We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Audit and compliance
  2. Zero trust architecture assessment
Zero trust assessment, UAE

Zero trust is not a product you bought. It is seven tenets your architecture either meets or does not.

NIST defines zero trust as a paradigm where trust is never granted implicitly but must be continually evaluated. An assessment tests your architecture against the published tenets rather than against a vendor description of its own capabilities.

Book a zero trust assessmentSee the seven tenets
Zero trust architecture assessment for UAE organisations
  • 7 tenetsThe published definition of the architecture
  • 6 assumptionsAbout the network a ZTA is built on
  • Per sessionHow resource access should be granted
  • No implicit zoneThe private network is not trusted
The honest framing

The tenets are the ideal goal, and NIST says so explicitly.

That single acknowledgement makes zero trust assessable rather than aspirational, and it changes how the results should be read.

  • The publication states that the tenets are the ideal goal, though it must be acknowledged that not all tenets may be fully implemented in their purest form for a given strategy. An assessment therefore produces a position rather than a pass or a fail.
  • That matters commercially, because zero trust is frequently sold as a binary state a product delivers. It is an architectural direction with measurable characteristics, and knowing where you sit on each tenet is more useful than a certificate would be.
  • It also removes the paralysis. Organisations postpone zero trust work because full implementation looks impossible. Improving three tenets meaningfully changes the security position, and the assessment identifies which three are worth the effort in your estate.
  • And it protects the budget conversation. A board asked to fund zero trust reasonably wants to know what changes. Tenet by tenet, with a current position and a target position, is an answer they can evaluate and hold you to afterwards.
Ask us where your estate actually sits
What the tenets require

Eight things an assessment establishes about your architecture.

Zero trust has been sold as a product category for years, and the published definition is architectural rather than technological. Testing an estate against the actual tenets produces a very different picture from a vendor capability matrix.

Trust is never implicit

The paradigm is focused on resource protection and the premise that trust is never granted implicitly but must be continually evaluated. Every architecture decision either supports that premise or quietly contradicts it, and most estates contain a mixture.

Network location alone does not imply trust

Access requests from assets on enterprise owned network infrastructure must meet the same security requirements as requests from any other network. Estates that still treat the office LAN as trusted fail this tenet regardless of what else they have deployed.

Access is granted per session

Trust in the requester is evaluated before access is granted, with least privileges needed to complete the task. Authentication and authorisation to one resource does not automatically grant access to a different resource, which is where most estates diverge from the model.

Policy is dynamic, not static

Access is determined by dynamic policy including the observable state of client identity, the application or service, and the requesting asset, and may include behavioural and environmental attributes such as location, time, and reported active attacks.

Asset posture is measured continuously

The enterprise monitors and measures the integrity and security posture of all owned and associated assets, because no asset is inherently trusted. Assets found subverted or unmanaged may be treated differently, including denial of all connections.

Authentication is a cycle, not an event

A constant cycle of obtaining access, scanning and assessing threats, adapting, and continually reevaluating trust in ongoing communication. That expectation includes identity, credential and access management, asset management, and multifactor authentication.

Everything is a resource

All data sources and computing services are considered resources, and an enterprise may classify personally owned devices as resources where they can access enterprise owned resources. That framing changes what belongs inside the scope of the architecture.

Telemetry feeds the policy

The enterprise collects as much information as possible about the current state of assets, network infrastructure and communications, and uses it to improve its security posture and to provide context for access requests. Telemetry is an input, not a report.

The network assumptions

Six assumptions a zero trust architecture is built on.

These are as diagnostic as the tenets. An estate whose design contradicts these assumptions is not going to reach the tenets, whatever is deployed on top.
AssumptionWhat it rules out
The private network is not an implicit trust zoneTreating the office LAN as safe
Assets act as if an attacker is present on the networkUnauthenticated internal connections
Devices may not be owned or configurable by the enterpriseAssuming managed endpoints everywhere
No resource is inherently trustedServer to server trust by network position
Subject credentials alone are insufficient for device authenticationUsername and password as the whole check
Not all enterprise resources sit on enterprise infrastructurePerimeter thinking for cloud services
Remote subjects cannot fully trust their local networkTrusting home and public networks
Assets keep a consistent posture when they moveDifferent rules on and off the network
How we approach it

Four things that make a zero trust assessment useful.

The word has been used so loosely that an assessment has to anchor on published text, otherwise it becomes an opinion exchange between consultants and vendors.

We assess against the published tenets, not a vendor model

Seven tenets and six network assumptions, each given an evidenced position. Vendor maturity models are designed around what that vendor sells, which makes them useful for planning a purchase and unsuitable for assessing an architecture.

We look for implicit trust zones specifically

The publication is explicit that the implicit trust zone must be as small as possible for enforcement to be specific. Finding and sizing those zones is the most direct way to see where an estate departs from the model.

We accept that full implementation is not the goal

The tenets are described as the ideal goal, with the acknowledgement that not all may be fully implemented in their purest form. An assessment that treats anything short of perfection as failure produces a report nobody can act on.

We map existing investment to the tenets it supports

Most organisations have already bought several products that genuinely advance one or two tenets. Showing which ones, and which tenets remain unaddressed, usually reframes the conversation from more spending to better sequencing.

How an engagement runs

Four phases across roughly eight to twelve weeks.

The assessment itself is quick. Producing a roadmap that a board will fund, tenet by tenet, is where the value and the time are.
  1. 01
    Weeks 1 to 3

    Establish the current architecture

    Where identity is decided, where policy is evaluated, where it is enforced, and what the enterprise actually knows about asset posture. The published logical components give this a structure that is comparable between estates.

    • Policy decision and enforcement points identified
    • Identity and asset management inventory documented
    • Implicit trust zones located and sized
    • Telemetry sources mapped against policy inputs
  2. 02
    Weeks 4 to 6

    Assess against the tenets and assumptions

    Each of the seven tenets given an evidenced position, and each of the six network assumptions tested against how the estate is actually built. The output is a picture rather than a score, since the tenets are the ideal goal.

    • Position per tenet with supporting evidence
    • Network assumptions tested against the design
    • Contradictions identified where design fights the model
    • Quick wins separated from structural work
  3. 03
    Weeks 7 to 9

    Prioritise by risk and feasibility

    Not every tenet is worth the same effort in every estate. Lateral movement is called out as one of the biggest challenges, so tenets that constrain it usually rank highly, but the ordering follows your architecture rather than a template.

    • Tenets prioritised by risk reduction and feasibility
    • Dependencies between improvements sequenced
    • Existing investments mapped to tenets they support
    • Target position defined per tenet
  4. 04
    Weeks 10 to 12

    Roadmap and governance

    A funded and sequenced plan, with a way of measuring progress that is not a vendor dashboard. Zero trust work spans years, so the measurement approach matters as much as the first tranche of changes.

    • Roadmap with sequencing and owners
    • Measurement approach per tenet defined
    • Board level summary framed around the tenets
    • Reassessment cadence agreed
Where this comes up

Six situations that prompt an assessment.

The trigger is usually a question about what was actually achieved, asked by somebody who authorised the spending.

A regulated firm asked to evidence its architecture

Supervisors and auditors increasingly ask how access decisions are made and whether network position confers trust. An assessment against published tenets is a much stronger answer than a list of products with zero trust in their marketing.

A board asking what the programme delivered

Zero trust programmes consume significant budget over several years. A position per tenet, before and after, gives a board something to evaluate that is neither a product inventory nor an assurance from the team that spent the money.

An organisation that suffered lateral movement

The publication identifies unauthorised lateral movement as one of the biggest challenges, and the tenets are designed against it. After an incident involving movement between systems, the tenets provide a structured remediation frame.

A business moving substantially to cloud services

Not all enterprise resources sit on enterprise owned infrastructure, and assets moving between environments should keep a consistent security policy and posture. Cloud migration is where perimeter assumptions break most visibly.

An operation with unmanaged and third party devices

Devices on the network may not be owned or configurable by the enterprise, and that assumption is built into the model. Estates with contractors, visitors and operational technology need policy that accounts for it rather than exceptions that bypass it.

A team whose policy cannot see device posture

Dynamic policy is supposed to include the observable state of the requesting asset. Where access decisions rely on identity alone, that is a specific and addressable gap rather than a general shortfall in maturity.

Three positions

How UAE organisations describe their zero trust position.

The middle column is extremely common and it is where the most money has usually been spent, which is what makes an honest assessment uncomfortable and useful.
Position known per tenet
Assessed against the tenetsEvidenced
Bought a zero trust productAssumed
Perimeter architectureNot applicable
Internal network treated as trusted
Assessed against the tenetsNo
Bought a zero trust productOften still yes
Perimeter architectureYes
Access granted per session
Assessed against the tenetsAssessed
Bought a zero trust productPartially
Perimeter architectureNo
Device posture in policy
Assessed against the tenetsYes
Bought a zero trust productSometimes
Perimeter architectureNo
Implicit trust zone size known
Assessed against the tenetsMeasured
Bought a zero trust productNot considered
Perimeter architectureLarge
Decision and enforcement separated
Assessed against the tenetsMapped
Bought a zero trust productVendor dependent
Perimeter architectureNot applicable
Lateral movement constrained
Assessed against the tenetsDeliberately
Bought a zero trust productPartially
Perimeter architecturePoorly
Roadmap tied to risk
Assessed against the tenetsYes
Bought a zero trust productProduct driven
Perimeter architectureNone
Board can evaluate progress
Assessed against the tenetsTenet by tenet
Bought a zero trust productBy spend
Perimeter architectureNot discussed
Effort to reach
Assessed against the tenetsWeeks to assess, years to build
Bought a zero trust productProcurement
Perimeter architectureNone
Feature
Assessed against the tenets
Bought a zero trust product
Perimeter architecture
Position known per tenet
EvidencedAssumedNot applicable
Internal network treated as trusted
NoOften still yesYes
Access granted per session
AssessedPartiallyNo
Device posture in policy
YesSometimesNo
Implicit trust zone size known
MeasuredNot consideredLarge
Decision and enforcement separated
MappedVendor dependentNot applicable
Lateral movement constrained
DeliberatelyPartiallyPoorly
Roadmap tied to risk
YesProduct drivenNone
Board can evaluate progress
Tenet by tenetBy spendNot discussed
Effort to reach
Weeks to assess, years to buildProcurementNone
The component question

Ask who makes the decision, who executes it, and where the log goes.

The logical components give an assessment something concrete to test, and many estates cannot answer these three questions cleanly.

  • The policy engine is responsible for the ultimate decision to grant access to a resource for a given subject, and it makes and logs the decision as approved or denied. In a real estate that decision is frequently split across several systems with no single record.
  • The policy administrator establishes or shuts down the communication path between a subject and a resource by issuing commands to enforcement points, and executes the decision the engine made. Where nothing performs that role, revocation tends to be theoretical.
  • Enforcement points are where the tenets become real. Moving them closer to the resource is what shrinks the implicit trust zone, and the publication is explicit that the implicit trust zone must be as small as possible for enforcement to be specific.
  • The components communicate on a separate control plane while application data moves on a data plane. Estates where policy and data share a path have a structural weakness that no amount of policy configuration compensates for.
Ask us to map your decision points
How an engagement runs

Five steps, anchored on published text throughout.

Every finding traces to a tenet or an assumption, which is what keeps the assessment from becoming a discussion about product preferences.
  1. 1

    Map decision, administration and enforcement

    Where the ultimate access decision is made and logged, what establishes and shuts down communication paths, and where enforcement sits relative to the resources. Those three roles give the assessment a comparable structure.

  2. 2

    Locate and size the implicit trust zones

    Every area where entities are trusted to the level of the last enforcement point. The publication states the implicit trust zone must be as small as possible, so finding the large ones identifies where the architecture most departs from the model.

  3. 3

    Assess each tenet with evidence

    Resources, communication security regardless of location, per session access, dynamic policy, continuous posture measurement, dynamic and strictly enforced authentication, and telemetry feeding posture improvement. Evidence rather than self assessment.

  4. 4

    Test the six network assumptions against the design

    Whether the private network is treated as an implicit trust zone, whether unmanaged devices are accounted for, whether subject credentials alone are relied on for device authentication, and whether posture travels with assets that move.

  5. 5

    Sequence a roadmap the business can fund

    Prioritised by risk reduction and feasibility, with existing investments mapped to the tenets they already support, a target position defined per tenet, and a measurement approach that does not depend on a single vendor dashboard.

Straight answers

What organisations ask about zero trust.

A cybersecurity paradigm focused on resource protection and the premise that trust is never granted implicitly but must be continually evaluated. The architecture is an enterprise cybersecurity plan encompassing component relationships, workflow planning and access policies.

No. Products can advance particular tenets, sometimes substantially. The architecture itself is a plan built on those tenets, which is why an assessment measures the estate rather than the procurement history behind it.

All data sources and computing services are resources, all communication is secured regardless of network location, access is granted per session, access is determined by dynamic policy, asset posture is monitored and measured, authentication and authorisation are dynamic and strictly enforced, and telemetry is collected and used to improve posture.

No. The publication frames the tenets in terms of what should be involved rather than what is excluded, and notes that internet gateways remain useful against external attackers while being less useful for attacks originating inside the network.

An area where all entities are trusted to at least the level of the last decision and enforcement point. The published guidance is that it must be as small as possible, because enforcement cannot apply policies beyond its own location in the traffic flow.

No, and the publication says so. The tenets are the ideal goal, with an acknowledgement that not all may be fully implemented in their purest form for a given strategy. Progress on the tenets that matter most to your estate is the practical objective.

Network location. Access requests from assets on enterprise owned infrastructure are supposed to meet the same security requirements as requests from anywhere else, and a great many estates still grant materially more trust to the internal network.

It is expected and it is not sufficient. The model anticipates identity, credential and access management alongside asset management, dynamic policy including device state, per session authorisation and continual re-evaluation during ongoing communication.

Access is determined by dynamic policy including the observable state of the requesting asset. Assets found to be subverted, carrying known vulnerabilities or unmanaged may be treated differently, including denial of all connections to enterprise resources.

The model accounts for them directly. Devices on the network may not be owned or configurable by the enterprise, and an enterprise may classify personally owned devices as resources where they can access enterprise owned resources.

Very much so. One of the stated assumptions is that not all enterprise resources are on enterprise owned infrastructure, and another is that assets and workflows moving between enterprise and non enterprise infrastructure should keep a consistent policy and posture.

Years for an estate of any size, which is why sequencing matters more than ambition. The assessment takes weeks and produces the ordering, and the first tranche of improvements usually delivers most of the near term risk reduction.

Tenet by tenet, with an evidenced position and a target. That measurement survives a change of vendor, which a product dashboard does not, and it is comprehensible to a board without requiring them to understand the underlying technology.

No. It is an architectural direction that gives existing work a frame. Identity, endpoint management, network segmentation, logging and access review all map onto specific tenets, and the assessment shows which of them are already carrying weight.

We scope by estate size and the number of environments involved. The free first step: ask whether a request from a laptop on your office network is treated differently from the same request from a coffee shop. If it is, that is tenet two.

With identity and with the assumption that network location confers no trust. Those two changes underpin most of the tenets, and they are prerequisites for the per session, dynamic policy and continuous evaluation work that follows.

No. Segmentation can shrink implicit trust zones, which advances the model, and it is one technique rather than the architecture. The publication frames the tenets in terms of what should be involved rather than in terms of any particular technique.

Usually by placing enforcement in front of them rather than by changing them. The objective is moving decision and enforcement points closer to the resource, and a proxy or gateway achieves that for systems that cannot be modified.

It is in scope. All data sources and computing services are considered resources, and all communication is secured regardless of network location. Service to service trust granted by network position is one of the most common departures from the model.

Not necessarily. Dynamic policy considering device state, location and behaviour can reduce prompts for low risk access while increasing scrutiny where the signals warrant it. Friction rises where policy is static rather than where it is strict.

By whether the findings are uncomfortable. An assessment reporting strong coverage across all seven tenets in a typical estate is almost certainly measuring intent rather than implementation, and the value comes entirely from the accuracy.

A position per tenet with a target, framed around which stages of an intrusion you would currently see and which access decisions currently rely on network position. That is evaluable by people who do not work in security.
Architecture check

Fifteen questions that reveal your real position.

These are answerable without any tooling, and the answers usually tell you more than a maturity questionnaire does.

Trust and location

  • Is the office network treated as trusted?
    Location alone should not imply trust.
  • Do internal connections authenticate?
    Assume an attacker is present.
  • Is traffic encrypted internally?
    Most secure manner available.
  • How large is the implicit trust zone?
    It should be as small as possible.
  • Do servers trust each other by subnet?
    No resource is inherently trusted.

Access decisions

  • Is access granted per session?
    Not once per login.
  • Does one resource grant imply another?
    It should not.
  • Does policy use device posture?
    A named policy input.
  • Is MFA in place for enterprise resources?
    An expected component.
  • Is trust re-evaluated during a session?
    A constant cycle.

Visibility

  • Do we measure asset posture continuously?
    All owned and associated assets.
  • Can we deny an unmanaged device?
    A documented option.
  • Does telemetry feed policy?
    Not just reporting.
  • Is every access decision logged?
    The engine makes and logs it.
  • Can we revoke a live session?
    The administrator executes it.
Related reading

The pages around this one.

Conditional Access

Where dynamic policy is usually enforced.

Learn more

Global Secure Access

Moving enforcement closer to the resource.

Learn more

IT risk assessment

The wider risk picture the architecture serves.

Learn more
Next step

Ask whether a request from your office network is treated differently from the same request elsewhere.

If it is, network location is still conferring trust, and that is the second tenet. It is also the most common place an estate departs from the model.

Book a zero trust assessmentCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Entra Conditional Access

The control that decides who reaches your data

Learn more

Entra Global Secure Access

Internet Access, Private Access and tenant restrictions

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

Microsoft Cloud PKI

Retire the certificate server, NDES and the Intune connector

Learn more

Privileged Access Audit

Every privileged path, not just the admin list

Learn more

Network Monitoring NOC

24/7 NOC monitoring with named engineers

Learn more

ATT&CK coverage assessment

Which adversary behaviours would go unnoticed today.

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy