BUS 237 · Emerging Technology

Trust nothing.
Verify everything.

Zero Trust Security Architecture replaces automatic network trust with continuous, context-aware verification—protecting each user, device, application, and data request individually.

No implicit trust Least-privilege access Continuous verification
IdentityMFA confirmed
DeviceHealthy & updated
ContextLow-risk request
ResourceMinimum access
Never trust, always verify.
Core Zero Trust principle

What changed?

From a trusted perimeter to protected resources.

Traditional security often treated people inside the office network or connected through a VPN as trusted. Zero Trust assumes threats may already exist and evaluates every access request.

Traditional model

Trust the network.

Once an attacker crosses the perimeter, broad internal access may allow them to move laterally and reach more systems.

👤
Employee
Connected by VPN
Trusted
⚠️
Compromised account
Inside the network
Wide access
Zero Trust model

Verify each request.

Identity, device condition, location, behaviour, and business need are assessed before access is granted.

🔐
Identity checked
MFA + risk signals
Verified
🎯
Specific resource
Only what the role requires
Limited

How access is decided

Three checks before the door opens.

Every request is evaluated using multiple signals rather than a single password or network location.

01

Identity

Confirms that the user is who they claim to be through multi-factor authentication, sign-in risk, and role-based permissions.

Example signalMFA passed
02

Device health

Checks whether the laptop, phone, or medical device is managed, updated, encrypted, and free from known threats.

Example signalPatch current
03

Access context

Evaluates location, time, behaviour, sensitivity of the resource, and whether the request is necessary for the user’s job.

Example signalRole matched

Industry impact

Why healthcare needs Zero Trust.

Hospitals and clinics hold highly sensitive patient, insurance, and financial information while operating large networks of staff, vendors, cloud services, and connected medical devices.

Connected care environment

A modern hospital is not one network.

It is a constantly changing ecosystem of people, devices, applications, and data.

🧑‍⚕️Verified
📋Least privilege
🩻Segmented
💉Monitored
☁️Encrypted

Protect patient privacy

Access to medical records can be limited to the exact patients, systems, and tasks required for a worker’s role.

Reduce lateral movement

If one staff account or workstation is compromised, segmentation and least privilege help prevent the attacker from freely reaching other systems.

Secure connected devices

Smart pumps, MRI systems, patient monitors, and other medical technologies can be isolated and continuously monitored based on risk.

Breach-containment scenario

One exposed account does not become a hospital-wide breach.

A compromised scheduling account may still be blocked from patient records, finance systems, and clinical devices because each resource requires separate authorization.

Scheduling account: breached
Patient records: blocked
Medical devices: isolated

Business view

Benefits and implementation challenges.

Advantages

  • Smaller breach impact. Compromised access is limited to approved resources.
  • Stronger privacy. Sensitive patient and business data receive granular protection.
  • Better visibility. Continuous logs help organizations understand who accessed what, when, and why.
  • Safer remote work. Access decisions do not depend only on being inside a company network.

Challenges

  • User fatigue. Poorly designed authentication can interrupt employees and slow urgent work.
  • Upfront investment. Migration can require new identity tools, network controls, device management, and staff training.
  • Legacy technology. Older healthcare systems and devices may not support modern authentication or monitoring.
  • Ongoing commitment. Policies, access roles, and risk signals must be maintained continuously.

Vendor ecosystem

Zero Trust is a strategy supported by many tools.

No single product creates Zero Trust by itself. Organizations combine identity, endpoint, network, cloud, data, and monitoring technologies.

Zscaler

Zscaler Private Access connects users directly to approved applications instead of placing them broadly on the corporate network.

Private app access

Microsoft

Microsoft Entra ID and Defender provide identity verification, conditional access, device signals, and threat protection across Microsoft environments.

Identity + security

Palo Alto Networks

Prisma Access applies cloud-delivered security controls to users, applications, network traffic, and remote devices.

Cloud security

Okta

Okta focuses on identity management, authentication, and real-time access policies for employees, customers, and applications.

Identity management
Real-world examples

Large organizations have used Zero Trust strategies to modernize access and protect distributed systems.

GoogleBeyondCorp approach
FedExEnterprise security modernization
U.S. DoDDepartment-wide strategy

The future of Zero Trust

Verification is becoming more intelligent.

As organizations use more cloud services and AI-enabled systems, access decisions are expanding beyond passwords to include behavioural analytics and automated risk detection.

AI-assisted anomaly detectionSystems learn normal patterns and identify unusual activity.

Adaptive authenticationHigher-risk requests trigger additional verification.

Policy-driven automationSuspicious access can be blocked in real time.

Growing regulatory expectationsGovernment and regulated industries increasingly treat Zero Trust as an important security direction.

Behavioural risk example

An unusual 3:00 a.m. database request

03:00:02User requests finance database
03:00:02New location detected
03:00:03Behaviour differs from normal pattern
03:00:03Risk threshold exceeded
Automated decision
Access blocked · verification required
HIGH RISK