Zero trust for the mid-market: a 90-day path
You do not need an enterprise security budget to close the gaps attackers actually use. You need to sequence by risk reduced per rupee, and start with identity.
01Days 1–30: identity, because that is the front door
The overwhelming majority of intrusions we are asked to review began with a credential, not an exploit. Phishing, reuse, or a stale account belonging to someone who left. This is where the first month goes, and it produces more risk reduction than anything else on the list.
Concretely: consolidate to a single identity provider, enforce phishing-resistant multi-factor authentication for all administrative access, remove standing privileged access in favour of just-in-time elevation, and run a joiner-mover-leaver audit. That last one routinely surfaces active accounts for people who left months ago.
02Days 31–60: device posture and the administrative plane
Next, establish what a trusted device is and require it for privileged operations. Managed, encrypted, patched within an agreed window, endpoint detection running. Unmanaged devices can retain access to low-sensitivity systems; they should not be able to reach the administrative plane of anything.
In the same window, separate administration from daily work. Administrative actions from a dedicated context - a separate account and ideally a separate workstation profile - removes an entire class of attack in which a compromised browser session becomes infrastructure access.
03Days 61–90: segmentation where it pays
Full micro-segmentation is a multi-year programme and is not the mid-market answer. What is achievable in thirty days is isolating the crown jewels - the customer database, the payment path, the backup infrastructure - behind their own controls with explicit allow-lists and logged access.
Backups deserve specific attention. Ransomware response is entirely determined by whether your backups were reachable from the compromised network. Immutable, credential-isolated, and restore-tested. An untested backup is a hypothesis.
At the end of ninety days you will not be 'zero trust'. You will have closed the paths that are actually used, with evidence, and you will have a defensible sequence for the next ninety.
Written by the Armonix Solutions delivery team. If you are working through this problem right now, send us the specifics — a 30-minute conversation is usually more useful than another article.
