ON2IT - Zero Trust Innovators

Select your region

Talk to us →
Zero Trust · Learn from our experts
You have the mandate.
Here is exactly how to deliver it.
Strategy without execution is a document. These guides translate Zero Trust principles into phase-by-phase programmes — tested across real environments, authored by the practitioners who ran them. From first Protect Surface to compliance against nine frameworks simultaneously.
For IT Directors · Security Program Owners · CISOs · Risk & Compliance Leads
Programme Design
A phase-by-phase Zero Trust implementation framework — with decision checkpoints, the Kipling policy method, and what actually breaks in practice.
Compliance Coverage
One Zero Trust programme satisfies ISO 27001, NIST 800-53, NIS2, DORA, PCI DSS, and five others — without running parallel workstreams.
Sector Intelligence
Zero Trust for hospitals, critical OT, and environments where downtime is a patient safety event — not just a business risk.
Implementation Guides
Field-Tested Guidance for Security Program Owners
Practical intelligence from practitioners who've run Zero Trust in production
5 guides · 8–10 min each
From the Implementation Guide · Rob Maas · ON2IT
The Five-Step Zero Trust Process
01
Define the Protect Surface
Identify your most critical data, assets, applications, and services — DAAS. Smaller than the attack surface. Manageable.
02
Map Transaction Flows
Understand how traffic reaches the protect surface — and from where. Visualise dependencies before writing a single policy.
03
Architect the Environment
Design the Zero Trust environment around the protect surface. Segment, gate, and enforce — architecture first.
04
Create the Policy
Apply the Kipling Method — Who, What, When, Where, Why, How. Every access policy answers all six questions.
05
Monitor & Maintain
Log everything. Inspect all traffic. Use telemetry to continuously improve the protect surface and policy set.

Frequently Asked Questions

What are the five steps of the Zero Trust implementation process?

The five steps are: define the Protect Surface, map transaction flows, architect the environment, create the policy using the Kipling Method, and monitor and maintain.

What is the Kipling Method?

The Kipling Method structures every access policy around six questions: Who, What, When, Where, Why, and How.

Can one Zero Trust programme satisfy multiple compliance frameworks at once?

Yes. A single, properly structured Zero Trust programme can simultaneously satisfy ISO 27001, NIST 800-53, NIS2, DORA, PCI DSS, and several others, without running parallel compliance workstreams.

Why does Zero Trust matter specifically for hospitals?

When HVAC, water, or sterilisation systems are compromised in a hospital, it becomes a patient safety event, not just a business risk.

What is the Protect Surface, and why is it defined first?

The Protect Surface is an organisation's most critical data, assets, applications, and services (DAAS). It is smaller and more manageable than the full attack surface, which is why it is the first step of the five-step process.