Skip to main content
Armonix Solutions logo
All insights
Security2 June 202610 min read

Zero trust for the mid-market: a 90-day path

You do not need an enterprise security budget to close the gaps attackers actually use. You need to sequence by risk reduced per rupee, and start with identity.

01Days 1–30: identity, because that is the front door

The overwhelming majority of intrusions we are asked to review began with a credential, not an exploit. Phishing, reuse, or a stale account belonging to someone who left. This is where the first month goes, and it produces more risk reduction than anything else on the list.

Concretely: consolidate to a single identity provider, enforce phishing-resistant multi-factor authentication for all administrative access, remove standing privileged access in favour of just-in-time elevation, and run a joiner-mover-leaver audit. That last one routinely surfaces active accounts for people who left months ago.

02Days 31–60: device posture and the administrative plane

Next, establish what a trusted device is and require it for privileged operations. Managed, encrypted, patched within an agreed window, endpoint detection running. Unmanaged devices can retain access to low-sensitivity systems; they should not be able to reach the administrative plane of anything.

In the same window, separate administration from daily work. Administrative actions from a dedicated context - a separate account and ideally a separate workstation profile - removes an entire class of attack in which a compromised browser session becomes infrastructure access.

03Days 61–90: segmentation where it pays

Full micro-segmentation is a multi-year programme and is not the mid-market answer. What is achievable in thirty days is isolating the crown jewels - the customer database, the payment path, the backup infrastructure - behind their own controls with explicit allow-lists and logged access.

Backups deserve specific attention. Ransomware response is entirely determined by whether your backups were reachable from the compromised network. Immutable, credential-isolated, and restore-tested. An untested backup is a hypothesis.

At the end of ninety days you will not be 'zero trust'. You will have closed the paths that are actually used, with evidence, and you will have a defensible sequence for the next ninety.

Written by the Armonix Solutions delivery team. If you are working through this problem right now, send us the specifics — a 30-minute conversation is usually more useful than another article.

Tell us what is not working. We will tell you what it takes.

A stalled migration, a platform that will not scale, an audit finding you cannot close, or a team stretched past its limit. Start with the problem - the engagement model can follow.

What happens next

  1. 01

    A reply within one working day

    From a consultant, not an auto-responder or a sales sequence.

  2. 02

    A 30-minute scoping call

    We establish whether we are the right fit. Sometimes the answer is no, and we say so.

  3. 03

    A written proposal

    Scope, sequence, team, commercials and assumptions - in plain language.

No NDA needed for a first conversation. If you would rather send a brief first, email is fine.