Skip to main content
Italian Oral History Institute Los Angeles, California
Institute seal
I.O.H.I. Italian Oral History Institute

An archive of Italian life in California, built from people's own words.

Reference

Understand Zero Trust

A short guide to the security model built on one rule: never trust, always verify.

Working with others

Why the perimeter no longer holds

Few organisations work alone. Supply chains, specialist suppliers and outside contractors carry more of the load than they once did, and each partnership opens a new path into systems that were built to be private. A vendor with a login is also a way in for anyone who can reach that vendor.

The old answer was to build a wall around the office network and treat everything inside it as safe. That answer fits a world where staff sit at desks and data stays at home. It fits far less well when partners, contractors and cloud services need to reach the same systems from anywhere.

What Zero Trust means

Zero Trust is a security model built on a single rule: never trust, always verify. It makes no assumptions about a person, a device or a service based on location. A request from inside the building is checked just as carefully as one from a partner on the other side of the world. Trust is not granted once and forgotten. It is earned again at every step.

Because nothing is taken on faith, the model suits the untidy reality of working with outside vendors, who often need to reach sensitive data to do their job.

Vetting vendors as an ongoing duty

Vendor vetting is the work of checking a partner before giving them access: their security posture, their reliability and their record. Under a Zero Trust model, vetting is not a form completed at the start of a contract and filed away. It continues for as long as the partnership lasts, because a partner's security can shift as quickly as your own.

The critical elements

Six habits of Zero Trust vendor vetting


Taken together, these practices turn a one time check into a standing discipline.

One

Initial assessment

Begin with a careful review of the vendor: the certifications they hold, the practices they follow and the record they have built. This first pass decides whether a partnership should begin at all.

Two

Continuous monitoring

Watch vendor activity as it happens and revisit their security posture at set intervals, rather than trusting the result of an audit carried out years ago.

Three

Least privilege access

Give a vendor only the access needed for the task in hand, and nothing beyond it. Access that is not required should not exist in the first place.

Four

Multifactor authentication

Protect every access point with more than a password, so that a single stolen credential is not enough on its own to open a door.

Five

Microsegmentation

Divide systems into small, separate parts so that a breach in one place cannot spread freely through everything that sits beside it.

Six

Encryption

Keep data protected both in transit and at rest, so that information taken without authorisation stays unreadable to whoever holds it.

Practice, not a purchase

None of these measures is glamorous, and together they ask for steady attention rather than a single product. That is the point. Zero Trust treats security as a habit that is renewed, and vendor vetting as one more place where the habit has to be applied. Organisations that get this right keep the benefits of working with outside partners while narrowing the ways in which those partnerships can be turned against them.

Further learning

Readers looking to build practical expertise in Workday can benefit from a structured training programme. One example is this Workday Training, which provides learners with knowledge of Workday tools, features, and best practices, helping them develop the skills needed to work effectively with the platform.