Skip to main content
Back to Insights
Cybersecurity

Implementing Zero Trust Architecture in Regulated Environments

Arataki Nexus Security Office 6 min readMay 2026

A structured guide to transitioning legacy network perimeters into identity-verified Zero Trust security postures aligned with NZ ISM standards.

The traditional security model assumed a trusted inside and a hostile outside: build a strong perimeter, and anything within it is safe. Distributed workforces, cloud services, and supply-chain access have quietly dismantled that assumption. Once an attacker is inside a flat, trusted network, lateral movement is often trivial.

Zero Trust replaces implicit trust with continuous verification. No request is trusted because of where it originates; every request to every resource is authenticated, authorised, and checked against context.

Perimeter modeltrusted internal networkonce inside → implicitly trustedZero TrustVerify identityevery request, every resourceCheck device & contextevery request, every resourceLeast-privilege accessevery request, every resource
Figure 1 — Perimeter (castle-and-moat) trust versus Zero Trust’s verify-every-request model.

Core principles

  • Verify explicitly — authenticate and authorise on identity, device health, and context for every request.
  • Least-privilege access — grant the minimum access needed, for the minimum time.
  • Assume breach — segment the network and design so that a single compromise cannot spread freely.

A phased transition

Zero Trust is a direction, not a product you install. A transition that respects operational reality moves in deliberate stages:

  • Establish strong identity — consolidate identity providers and enforce phishing-resistant multi-factor authentication.
  • Gain visibility — inventory users, devices, and the resources they reach before changing controls.
  • Segment — introduce network and application segmentation to contain lateral movement.
  • Enforce least privilege — move from broad standing access to just-enough, just-in-time access.
  • Monitor continuously — feed identity, device, and access signals into detection and response.

Aligning to NZ ISM

For agencies and regulated organisations, the New Zealand Information Security Manual (NZ ISM) sets expectations that map naturally onto Zero Trust principles — strong authentication, access control, segmentation, and monitoring. Framing a Zero Trust roadmap against ISM controls turns a security initiative into an auditable, defensible programme.

Zero Trust succeeds when it is sequenced to protect operations, not disrupt them. Identity first, visibility second, enforcement third.

The goal is not to make access harder for legitimate users, but to make trust explicit and revocable. Done well, Zero Trust reduces attack surface while keeping delivery teams productive.

Discuss this topic with Arataki Nexus

Book a consultation for a detailed, context-specific discussion of what this means for your organisation's objectives and constraints.