← all notes
securityzero-trustinfrastructure

Zero Trust security: an infra admin's perspective

5 min read

After spending many years in the trenches as an infrastructure administrator and then moving into cloud and security, I have gained a particular perspective on Zero Trust. For infrastructure people like me, security has always been part of the job — just not the whole job. We built networks, managed servers, and kept systems running while maintaining security along the way.

When I first heard about Zero Trust many years ago, I thought it was another security buzzword vendors were using to sell products. I was wrong. As I focused more on security, I discovered that Zero Trust is not something you buy. It is a strategy that changes how we approach the infrastructure we already have.

From perimeter defence to continuous verification

For most of my career, I approached security the way many infrastructure administrators did: build a strong firewall, keep the bad actors out, and trust what is inside. We set up VLANs and DMZs, implemented network segmentation, and called it a day. That worked when applications lived in our data centres and users worked from office desktops.

That world no longer exists. Applications are scattered across cloud providers, users work from anywhere, and the network perimeter has effectively dissolved. Zero Trust acknowledges this reality by assuming breach and verifying every connection, regardless of where it originates.

Using what infrastructure teams already know

The good news is that our knowledge of systems and networks gives infrastructure administrators an advantage when implementing Zero Trust. We understand how things connect, where data flows, and what normal operations look like. That context is invaluable when designing a Zero Trust architecture. I see three main areas where our existing expertise applies.

1. Identity infrastructure

Most of us have managed Active Directory or LDAP for years. Zero Trust builds on that foundation by strengthening how identity is verified and how access is granted.

  • Add multi-factor authentication so users are verified by more than a password.
  • Apply conditional access based on device health, location, and risk.
  • Replace broad group permissions with just-in-time, just-enough access.
  • Integrate existing identity systems with cloud identity providers.

2. Endpoint management

We have all deployed and managed workstations and servers. Zero Trust extends that discipline beyond periodic maintenance.

  • Continuously monitor device health instead of relying only on periodic patching.
  • Use application allowlisting rather than relying only on antivirus software.
  • Manage vulnerabilities in real time.
  • Secure access to resources regardless of the device's location.

3. Network architecture

Network design has always been a core infrastructure responsibility. Zero Trust changes its focus from trusted zones to verified flows and application-level access.

  • Implement micro-segmentation to limit lateral movement.
  • Encrypt traffic between all resources, including traffic inside the data centre.
  • Move access control from the network level to the application level.
  • Design around data flows rather than network zones.

Start the journey with what you have

One thing my infrastructure background taught me is the importance of being pragmatic. You cannot rip and replace enterprise infrastructure overnight. Progress starts by understanding the environment and improving it deliberately.

  • Start with visibility. Map data flows, identify critical assets, and document current access patterns before changing anything.
  • Use existing tools fully. Platforms such as Microsoft Defender, Cisco, and VMware already include Zero Trust capabilities that many organisations have not implemented.
  • Tackle the low-hanging fruit. Enable multi-factor authentication, deploy endpoint protection everywhere, and review administrative privileges.
  • Focus on one workflow. Apply Zero Trust principles to a single critical application as a proof of concept before expanding.

Real-world challenges

Infrastructure experience also helps us anticipate the practical obstacles that appear during a Zero Trust programme.

  • Legacy applications that do not support modern authentication.
  • Specialised equipment that cannot run security agents.
  • Business processes that depend on broad network access.
  • Limited cloud environments.
  • Integration gaps between different vendors' security tools.

These are recommendations, not an ultimatum. The important thing is not to let these challenges stop progress. Perfect security is unattainable, but we can significantly improve our security posture by applying Zero Trust principles wherever possible and mitigating the remaining risks.

An evolution of infrastructure practice

As someone who has spent most of my career building and maintaining infrastructure, I see Zero Trust not as a replacement for good infrastructure practices but as their evolution. It means applying least privilege consistently across resources, verifying every access request, and always assuming breach.

My suggestion to infrastructure administrators exploring Zero Trust is to lean into your knowledge of how systems actually work. Your understanding of the practical realities of enterprise IT is invaluable when improving security without breaking critical business functions.

Zero Trust is not just a security strategy. It is the future of infrastructure design, and infrastructure professionals are uniquely positioned to lead that transformation.