Zero Trust for UK SMEs: a practical, affordable path
Zero Trust is not a product. Here is the order to implement it in when you have a small team and a real budget.
By the Telappliant team

Zero Trust has a reputation for being an enterprise programme with an enterprise budget. It is not. For a UK SME it is a sequence of sensible decisions, most of which you can make with licences you already own.
The principle in one paragraph
Stop assuming that being inside the network, or holding a valid password, means someone should be trusted. Verify identity explicitly, check the device is healthy, grant the least access needed, and assume a breach will happen so you limit what one compromised account can reach.
Start with identity, because that is where attacks start
- Enforce phishing-resistant MFA for every user, with no standing exceptions
- Block legacy authentication protocols that bypass MFA entirely
- Use conditional access to challenge risky sign-ins and impossible travel
- Remove permanent global administrator rights and grant them just in time
- Review guest and third-party accounts quarterly and remove the dormant ones
Then prove the device is trustworthy
Access from an unmanaged, unpatched laptop is the same risk whether the person is genuine or not. Enrol devices in Intune, require disk encryption and current patch levels, and make compliance a condition of access to email and files. This single control stops most credential theft turning into data theft.
Segment what an attacker can reach
- Separate corporate, guest, voice, CCTV and operational networks
- Restrict administrative interfaces to a dedicated management network
- Apply least privilege to file shares and SharePoint, not just to servers
- Turn off open internal sharing links and external sharing by default
Assume breach and prepare to see it
Zero Trust assumes something will get through. That means logging that is retained long enough to investigate, alerting that reaches a human out of hours, and a rehearsed incident response plan. Detection without a responder is a dashboard, not a control.
A realistic order of implementation
MFA and legacy auth first, then device compliance, then privileged access, then segmentation and monitoring. Each stage reduces meaningful risk on its own, so a stalled programme still leaves you better protected. Aim for a quarter per stage rather than a big bang.



