Zero Trust has become the most overused term in cybersecurity marketing. Every vendor claims to deliver it. Every framework references it. But after implementing Zero Trust architectures across 170+ South African organisations over the past six years, we've learned that the reality is far more nuanced than the whitepapers suggest.
By Neil Beulecke, Managing Director — Layer7 Networking
Start with Identity, Not Network
The most common mistake organisations make is treating Zero Trust as a network segmentation project. It's not. Zero Trust is fundamentally an identity problem.
Before you segment a single VLAN, you need to answer: who are your users? What devices do they use? What applications do they need? What's their risk profile? If you can't answer these questions with confidence, your segmentation will be based on assumptions — and assumptions are what attackers exploit.
In practice, this means your first investment should be in identity governance: a modern identity provider with conditional access policies, phishing-resistant MFA, and device trust verification. Get this right, and your subsequent segmentation decisions will be grounded in reality rather than guesswork.
Segment Before You Encrypt
We see organisations rush to deploy encrypted tunnels and private access solutions before they've established meaningful network segmentation. The result is encrypted traffic flowing across a flat network — which is arguably worse than the starting position, because now you've lost visibility into lateral movement.
The correct sequence:
- Discover and classify — understand what's on your network, where data flows, and what the dependencies are.
- Segment — create logical boundaries between workloads, environments, and trust levels. Micro-segmentation is ideal but macro-segmentation (separating production from development, OT from IT, management from user traffic) delivers 80% of the value.
- Apply policy — define what traffic is permitted between segments and deny everything else.
- Encrypt — once you have visibility and control, add encryption for sensitive data flows.
Don't Boil the Ocean
Zero Trust is a journey, not a destination. Organisations that try to implement everything simultaneously — identity, segmentation, encryption, continuous verification, device trust, application-level access — typically stall at the planning stage and implement nothing.
Our phased approach delivers measurable risk reduction at each stage:
Phase 1 (Months 1-3): Identity foundation. Deploy modern identity provider, implement conditional access, roll out phishing-resistant MFA for privileged accounts. Measurable outcome: elimination of password-only authentication for administrative access.
Phase 2 (Months 3-6): Network visibility. Deploy network detection and response, establish baseline traffic patterns, identify shadow IT and unsanctioned data flows. Measurable outcome: complete inventory of east-west traffic patterns.
Phase 3 (Months 6-12): Macro-segmentation. Separate critical asset zones, implement firewall policies between segments, deploy application-aware policies. Measurable outcome: lateral movement between segments requires explicit policy approval.
Phase 4 (Months 12-18): Micro-segmentation and continuous verification. Workload-level segmentation, continuous posture assessment, automated policy enforcement. Measurable outcome: blast radius of a compromised endpoint limited to its immediate workload group.
Common Mistakes We See
Buying a "Zero Trust product." Zero Trust is an architecture, not a product. Any vendor selling you a box labelled "Zero Trust" is selling you a component at best, and marketing at worst. You need an architecture strategy, not a purchase order.
Ignoring legacy systems. Your Zero Trust architecture must account for systems that can't support modern authentication — OT environments, legacy applications, mainframes. Wrapping these in compensating controls is essential; ignoring them creates gaps attackers will find.
Forgetting the user experience. If Zero Trust makes people's jobs harder, they'll find workarounds. Shadow IT, personal devices, credential sharing — all the things you're trying to prevent. Every security control must be measured against the friction it introduces.
No metrics. If you can't measure your Zero Trust maturity, you can't demonstrate progress to the board, justify continued investment, or identify gaps. Define your metrics before you start: mean time to detect lateral movement, percentage of applications behind identity-aware proxies, number of overly permissive firewall rules remaining.
The South African Context
Zero Trust adoption in South Africa faces specific challenges. Skills scarcity means organisations can't always staff dedicated Zero Trust teams. Load shedding creates reliability concerns for always-on verification systems. Budget constraints force harder prioritisation decisions. And the regulatory environment (POPIA, sector-specific regulations) adds compliance requirements to every architecture decision.
These aren't reasons to avoid Zero Trust — they're reasons to be pragmatic about implementation. Start with the highest-risk areas, deliver measurable improvements in 90-day cycles, and build institutional knowledge as you go.
Layer7 Networking has implemented Zero Trust architectures for organisations across financial services, mining, retail, and government sectors. Our phased approach delivers risk reduction from day one, not month eighteen.