Name the protect surface
Select important applications, data and operational functions. Map the transactions and dependencies required for legitimate work.
Improve identity and device confidence
Centralise authentication, strengthen MFA, manage service identities and use device health where it adds reliable context. Avoid treating any single signal as permanent trust.
Enforce close to the resource
Make access decisions at the application, service or workload boundary. Use least privilege and separate administrative paths from normal user access.
Learn from decisions
Log allow and deny outcomes, policy exceptions and unusual access paths. Review whether controls reduce exposure without creating unsafe workarounds.
