Real IT Consulting article cover: Zero Trust and SASE explained for small and medium business

Zero Trust, SASE and the End of the Office Perimeter

For thirty years, network security had a simple mental model: build a strong wall around the office, and treat everything inside it as trustworthy. That model has been dying slowly for a decade and is now, for most organisations, comprehensively dead. This post examines what replaced it, what the vendor terminology actually means, and what any of it means for organisations without a security team.

How the perimeter dissolved

The castle-and-moat model rested on two assumptions: that your applications lived in your building, and that your people did too. Both have failed.

Applications moved to SaaS. Your email is Microsoft's, your files are in SharePoint, your accounting is in the cloud, your CRM is someone else's platform. The firewall at your office cannot protect data that never passes through it.

People moved too — hybrid work, home offices, phones, tablets, and personal devices. And the network itself expanded to include contractors, suppliers with portal access, managed service providers with administrative rights, and an ever-growing population of connected devices nobody is quite responsible for.

The result is that "inside the network" stopped being a meaningful security boundary. What matters now is identity, device posture, and the specific resource being accessed.

Zero Trust, without the marketing

Zero Trust is a design principle, not a product you can buy, despite considerable marketing effort to suggest otherwise. The principle is: never trust based on network location; always verify.

In practice it means three things:

  • Verify explicitly. Every access request is authenticated and authorised using all available signals — who the user is, what device they are on, where they are, what they are asking for, and whether any of that looks unusual.
  • Use least privilege. Grant the minimum access needed, for the minimum time. Just-in-time and just-enough access rather than standing permissions.
  • Assume breach. Design as though an attacker is already inside. Segment, encrypt, monitor, and limit how far any single compromise can spread.

That third principle is the mental shift that matters. The question stops being "how do we keep attackers out" and becomes "when someone gets in, how much can they reach, and how quickly do we know."

Decoding the acronyms

The vendor landscape has produced a thicket of terminology. The ones you will encounter:

SASE (Secure Access Service Edge) — the convergence of networking and security functions into a cloud-delivered service. Rather than backhauling all traffic to a firewall in your office, traffic goes to a nearby cloud point of presence where security policy is applied. Combines SD-WAN with a set of security services.

SSE (Security Service Edge) — the security half of SASE without the networking half. Typically a secure web gateway, a cloud access security broker, and zero trust network access.

ZTNA (Zero Trust Network Access) — the replacement for the traditional VPN. Instead of connecting a user to the network, it connects a specific user on a specific device to a specific application, and nothing else. The difference matters: a compromised VPN credential gives an attacker your whole network; a compromised ZTNA credential gives them one application.

CASB (Cloud Access Security Broker) — visibility and control over what your people do in cloud applications, including the ones IT never approved.

SWG (Secure Web Gateway) — filtering and inspecting web traffic wherever the user is, rather than only when they are in the office.

MDR / XDR — detection and response services that monitor across endpoints, identity and cloud, usually with human analysts attached.

Where small and medium business fits into this

Here is the honest position: most of the above was designed and priced for enterprises. A twenty-person business does not need a SASE platform and cannot sensibly operate one.

But the principles apply at any size, and increasingly the capabilities do too, bundled into platforms smaller organisations already pay for. The practical zero trust roadmap for an SMB looks like this:

Level 1: Identity as the new perimeter

If you do one thing, do this. Identity is where the boundary now sits.

  • Multi-factor authentication on everything, with an authenticator app or passkeys rather than SMS
  • Single sign-on so access is granted and revoked in one place
  • Conditional access rules — block sign-ins from countries you never operate in, require a compliant device for sensitive applications, step up authentication for unusual activity
  • Separate administrative accounts, not used for daily work
  • A real offboarding process that revokes access the day someone leaves

Much of this is included in business productivity suites you may already be licensed for. The most common failure is not cost — it is that nobody turned it on.

Level 2: Device posture

Access decisions should account for what device is asking.

  • Device enrolment and management, so you know what is connecting
  • Disk encryption enforced
  • Patch compliance as a condition of access
  • Endpoint detection and response, not just traditional antivirus
  • Remote wipe capability for lost or stolen devices

Level 3: Segment what remains

You still have a physical network, and it should not be flat. Separate staff, guests, payment systems, and the growing population of connected devices that will never receive a security update. Deny between segments by default.

Level 4: Retire the flat VPN

If you still run a traditional VPN that drops remote users onto the office network with broad access, that is your largest remaining perimeter-era liability. Application-level access is the direction of travel, and ZTNA offerings have become accessible to smaller organisations.

Level 5: Monitor and be able to respond

Logging that nobody reads is not monitoring. Either someone internally owns alert response, or you engage a service that does. The value of detection is entirely in the response time.

The honest caveats

Zero trust is a direction, not a destination, and there is no point at which you are finished. Anyone selling you a product that "delivers zero trust" is selling you a component.

It also introduces friction, and friction has costs. Security that makes work impossible gets circumvented, and a workforce that has learned to route around your controls is less safe than one that never had them. Design for the reality of how your people work.

And it does not remove the need for the basics. Patching, backups, and MFA still prevent more real-world incidents than any architectural sophistication. An organisation with a beautiful zero trust design and untested backups is one bad day from a very bad quarter.

Where to start

If your organisation is somewhere on this journey and unsure of the next step, the sequence is almost always the same: identity first, device posture second, network segmentation third, VPN replacement fourth, monitoring throughout. Each step is independently valuable, which means you can stop at whatever level matches your risk and budget without having wasted the earlier work.

Real IT Consulting helps businesses across the Gold Coast, Brisbane, Logan, Pimpama and Sydney work through this practically — starting with what you already own and are not using, before recommending anything new. Call 0489 940 359 for a cybersecurity check with no jargon and no scare tactics.

Back to blog