October 29, 2026

Zero-Trust Security: Why Every Pillar Matters More Than You Think

Leaving out one pillar of zero trust quietly weakens the whole model, even if the rest are well-implemented. True protection only comes when all five pillars work together as a single system.

What actually breaks when zero-trust security has a gap in it isn't usually the headline system — it's the quiet entry point nobody was watching, and the costs that follow (downtime, lost data, a client who finds out the hard way) tend to show up long after the gap opened.

We think of zero-trust security as a set of tools that get bought and switched on one at a time, but the real work is in how those tools lean on each other. Miss one pillar and the others don't quite cover for it — and because the gap isn't loud, an attacker can sit in it for a while before anyone notices.

That's partly why the shift towards this model has picked up pace: something like 60% of organisations are expected to have adopted a zero-trust strategy by 2025.

The idea underneath it is fairly simple, even if the engineering isn't: no user or device gets trusted automatically, inside the network or out, and every request for access gets checked on its own merits. Getting there properly means understanding how the five pillars of zero trust actually fit together, because that's where most setups quietly fall short.

IT consultant discussing zero-trust security with team in office

The risk of treating zero trust as separate projects

Rolling zero trust out one piece at a time — multi-factor authentication this quarter, network segmentation next — feels sensible when budget or headcount is tight, and we get why that's the instinct. The trouble is that treating each pillar as its own project leaves the whole thing weaker than it looks on paper.

Say your user authentication is solid, but device controls are an afterthought. That's exactly where pressure lands, because the weaker area becomes the way in, and the stronger controls elsewhere don't help. What you end up with is a patchwork rather than a system, and patchworks have seams.

The part that catches people out is that those seams are invisible until they're not. By the time a breach surfaces, whatever damage it's going to do has usually already been done. So the point of zero trust isn't really "add more tools" — it's making the tools you have work as one connected system rather than five separate ones.

How traditional security models fall short

Older security models lean on a strong perimeter, built on the assumption that the threat is outside and anything inside the fence can be trusted. That logic held up reasonably well when resources lived on-site and remote access was the exception rather than the rule.

Cloud services and remote work have moved the boundary, though, or rather removed it — there isn't really a single edge to defend any more. A compromised device or a stolen set of credentials can now get someone in through any number of doors, which means a single line of defence leaves far more exposed than it used to.

Zero-trust security answers that by checking at every step rather than just at the gate, treating each user and device as unverified until it proves otherwise. For businesses in London, where so much of day-to-day operation now runs through digital systems, that shift isn't really optional anymore.

Checklist: Why perimeter security falls short

The five pillars of zero trust security: What must work together

A proper zero-trust model rests on five pillars that depend on each other to function, and losing one weakens the rest more than it might seem to from outside. Here's how they sit together.

Identity verification

Every user has to prove who they are — passwords, biometrics, multi-factor authentication, whatever combination suits the business. Skip this and an attacker only needs to look like staff, not actually be them.

Device security

Only devices that meet your security standards get to connect, which means checking laptops, phones and tablets before they touch company resources, not after.

Network segmentation

Splitting the network into smaller zones means that getting in doesn't mean getting everywhere. Each zone carries its own controls and its own monitoring.

Application access control

People and devices get access to what their role actually needs, nothing more — so if an account is compromised, the blast radius stays small.

Continuous monitoring and response

Activity gets watched for anything unusual, and when something looks off, the system can respond fast enough to contain it before it spreads.

Why skipping a pillar quietly weakens your defences

Miss one pillar, or implement it half-heartedly, and that's where the pressure finds its way through. Strong identity checks don't do much good if a compromised device can still walk an attacker past them — the other pillars genuinely can't absorb that gap.

That's not a hypothetical worry, either. The path of least resistance is usually all that's needed, and a single overlooked corner can be enough on its own. Left alone, small weaknesses tend not to stay small.

Businesses leaning hard on one or two pillars can feel well-protected, and in a narrow sense they are, but the posture as a whole is incomplete. The benefit of zero trust only really shows up once all five pillars are in place and actually talking to each other.

Signs your zero trust architecture is incomplete

Spotting where things are thin isn't always obvious from the inside, so a few patterns are worth checking for:

  • Inconsistent access policies: some users or devices carry more access than their role needs, or the rules aren't applied the same way across the business.
  • Lack of device checks: devices connect without anyone verifying their security status first.
  • Limited network segmentation: once someone's in, they can move around without hitting any further checks.
  • No real-time monitoring: issues surface after the fact rather than as they're happening.
  • Over-reliance on one pillar: heavy investment in, say, identity, while application controls or monitoring get left behind.

If any of that sounds familiar, it's probably worth treating as a signal rather than a coincidence — your zero-trust network may not be carrying as much weight as it looks like it is.

How to build a zero trust model that holds up under pressure

Building something that actually holds requires more than ticking five boxes in sequence. We'd start by reviewing each pillar on its own terms and asking honestly whether it's pulling its weight — gaps tend to appear exactly where a team assumed another control had it covered.

From there, it helps to trace how users and devices actually move through the network day to day. Where does access get granted without a proper check? Which devices aren't being watched for compliance? Questions like those tend to surface the gaps that a tidy diagram hides.

Part of what makes this more manageable, we'd say, is fixed-fee managed IT built with the tooling already in place — things like endpoint detection, Microsoft 365 backup, dark web scanning and full EDR included at no extra charge, rather than bolted on pillar by pillar.

And in London specifically, where regulatory expectations and client scrutiny both run high, being able to show your approach is joined-up matters as much as the approach itself. Regular review keeps that picture current as threats shift.

Checklist: Steps to a resilient zero trust model

The business cost of missing a pillar

Losing a single pillar isn't just a technical problem — it tends to land on reputation, on client trust, and sometimes on the ability to keep operating normally at all. A breach that finds its way through a weak spot usually brings downtime, data loss, and regulatory exposure along with it.

Clients expect their information to be protected at every level, not most of them, and if a breach traces back to an incomplete zero-trust setup, that trust is genuinely hard to earn back. Put plainly, the cost of finishing the model properly is smaller than the cost of recovering from the incident it was meant to prevent.

For businesses running something like 15 to 40 endpoints, one missing pillar can matter more than its size suggests. It's not only a technology question — it's a question of what the business looks like on the other side of a bad week.

Two IT professionals discussing zero-trust security strategy document

Building complete protection for every endpoint

Many businesses with 15 to 40 endpoints find themselves with some strong controls in place, but a few quiet gaps that could be costly. At Sonar IT, we understand how easy it is to miss a pillar when your team is busy, or resources are stretched.

If you want to see how we approach zero trust as a connected system, or talk through your own setup, we’re here to help.

See how a complete model protects your business

Try Sonar IT with your first 30 days free and get our £3,000 satisfaction guarantee—available for businesses ready to strengthen every pillar of their security.

[.c-button-wrap2][.c-button-main2]Start your free 30 days[.c-button-main2][.c-button-wrap2]

Frequently asked questions

How do I know if my current security model is outdated?

If your setup still leans on a strong perimeter and trusts users or devices once they're inside it, that's worth reviewing. Modern threats routinely bypass perimeter-only defences, so a regular assessment against current technology and attack patterns is the only real way to know where you stand.

What is zero-trust network access and how does it differ from VPNs?

Zero-trust network access (ZTNA) grants secure, granular access to specific applications based on identity and device security, rather than opening up the network broadly once someone connects. A VPN tends to hand over wide access after one check; ZTNA checks every request and limits each user to what their role actually needs.

Can I implement zero trust principles gradually, or must it be all at once?

Adopting zero trust in stages is common and workable, but every pillar needs to be in place eventually for the model to function as intended. Starting with one area is fine as a first step, though leaving the others unaddressed for too long raises risk — a phased rollout works best with a clear plan for connecting all five pillars over time.

What are some common mistakes when building a zero trust architecture?

The most frequent one is over-investing in a single pillar, often identity, while device security or monitoring lag behind. Close behind that is letting access controls go stale as roles and technology change around them. Regular review and a deliberately balanced spread across all five pillars tend to catch both.

How does zero trust help with compliance requirements in the UK?

Zero trust supports compliance by enforcing strict access controls, continuous monitoring and detailed audit trails throughout the system rather than at a single checkpoint. That makes it considerably easier to demonstrate, under regulations like GDPR, that data is protected at every step rather than just at the perimeter.

About the author

Joshua Bevis

Managing Director

With over 13 years of experience in the managed IT services industry, Joshua Bevis brings both technical expertise and leadership to his role as Managing Director at Sonar IT. His career began on the service desk providing 1st Line Support, and through dedication and skill, he progressed to the Professional Services team, where he successfully managed and implemented large-scale cloud projects for some of London’s largest MSPs.

Read
Joshua Bevis
's
story
Full documentation here

Check our other posts

Customer Care Team
Customer Care Team
Hi there,
How can i help you today?
Start Whatsapp Chat