero Trust, ZTNA and VPN: the difference in practice

A VPN establishes a network connection. Once you dial in successfully you are on the network and can reach, in principle, whatever is reachable there. The access decision is made exactly once, at connection time.

Zero Trust Network Access (ZTNA) inverts that: what gets released is not the network but the individual application or target system. The decision is made per access and re-evaluated during the session. In practice, a compromised laptop no longer comes with access to the entire subnet attached.

For administrative access that difference matters most. Running remote maintenance over a VPN plus RDP, SSH or VNC grants network access rather than system access, and with it goes any record of what actually happened during the session.

Identity becomes the new perimeter

When the network edge loses its protective value, identity takes its place. Every access decision then rests on whether a person or system can prove who they are, and whether the permission being requested fits the task at hand.

Multi-factor authentication is the floor here, not the goal. What matters is that verification happens not only at sign-in but again at the start of every privileged session. That is the point where privileged access management plugs into a Zero Trust architecture.

Zero Trust for privileged access

Most Zero Trust programs start with employee endpoints. That is understandable, but it leaves the most dangerous accounts until last: administrators, service accounts, and external providers holding far-reaching rights.

For those accounts Zero Trust means something concrete: no permanently granted admin rights, but approvals on request with a clear expiry. The target state is zero standing privileges – no account holds elevated rights at rest. A stolen password then opens no privileged path, because at the moment of theft none exists.

Then there is evidence. Zero Trust tells you to assume breach, and an organization that assumes breach needs records that can reconstruct who did what, and when. Gap-free session recording of privileged access is therefore part of the model, not an add-on.

Zero Trust in OT and remote maintenance environments

In production and control technology the model meets different constraints. Plants run for decades, many systems cannot be patched, and agents on target systems are frequently not permitted at all. An agentless access point placed in front of the existing infrastructure is usually the only workable route.

The BSI IND.3.2 building block on remote maintenance in industrial environments describes exactly these requirements: need-based approval, restriction to the individual target system, and documented traceability. That is Zero Trust written in the language of plant safety.

Implementing Zero Trust step by step

A successful rollout starts with understanding your current state. This order has proven itself in practice:

  1. Map critical assets. Which systems would halt operations or expose reportable data?
  2. Make access paths visible. Who reaches those systems today, with which rights, and by what route? External providers count explicitly.
  3. Strengthen identity verification. MFA on every administrative path, tied to your central identity system rather than a separate user directory.
  4. Remove standing rights. Replace permanent administrator accounts with time-limited approvals.
  5. Segment. Scope access to the individual target system rather than to whole network segments.
  6. Log and review. Records are only worth keeping if they can be found and read during an audit.

The journey is incremental, but the security improvements are immediate. Start with the most sensitive systems and the accounts holding the widest rights, not with the easiest use cases.

What Zero Trust is not

Three misconceptions persist. Zero Trust is not a product you procure and tick off. It is not a replacement for network security but a layer above it. And it does not mean distrusting your own staff: what gets verified is the individual access, not the person, because credentials get stolen and devices get compromised without their owner noticing.

Zero Trust and regulatory requirements

Zero Trust rarely appears by name in legislation, though its components do. The minimum measures under § 30 BSIG, Germany's implementation of NIS-2, require access control, multi-factor authentication, supply chain security and auditability. An organization that implements Zero Trust seriously satisfies those points as a by-product – and can demonstrate it when audited.

Contact

Your Direct Path to Secure Remote Access

Speak directly with a cybersecurity expert.

Personal Meeting
Personal Meeting
Personal Meeting

Conclusion

Zero Trust isn't a trend, it's a necessary evolution in how we think about security. Organizations that adopt this mindset will be far better positioned to withstand the attacks of today and tomorrow. Start small, stay consistent, and never stop verifying.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Jan has over 12 years of consulting experience at PwC and Ernst & Young, focusing on information security and compliance for critical infrastructure and the automotive industry. As a certified ISO 27001 Lead Auditor and strategy expert, he advises organizations on establishing and auditing security management systems in accordance with ISO 27001 and TISAX.