dashboard radar bug_report school newspaper sensors

Learning Hub › Deep Dives › Zero Trust

Deep Dive 01 · Interactive guide

Zero Trust Cloud Architecture

"Never trust, always verify." Zero Trust drops the idea that anything inside the company network is safe. Every request, from every user, device and workload, is checked against policy before it gets access, and checked again while it runs. This page walks you from the basic idea to the real frameworks (NIST SP 800-207, CISA's Zero Trust Maturity Model) with hands-on models you can play with.

01

Castle-and-moat vs Zero Trust

The old model is a castle: a strong wall (firewall, VPN) and everyone inside is trusted. The trouble is that attackers rarely break the wall. They phish one employee and walk in through the front door. Pick a model, then phish a laptop and watch how far the attacker gets.

Model Teaching model
CORPORATE NETWORK · inside = trusted skullAttacker laptop_windowsEmployee laptop folder_sharedFile server databaseHR database cloudCloud CRM

Press "Phish a laptop" to start the attack.

02

The 7 tenets of NIST SP 800-207

NIST's Zero Trust Architecture standard (SP 800-207) boils the idea down to seven tenets. Open each one for the plain-words version and an everyday example.

Three logical parts make it work. The Policy Engine (PE) decides yes or no. The Policy Administrator (PA) opens or closes the session based on that decision. The Policy Enforcement Point (PEP) sits in front of the resource and does the actual letting-in or blocking. You'll see all three in the simulator below.
03

Access-decision simulator

Be the Policy Engine. Set who is asking, from what device and where, and what they want. The engine weighs every signal and returns one of four answers. Try the presets first, then change one signal at a time and see what happens.

Presets
Teaching model · not a product policy
Risk score

Why: the engine's trace

    04

    CISA Zero Trust Maturity Model v2.0

    CISA's model breaks Zero Trust into five pillars and four stages, from Traditional to Optimal. Nobody jumps straight to Optimal: organisations move each pillar forward one stage at a time. Pick a pillar to see what each stage looks like.

    Cross-cutting capabilities: they run across all five pillars

    Self-check: where is your organisation?

    Pick the stage that best matches today for each pillar. Answer honestly; this stays in your browser.

    Your profile

    05

    Micro-segmentation in a hybrid cloud

    Most companies run a mix: an on-prem data centre plus one or more cloud VPCs joined by VPN or peering. Joined networks are convenient, and they also let an attacker roam. Micro-segmentation draws a tiny boundary around each workload and only allows the flows that the business needs, written as rules about identities (which service, which user group) rather than IP addresses.

    Segmentation Teaching model
    ON-PREM DATA CENTRE CLOUD VPC A · app CLOUD VPC B · data

    Click a flow to test it

    Pick a flow above.

    06

    A practical roadmap

    Zero Trust is a journey, not a product. NIST's National Cybersecurity Center of Excellence proved this in SP 1800-35 (final, June 2025): it built 19 example architectures with 24 vendors, each mixing existing tools rather than buying one box. A sensible order of work looks like this.

      Myth or fact?

      Five statements you will hear in meetings. Decide for each.

      07

      Sources & further reading

      Building pipelines too? Zero Trust's Applications & Workloads pillar expects security testing inside CI/CD. See it in action in the SAST in CI/CD lab, or continue with Threat Intelligence & MITRE ATT&CK.