Zero trust architecture
Zero trust architecture is a cybersecurity model built on the principle "never trust, always verify": no user, device, application or network segment is trusted by default, whether inside or outside the traditional corporate perimeter, and every access request is authenticated, authorised and continuously evaluated against policy based on identity, device health, location, behaviour and the sensitivity of the resource. The reference description is NIST Special Publication 800-207 (2020), and the model is promoted by ENISA, the US Cybersecurity and Infrastructure Security Agency and national agencies such as the UK NCSC and France's ANSSI as the answer to cloud adoption, remote work and the failure of perimeter-based defences against lateral movement by attackers.
Core components include strong identity and access management with multi-factor authentication and single sign-on; least-privilege and just-in-time access; device posture assessment and endpoint detection; micro-segmentation of networks so that a compromised system cannot reach others; encryption of all traffic; continuous monitoring, logging and analytics; and policy engines that grant access per session rather than per network. Zero trust is an architecture and a programme rather than a product, typically implemented over several years.
For life sciences organisations, zero trust addresses the realities of clinical research: data spread across sponsors, CROs, sites, laboratories and cloud vendors; thousands of external users (investigators, monitors, vendor staff) accessing EDC, eCOA and safety systems; and ransomware groups that specifically target hospitals and pharmaceutical companies. Legally, zero trust measures map directly onto the Art. 32 GDPR duty to ensure security of processing appropriate to the risk of health data, onto the risk management measures of Art. 21 of the NIS2 Directive (access control, multi-factor authentication, network security, supply chain security), onto the cybersecurity requirements for connected medical devices and onto Art. 15 of the AI Act on robustness and cybersecurity of high-risk AI systems. ISO/IEC 27001 Annex A controls provide the management framework, and zero trust maturity is an increasingly common question in vendor assessments and investor due diligence.
