Why Zero Trust Is the Way Forward with Todyl
Traditional cybersecurity was designed around a simple assumption: people and devices inside the company network could generally be trusted, while threats were expected to come from outside.
That model no longer reflects how most businesses operate.
Employees work from home, customer sites, shared offices and mobile devices. Business information is spread across cloud platforms, software-as-a-service applications, branch locations and on-premises servers. Contractors and third parties may also require controlled access to selected systems.
In this environment, being connected to the office network should not automatically grant broad access.
Zero Trust takes a different approach:
Never trust automatically. Verify every request and grant only the access that is genuinely needed.
NIST describes Zero Trust as a move away from static, network-based perimeter security towards protecting users, devices, applications and individual resources. Access should not be trusted simply because a person or device is inside the local network or owned by the organisation.
Todyl provides a security platform designed to help organisations put these principles into practice through secure connectivity, identity-aware access, network segmentation, endpoint protection, monitoring and managed threat response.
The result can be stronger protection without forcing every business to assemble and operate a complicated collection of disconnected security products.
What Zero Trust Really Means
Zero Trust is sometimes presented as a single product that can be purchased and switched on.
It is not.
It is a security strategy built around several principles:
- Treat every network as potentially hostile.
- Verify the user and device requesting access.
- Grant the minimum necessary permissions.
- Restrict access to specific applications and resources.
- Monitor activity continuously.
- Assume that a breach may already have occurred.
- Limit how far an attacker could move if one account or device is compromised.
NIST describes Zero Trust as a collection of principles for making accurate, least-privilege access decisions in an environment considered potentially compromised. It also recommends implementing Zero Trust incrementally rather than attempting an immediate replacement of every existing system.
Todyl similarly states that Zero Trust is a strategy and cultural shift rather than a single tool. Its platform is designed to support that strategy by continuously verifying users and devices, limiting access and reducing the exposed attack surface.
Why the Traditional Network Perimeter Is No Longer Enough
In the traditional model, a firewall protected the boundary of the office.
Once a user connected to the internal network—either physically or through a VPN—they could often reach many other systems.
That creates a serious problem when an attacker compromises:
- A laptop
- A user password
- A remote-access account
- A supplier connection
- An unpatched device
- A server inside the network
After gaining entry, the attacker may be able to explore the environment, discover other systems and move laterally towards valuable information.
Modern organisations also have resources that do not sit behind one office firewall:
- Microsoft 365
- Cloud servers
- Hosted applications
- Remote desktops
- Branch offices
- Employee homes
- Mobile devices
- Third-party platforms
There is no longer one clear perimeter to defend.
Zero Trust focuses on protecting the resource itself and verifying each access request, regardless of where the person or device is located.
How Todyl Supports a Zero Trust Approach
Todyl’s platform brings together several capabilities that can contribute to a wider Zero Trust strategy.
These include:
- Secure Access Service Edge
- Zero Trust Network Access
- LAN ZeroTrust
- Next-generation firewalling
- Secure web gateway
- Secure DNS
- Web and content filtering
- SSL inspection
- Endpoint Detection and Response
- Next-generation antivirus
- Security Information and Event Management
- Managed Extended Detection and Response
- Governance, Risk and Compliance tools
Todyl describes its platform as providing always-on secure connectivity, Zero Trust access enforcement and multiple network-security functions through a consolidated architecture.
The advantage is not simply having more tools. It is being able to coordinate access, network protection, endpoint security and monitoring as part of one security model.
Verify Users Before Granting Access
A Zero Trust system should not assume that a request is legitimate merely because the correct username and password have been entered.
Passwords can be:
- Stolen through phishing
- Reused from another breach
- Captured by malware
- Shared accidentally
- Guessed
- Exposed by an insecure supplier
Access decisions should therefore consider identity and additional verification.
Policies may include:
- Multi-factor authentication
- User identity
- Group membership
- Device status
- Requested application
- Source location
- Connection type
- Time of access
Todyl’s approach supports identity-aware and conditional access policies intended to verify requests rather than relying only on network location. Todyl identifies continuous verification, least-privilege access and segmentation as core Zero Trust principles.
This reduces the chance that a stolen password alone provides unrestricted access.
Give People Access Only to What They Need
Many traditional networks give employees broader access than their role requires.
An employee may be able to discover:
- File servers
- Printers
- Management interfaces
- Database servers
- Other workstations
- Backup systems
- Remote administration services
They may never intentionally use these systems, but the connectivity still exists.
If that employee’s computer becomes infected, malware may use the same network paths.
Least privilege means granting only the access needed for a particular job.
For example:
- Sales employees can reach the CRM but not server-management interfaces.
- Finance employees can reach accounting systems but not development resources.
- Contractors can reach one approved application for a limited period.
- Ordinary users cannot communicate directly with backup infrastructure.
- Guest devices can reach the internet but not internal business systems.
The objective is not to make normal work difficult. It is to remove unnecessary routes that an attacker could exploit.
Replace Broad VPN Access With ZTNA
Traditional VPNs usually connect a remote device to the business network.
Once connected, the device may behave almost as though it were physically inside the office.
That model can create several issues:
- Broad network visibility
- Excessive access
- Increased lateral-movement risk
- Complicated firewall rules
- Poor performance through central offices
- Difficulty supporting cloud applications
- Limited context around each request
Zero Trust Network Access, or ZTNA, can grant access to specific approved applications or resources instead of connecting the user broadly to the network.
Todyl identifies ZTNA as one of its core Zero Trust capabilities and places it within its Secure Access Service Edge offering.
A remote employee may therefore receive access to the systems required for their role without being given visibility of the wider environment.
Use LAN ZeroTrust to Protect the Internal Network
Zero Trust should not stop at remote access.
Many organisations carefully filter internet traffic but allow devices inside the local network to communicate too freely.
Todyl’s LAN ZeroTrust capability uses a deny-by-default design intended to prevent internal devices from reaching resources unless an administrator has explicitly allowed the traffic.
This can be used to create internal segmentation between:
- Users and servers
- Departments
- Workstations
- Printers
- Cameras
- Building systems
- Guest networks
- Management interfaces
- Backup infrastructure
Instead of assuming that every internal connection is safe, each required route is deliberately approved.
Limit Lateral Movement
Lateral movement occurs when an attacker uses one compromised system to reach others.
For example:
- A phishing email compromises a laptop.
- Malware scans the local network.
- It finds an exposed server or management service.
- Stolen credentials provide additional access.
- The attacker reaches sensitive files or backup systems.
Network segmentation can disrupt that chain.
Todyl’s deny-by-default LAN ZeroTrust design is intended to isolate systems and reduce the ability of compromised devices to communicate freely with other resources.
The infected device still needs to be investigated, but the potential blast radius can be considerably smaller.
Protect Employees Wherever They Work
Security policies should follow the user rather than disappear when the employee leaves the office.
A laptop may connect through:
- Home broadband
- Hotel Wi-Fi
- Mobile data
- Customer networks
- Shared workspaces
- Public wireless hotspots
The organisation does not control these networks.
Todyl’s SASE platform is designed to provide secure connectivity and apply network-security controls to users and devices regardless of location. Its listed capabilities include secure web gateway functions, secure DNS, next-generation firewalling, SSL inspection and content filtering.
This can provide a more consistent security experience for office, hybrid and fully remote employees.
Inspect Internet Traffic More Consistently
Users encounter threats through:
- Malicious websites
- Phishing links
- Fake sign-in pages
- Compromised downloads
- Command-and-control servers
- Newly registered domains
- Inappropriate or risky content
A cloud-delivered security platform can inspect and control traffic before it reaches the endpoint.
Todyl’s SASE capabilities include:
- Secure web gateway
- Secure DNS
- URL filtering
- Content filtering
- Next-generation firewalling
- SSL inspection
- Conditional access rules
These controls are intended to block threats and enforce policy as traffic passes through the secure platform.
Because the protection is not limited to the office firewall, it can also apply when users are working remotely.
Use Secure DNS to Block Dangerous Destinations
DNS translates names such as example.com into the network addresses devices need.
Attackers rely on DNS too.
Malware and phishing campaigns may use domains created for:
- Credential theft
- Malware delivery
- Remote control
- Data exfiltration
- Fraudulent payment pages
Secure DNS can block access to known or suspicious destinations before a full connection is established.
It is not a replacement for endpoint security or staff training, but it adds another preventative layer.
Todyl includes Secure DNS within its SASE network-security capabilities.
Combine Network Security With Endpoint Protection
Zero Trust should evaluate more than the user identity.
The condition of the device also matters.
A genuine employee may be connecting from a computer that is:
- Infected
- Unpatched
- Missing security software
- Running unauthorised applications
- Already controlled by an attacker
Todyl’s broader security platform includes Endpoint Detection and Response and next-generation antivirus capabilities alongside SASE and Zero Trust access controls.
This layered approach can help:
- Prevent malware
- Detect suspicious behaviour
- Investigate endpoint activity
- Contain compromised systems
- Connect endpoint events with wider network activity
Identity confirms who is requesting access. Endpoint protection helps determine whether the device itself can be trusted at that moment.
Improve Visibility With SIEM
Zero Trust depends on visibility.
A business needs to understand:
- Who signed in
- Which device was used
- What resource was requested
- Whether access was allowed
- Which security events occurred
- Whether behaviour changed
- Whether several alerts are connected
Todyl provides a cloud SIEM capability designed to collect and analyse security information across the environment.
Centralising logs can help reveal activity that might be missed when each product is reviewed separately.
For example, an investigation may connect:
- A risky login
- A newly infected endpoint
- An unusual DNS request
- A denied internal connection
- A large outbound transfer
Individually, each event may appear minor. Together, they may indicate an active attack.
Add Managed Detection and Response
Security products produce alerts, but somebody must determine:
- Whether the alert is genuine
- What happened
- Which systems are affected
- Whether the threat is still active
- What action should be taken
Smaller organisations may not have a dedicated internal security-operations team available around the clock.
Todyl’s platform includes Managed Extended Detection and Response, or MXDR, intended to add expert monitoring, investigation and response across the security environment.
This is important because Zero Trust is not only about blocking access. It also assumes that some attacks will still succeed and therefore requires continuous monitoring and effective response.
Reduce the Number of Disconnected Security Tools
Many businesses accumulate separate products for:
- Antivirus
- VPN
- DNS filtering
- Web filtering
- Firewalling
- Log management
- Threat detection
- Compliance tracking
These tools may:
- Use different consoles
- Generate unrelated alerts
- Require separate policies
- Duplicate capabilities
- Increase licence costs
- Create gaps between vendors
- Require specialist knowledge
Todyl’s platform is designed to consolidate multiple security and connectivity capabilities into one architecture. Its platform overview describes more than a dozen network-security functions, alongside endpoint, SIEM and managed-response modules.
Consolidation does not automatically make a business secure. Policies still need to be designed, tested and monitored properly.
However, fewer disconnected systems can make consistent policy enforcement and incident investigation easier.
Provide Consistent Protection Across Multiple Sites
Businesses with several offices often have different equipment and security policies at each location.
One site may have a modern firewall, while another relies on an ageing router. Remote employees may receive different protection again.
A cloud-delivered SASE model can help provide more consistent controls across:
- Head offices
- Branches
- Home workers
- Mobile users
- Cloud workloads
- Internet access
Todyl describes its Secure Global Network as the foundation of its SASE platform, providing secure connectivity to networks, applications, cloud environments and internet services from different locations.
This can reduce the need to purchase and manage a completely separate security stack for every small office.
Make Access Policies Easier to Understand
A mature Zero Trust deployment should be built around clear questions:
- Who is the user?
- What device are they using?
- What are they trying to reach?
- Why do they need access?
- Which protocol and port are required?
- Should additional authentication be required?
- Should the request be logged or blocked?
Todyl provides conditional access and traffic-policy capabilities that can be used to define explicit rules rather than relying on broad implicit trust.
A policy might state:
Members of the finance group using approved devices can reach the accounting application over the required port after successful multi-factor authentication.
That is more defensible than:
Anyone connected to the office network can reach the finance server.
Support Compliance Requirements
Many security and privacy frameworks expect organisations to demonstrate controls involving:
- Least privilege
- Network segmentation
- Access control
- Multi-factor authentication
- Monitoring
- Incident response
- Protection of sensitive information
Todyl states that LAN ZeroTrust can help support compliance through deny-by-default traffic control, identity-based policies, microsegmentation and restricted access to sensitive resources.
Technology alone does not make an organisation compliant.
Businesses still need:
- Policies
- Documentation
- Risk assessments
- Training
- Evidence
- Access reviews
- Incident procedures
- Management oversight
However, a well-configured platform can provide technical controls and records that support the wider compliance programme.
Make Network Segmentation More Practical
Traditional network segmentation can require:
- Complex VLAN design
- Switch configuration
- Firewall rules
- Routing changes
- Significant testing
- Specialist engineering time
This work remains important, particularly in larger or specialised networks.
Todyl’s LAN ZeroTrust approach can add identity-aware, deny-by-default controls intended to make microsegmentation more practical across internal resources.
The objective is to move from broad network membership towards explicit permission.
Improve Security Without Creating a Poor User Experience
Security controls are often resisted when they make routine work noticeably harder.
A badly designed Zero Trust deployment may create:
- Repeated login prompts
- Blocked legitimate applications
- Slow connectivity
- Confusing error messages
- Inconsistent remote access
- Excessive support calls
The goal is not to challenge the user every few minutes. It is to verify access intelligently and apply policies consistently.
Todyl’s SASE platform is designed to combine secure connectivity and access controls in a cloud-delivered model, supporting access to resources from different locations.
A successful deployment should be tested using real employee workflows before strict policies are enforced widely.
Reduce Reliance on the Office
Traditional security designs frequently route remote traffic back through the main office.
This can create:
- Additional latency
- Concentrated bandwidth demand
- Dependence on one internet connection
- Poor cloud-application performance
- Complicated VPN infrastructure
A SASE architecture moves security and access enforcement into a cloud-delivered platform rather than requiring every connection to pass through one physical site.
Todyl positions SASE as a way to provide secure and reliable access to cloud, SaaS, network and internet resources from anywhere.
This is particularly relevant for organisations whose employees primarily use services such as Microsoft 365 and other cloud applications.
Respond More Quickly to Compromised Devices
When a computer is believed to be compromised, the business should be able to restrict it quickly.
Traditional responses may depend on:
- Physically disconnecting the device
- Manually changing switch settings
- Disabling broad user access
- Waiting for the employee to return equipment
With centrally managed endpoint and network controls, the response may include:
- Isolating the device
- Blocking access to internal resources
- Revoking a user session
- Applying deny rules
- Investigating recent activity
- Preserving evidence
Todyl’s combination of endpoint, Zero Trust networking, SIEM and MXDR capabilities is intended to support coordinated detection and response.
Protect Backup and Management Systems
Backup servers, hypervisors and remote-management tools are high-value targets.
If an attacker can reach them, they may be able to:
- Delete backups
- Disable security
- Create administrator accounts
- Control several systems
- Prevent recovery
- Deploy ransomware widely
These systems should not be reachable simply because a device is connected to the internal network.
Zero Trust policies can restrict access to:
- Approved administrators
- Managed devices
- Specific management networks
- Required protocols
- Limited times or conditions
LAN segmentation can also prevent ordinary workstations from communicating directly with backup and management infrastructure.
Control Third-Party Access
Suppliers and contractors often need temporary access to specific systems.
A traditional approach may involve providing a VPN account that exposes more of the network than intended.
A Zero Trust approach can provide access only to:
- The approved application
- The required server
- The necessary protocol
- The agreed working period
Access can then be removed when the engagement ends.
This is especially valuable for:
- Software vendors
- Accountants
- Remote support companies
- Building-system engineers
- Temporary workers
- Project partners
Third-party users should not automatically inherit the same access as permanent staff.
Reduce the Impact of Stolen Credentials
Zero Trust cannot stop every credential from being stolen.
It can reduce what the stolen account can do.
Controls may include:
- Multi-factor authentication
- Device verification
- Limited application access
- Conditional access
- Segmentation
- Continuous monitoring
- Anomaly detection
If an attacker obtains one employee’s credentials, least-privilege policies can prevent the account from accessing unrelated systems.
SIEM and managed detection may also identify unusual behaviour, such as unexpected locations, resources or connection patterns.
Zero Trust Does Not Mean Trusting Nobody Personally
The phrase “Zero Trust” can sound as though an organisation assumes every employee is dishonest.
That is not the intention.
Zero Trust removes automatic technical trust.
A legitimate employee may make a mistake, lose a device or have their account compromised. Security policies verify each request so that one incident does not automatically expose the whole environment.
The model protects employees as well as the business.
Todyl Is Not a Substitute for Good Identity Management
Todyl can provide important access, networking, endpoint and monitoring capabilities, but the wider security environment still matters.
Organisations also need to secure:
- Microsoft Entra ID or another identity provider
- User accounts
- Administrator roles
- Multi-factor authentication
- Password policies
- Joiner and leaver processes
- Application permissions
- Service accounts
Zero Trust access policies are strongest when identity information is accurate and consistently managed.
An account belonging to a former employee should not remain active simply because the network layer is secure.
Todyl Does Not Replace Backups
Zero Trust can reduce the likelihood and spread of an attack, but it cannot guarantee that information will never be deleted or damaged.
Businesses still need:
- Separate backups
- Protected credentials
- Immutable or offline copies
- Defined retention
- Recovery testing
- Documented disaster-recovery plans
A restricted network is not a replacement for a recoverable copy of critical data.
Todyl Does Not Replace User Awareness
Employees still need to recognise:
- Phishing
- Fraudulent payment requests
- Fake support calls
- Suspicious attachments
- Unexpected MFA prompts
- Social-engineering attempts
Technical controls can block many threats and limit their impact, but people remain part of the security system.
Training should explain how to report suspicious activity quickly, without blaming employees who report mistakes.
Implement Zero Trust Gradually
Zero Trust should not be deployed through an immediate deny-everything policy with no understanding of business workflows.
NIST recommends an incremental approach based on use cases, resources and risk rather than a wholesale replacement of existing technology.
A practical Todyl deployment might follow several stages.
Stage 1: Discover the Environment
Identify:
- Users
- Devices
- Applications
- Servers
- Cloud services
- Network locations
- Existing security tools
- Sensitive data
- Third-party access
You cannot protect resources properly when nobody knows they exist.
Stage 2: Identify Critical Resources
Prioritise systems such as:
- Finance platforms
- Customer databases
- Backup infrastructure
- Management tools
- Microsoft 365
- Remote desktops
- Line-of-business applications
Define who genuinely needs access to each resource.
Stage 3: Establish Secure Connectivity
Deploy the SASE or secure-access components needed to provide consistent protection for users working from different locations.
Confirm that:
- Required applications work
- Internet access is stable
- Remote users are protected
- Existing VPN dependencies are understood
- Performance is measured
Stage 4: Introduce Least-Privilege Access
Replace broad network access with explicit policies.
Begin with high-value systems and clear user groups.
Use report, audit or staged deployment options where available before enforcing restrictive policies across every user.
Stage 5: Segment the Internal Network
Use LAN ZeroTrust and supporting network controls to separate:
- Workstations
- Servers
- Management systems
- Backups
- Guest devices
- Internet of Things equipment
Document each approved connection.
Stage 6: Integrate Endpoint Security
Ensure devices are protected and reporting.
Investigate:
- Missing agents
- Unsupported operating systems
- Malware detections
- Repeatedly unhealthy devices
- Unmanaged equipment
Access should reflect both identity and device risk.
Stage 7: Centralise Monitoring
Feed relevant security events into SIEM and establish:
- Alert priorities
- Escalation procedures
- Investigation ownership
- Retention requirements
- Response playbooks
Logging without monitoring provides limited value.
Stage 8: Review and Improve
Zero Trust policies must change as the business changes.
Regularly review:
- New applications
- Departed employees
- Contractor access
- Policy exceptions
- Blocked legitimate traffic
- Unused rules
- New threats
- Compliance requirements
Todyl describes Zero Trust as an ongoing process sustained through visibility, identity-based access, explicit policy enforcement and continuous monitoring.
Common Zero Trust Mistakes
Avoid these common problems:
- Treating Zero Trust as a single product
- Applying policies without mapping applications
- Trusting every internal device
- Ignoring endpoint health
- Leaving administrator access too broad
- Creating permanent contractor accounts
- Collecting logs without monitoring them
- Blocking legitimate work with no support process
- Assuming MFA alone provides Zero Trust
- Failing to review exceptions
- Neglecting backups and incident response
What a Successful Todyl Zero Trust Environment Looks Like
In a well-designed deployment:
- Users are verified before access is granted.
- Multi-factor authentication protects sensitive access.
- Employees can reach only the resources required for their roles.
- Internal devices cannot communicate freely by default.
- Remote users receive consistent protection.
- Internet traffic passes through security controls.
- Endpoints are monitored for suspicious behaviour.
- Security events are centralised.
- Threats are investigated promptly.
- Access policies are documented and reviewed.
- Compromised devices can be contained quickly.
- The business can continue operating without depending on one office perimeter.
Why Todyl Can Be a Strong Fit for Smaller Businesses
Building Zero Trust traditionally required multiple enterprise products and specialist teams.
Smaller organisations often struggle with:
- Several security consoles
- Limited internal expertise
- Complex licensing
- Unmonitored alerts
- Inconsistent remote-access policies
- Expensive hardware
- Difficulty supporting several sites
Todyl’s consolidated approach is designed to combine secure connectivity, Zero Trust access, endpoint security, SIEM and managed response through one modular platform.
This can make a Zero Trust programme more achievable for organisations that need enterprise-style protection without building a large in-house security operations centre.
Zero Trust Is a Better Match for Modern Work
The traditional approach asked:
Is this device inside the network?
Zero Trust asks better questions:
Who is requesting access?
What device are they using?
What are they trying to reach?
Do they need that access?
Is the request consistent with expected behaviour?
What happens if the account or device is compromised?
Todyl provides a set of technologies that can help translate those questions into practical policies across users, devices, networks and cloud services.
Zero Trust will not remove every risk, and purchasing Todyl does not eliminate the need for planning, identity security, backups, training and ongoing management.
However, combining Todyl’s SASE, ZTNA, LAN ZeroTrust, endpoint security, SIEM and managed-response capabilities can create a far stronger security model than relying on a firewall and broad VPN access alone.
Hamilton Group can assess your current security environment, design a Todyl Zero Trust deployment and manage secure access, segmentation, endpoint protection, monitoring and ongoing threat response.
Call 0330 043 0069 or visit hgmssp.com to speak with one of our cybersecurity experts.