Metaluxo
← Blog

Zero Trust for SMEs: A Reality Check

Zero Trust for SMEs: A Reality Check

Every security vendor now sells a “Zero Trust” solution. Every conference talk mentions it. Every CISO job description requires it. But what does Zero Trust actually mean for a 20-person company with a single office and cloud-based tools?

At Metaluxo we design security architectures for SMEs. Zero Trust is a valuable framework, but only when applied proportionately. This post separates the principles from the marketing.


What Zero Trust actually means

Zero Trust is not a product. It is a set of principles:

  1. Never trust, always verify. Every access request is authenticated and authorised, regardless of where it comes from.
  2. Assume breach. Design your systems as if an attacker is already inside the network.
  3. Least privilege. Users and systems get the minimum access they need, for the minimum time.
  4. Verify explicitly. Use multiple signals (identity, device health, behaviour) to make access decisions.

These principles are sound. The problem is that vendors have turned them into a product category that requires enterprise budgets and dedicated teams to implement.


What Zero Trust looks like for an SME

An SME does not need a Zero Trust Architecture with capital letters. It needs the principles applied practically:

Enterprise Zero TrustSME Proportionate Equivalent
Micro-segmentation with software-defined perimetersVLANs and firewall rules between office and production
Continuous adaptive risk and trust assessmentMFA + device management + conditional access on cloud apps
Privileged access management (PAM) platformSeparate admin accounts with hardware keys
Security orchestration, automation and response (SOAR)Documented incident response plan with a 24-hour contact
Network access control (NAC)Guest WiFi separate from corporate network

The SME equivalent is not a lesser version. It is the right version for the risk profile and budget.


The performative trap

The biggest mistake SMEs make with Zero Trust is buying enterprise tools they cannot configure or maintain. A poorly configured SIEM generates alerts that nobody reads. An over-engineered network segment breaks workflows and drives users to bypass controls.

The right approach:

  1. Start with identity — MFA on every account, admin accounts separate
  2. Add device context — managed devices for work, no personal devices on corporate resources
  3. Segment by data sensitivity — customer data on restricted systems, public marketing content on open systems
  4. Monitor what matters — failed logins, data exports, privilege escalation
  5. Review quarterly — access rights, device compliance, network rules

At Metaluxo we design proportionate security architectures for SMEs. If Zero Trust vendors are telling you what you need to buy but not what you actually need to do, book a free 30-minute consultation and we will design an architecture that fits your size.

Roberto Arias — founder of Metaluxo. Virtual CISO work, ISO 27001 and incident response for small and medium businesses across the EU. Ask him a question →

Send us a message
Message us Book now