A zero-trust design principle, sized to your context.
One principle, three zones (data, identity, network), one position the organisation can carry. Sharp enough to design against, modest enough to operationalise.
Three scenarios we encounter at organisations approaching zero-trust.
IAM gets sharper, ZTNA replaces VPN, the data and network sides stay where they were. The principle becomes inconsistent, the gain partial.
A platform delivers part of the picture. Without the design principle holding across the rest, the platform investment doesn't deliver what the slides promised.
Microsegmentation everywhere, every flow inspected, every identity continuously verified. Beautiful on paper, unsustainable in practice. The middle ground is missing.
A working principle, not a platform list.
One principle, three zones (data, identity, network), one position the organisation can carry. Sharp enough to design against, modest enough to operationalise.
Where to start, what to leave for later. Per move an indication of effort, duration and ownership. Sized to the team.
After the session, the three speak one language about zero-trust. That is the basis for any platform decision that follows.
Four steps, half a day or full day plus preparation and summary.
Existing architecture overview, current IAM and network setup, three scenarios to test the principle on. A first call to align on assumptions.
A structured working session in which we design the principle across data, identity and network with your team. We test it on the three scenarios you provided.
Within one working week, a written summary with the design principle, the three test scenarios and a first sequence of moves.
If you want architecture support during execution, we can stay involved. In a clear role, with a defined endpoint.
The session asks for the right people at the table, not the most.
One central contact, usually the CISO or Security Architect. Network and identity leads at the table for the parts where their input matters.
No team, no junior. The architect who runs the session writes the summary and presents it.
What this costs depends on your context and scale. We are upfront about effort and duration, so you know what you're asking for.
Plus preparation and a written summary within one working week.
Hans Raaijmakers facilitates the session. Preparation and synthesis are part of the engagement.
A fixed amount per session, after the orienting conversation. No hourly billing.
For clarity, what this is not.
We design the principle. Platform implementation follows in a separate engagement with the right partners.
We don't score products. The session is about the principle, not the platform.
Maximalist designs look good on slides and stall in practice. The session is about the middle ground that holds.