Name the protect surface

Select important applications, data and operational functions. Map the transactions and dependencies required for legitimate work.

Improve identity and device confidence

Centralise authentication, strengthen MFA, manage service identities and use device health where it adds reliable context. Avoid treating any single signal as permanent trust.

Enforce close to the resource

Make access decisions at the application, service or workload boundary. Use least privilege and separate administrative paths from normal user access.

Learn from decisions

Log allow and deny outcomes, policy exceptions and unusual access paths. Review whether controls reduce exposure without creating unsafe workarounds.

Do not start with the network diagramStart with a high-value resource and the people, workloads and devices that genuinely need access to it.