A scenario that keeps repeating itself in one form or another across the Greater Region: an employee working from home clicks a link in a seemingly internal email one morning. Their laptop is connected to the company network via VPN — and that single connection is enough. A few hours later, file servers are encrypted, the ERP is down, dispatch is working with Excel and the phone. Days of downtime, substantial damage — and the real problem wasn't the click. It was the architecture behind it.
The problem: VPN trusts too much
VPN was a good idea — for 2010. It opens a tunnel, and everything on the other side counts as "inside". Inside means: trusted. Inside means: access to file servers, databases, all internal systems. But a modern attacker only needs a single compromised endpoint with an active tunnel — then they're in, with everything "inside" implies. Ransomware then moves laterally through the network, because it can.
The idea behind Zero Trust: trust no one, always verify
Zero Trust is not a product; it's a posture in three sentences: no one gets automatic trust — not the employee in the office, not the CEO in a hotel, not the server in your own data center. Every access is checked individually — who is asking, from which device, in what state, to what? Assume attackers are already inside — so build the network so they can't get any further. It sounds paranoid. It is the realistic answer to the 2026 threat landscape.
What this really looks like in an SME
You don't need an enterprise stack with 14 tools. In SMEs, Zero Trust usually rests on three pillars:
Pillar 1: Identity as the new perimeter. Instead of "who is inside the network", the question becomes: "who is the person, on which device, in what context?" Concretely: Microsoft Entra ID with enforced multi-factor authentication for every login; Conditional Access — a login from Luxembourg at 9:00 is normal, one from Singapore at 3:00 is not; privileged access only time-limited and with extra verification.
Pillar 2: The endpoint must prove itself. The device is the second key. If the laptop isn't patched, has no running EDR, or shows suspicious behaviour, there is no access — no matter who signs in. Typical building block: Microsoft Defender for Endpoint, combined with device compliance policies and — where needed — a Securepoint UTM as a second line of defence on site.
Pillar 3: Think of the network in zones. The most demanding but most effective measure: instead of one flat company network, build zones — accounting, production, guests, servers — that may only talk to each other where genuinely needed. In a segmented network, ransomware gets stuck in the first zone instead of encrypting the whole company.
A realistic roadmap
This is what adoption looks like in a typical two-site SME: Month 1 — MFA for everyone, Conditional Access for the critical apps, an inventory of "who actually accesses what?". Months 2–3 — roll out EDR, enforce device compliance, clean up old admin accounts. Months 4–6 — segment the network, ZTNA for remote access instead of VPN, centralise logging. After that, the quarterly audit is often a glance at a dashboard instead of a week of paperwork.
When to start
Before the call comes. If everything still hangs on one VPN today, plus a domain admin with access everywhere, you are exactly what Zero Trust is meant to replace. The good part: you don't have to do everything at once — setting up MFA and Conditional Access within four weeks already reduces your risk noticeably. The rest comes in stages.
Let's talk for 30 minutes
The free Zero Trust quick check: no sales pitch, but an honest assessment of where you stand and the two or three most important steps for your company. — 📞 +352 20 60 12 44 · 📧 mail@local-it-partner.lu
Questions about this topic?
We are happy to advise you personally on Cybersecurity and other IT topics.
Matching services from Local-IT-Partner
More articles you may like
NIS2 in Luxembourg: what the new law actually means for SMEs
Since May 2026, NIS2 has been law in Luxembourg. Who is affected, what management is personally accountable for, and the 4 steps that matter now.
When the backup gets encrypted too: the three design flaws behind almost every data loss
"Everything's gone — including the backup." Why the cause is rarely the ransomware itself but three design flaws — and how the 3-2-1-1-0 rule prevents them.
