Skip to content
Content Hub

Zero Trust - Security Model

Everything about Zero Trust architecture: the "never trust, always verify" principle, microsegmentation, ZTNA, implementing the Zero Trust model in your organization. Expert guides from nFlo.

34 articles 3 categories

All Zero Trust articles

Knowledge base 6/17/2026

Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access

Device Code Phishing abuses a flow that most organizations don't even need. We show how to disable or restrict the Device Code Flow in Entra ID with Conditional Access — step by step, with pitfalls and validation.

Knowledge base 4/17/2026

What is passwordless authentication? Methods, benefits and implementation

Passwordless authentication eliminates passwords, replacing them with biometrics, hardware keys and magic links. How it works and how to implement it.

Knowledge Base 4/13/2026

Passwordless Authentication: The Future of Secure Login

Passwordless authentication eliminates passwords in favor of biometrics, passkeys, FIDO2 tokens, and magic links. Learn how it works, why it's more secure, and how to implement it.

Knowledge Base 4/3/2026

CIEM — What Is Cloud Infrastructure Entitlement Management?

CIEM (Cloud Infrastructure Entitlement Management) addresses the critical problem of over-permissioned identities in multi-cloud environments. Learn how it works, how it compares to CSPM and CWPP, and best practices for implementation.

Knowledge Base 4/3/2026

ITDR — What Is Identity Threat Detection and Response?

ITDR (Identity Threat Detection and Response) is a security discipline focused on detecting and responding to identity-based attacks. Learn how it works, how it differs from IAM, PAM, and EDR, and why Gartner considers it essential.

Knowledge Base 4/3/2026

Network Design — How to Build a Secure Network Infrastructure

Network design is the process of planning and structuring a computer network to meet performance, scalability, and security requirements. Learn about architecture models, segmentation strategies, and security-first design principles.

Knowledge Base 4/3/2026

RBAC — What Is Role-Based Access Control and How to Implement It

RBAC (Role-Based Access Control) assigns permissions through roles rather than individual users. Learn how it works, how it compares to ABAC, DAC, and MAC, and how to implement it across Active Directory, Azure, and AWS.

Knowledge Base 4/3/2026

SSE — What Is Security Service Edge and How Does It Differ from SASE?

Security Service Edge (SSE) consolidates cloud security services — ZTNA, CASB, SWG, and DLP — into a unified platform. Learn how SSE works, how it compares to SASE, and what to consider when choosing a vendor.

Knowledge Base 4/3/2026

UEM — What Is Unified Endpoint Management and How Does It Work?

Unified Endpoint Management (UEM) consolidates the management of every device — laptops, smartphones, tablets, IoT — into a single platform. Learn how UEM works, how it evolved from MDM, and why it matters for security.

Knowledge Base 4/3/2026

VDI — What Is Virtual Desktop Infrastructure and How Does It Work?

Virtual Desktop Infrastructure (VDI) centralizes desktop environments on servers, delivering them to endpoints over the network. Learn how VDI works, its architecture, security benefits, and when to choose it over DaaS or RDS.

Knowledge Base 4/3/2026

Zero Trust VPN — What Is ZTNA and Why Is It Replacing Traditional VPN?

ZTNA (Zero Trust Network Access) is rapidly replacing traditional VPN as the standard for secure remote access. Learn how ZTNA works, how it compares to VPN, and how to plan a migration.

Knowledge base 3/18/2026

Global Cybersecurity Trends Analysis

Modern trends in cybersecurity include the growing importance of cloud security and Zero Trust, which has a key impact on organizational protection.

Knowledge base 9/24/2025

Cyber Security Landscape 2024-2025: defense strategies and security technologies

Learn about key defense strategies and security technologies for 2024-2025. The nFlo guide will help your organization effectively protect itself from growing cyber threats.

Knowledge base 6/20/2025

Network Microsegmentation — How to Limit Lateral Movement of Attackers in Your Organization

Network microsegmentation is the zero trust foundation. Learn how to design policies and deploy segmentation without disrupting production environments.

Knowledge base 5/24/2025

Purdue Model and OT Network Segmentation in Industry 4.0: How to Protect a Modern Factory

In the IT world, three years is an eternity. In the OT world, a 30-year-old concept is still the basis for designing secure networks. The Purdue model, as it is referred to, is not an outdated relic, but a timeless philosophy. In this article, we'll explain how its fundamental principles of segmenta

Knowledge base 5/22/2025

Zero Trust in OT Networks: Can the "Trust No One" Principle Work in a Factory with PLCs?

Zero Trust is a revolution in cyber security, but how do you implement the

Knowledge base 5/12/2025

Identity management in the digital age - A comprehensive guide

In the digital world, identity is the new security perimeter. It is no longer

Knowledge base 5/7/2025

The SASE revolution: FortiSASE's approach to secure access to edge services

How FortiSASE is revolutionizing secure access to edge services.

Knowledge base 3/15/2025

FortiSASE - comprehensive cloud security for modern organizations

Branch offices, remote workers, cloud applications - traditional security models don't work anymore. FortiSASE provides protection where users and data actually are.

Knowledge base 3/13/2025

FortiGate NGFW: Next-Generation Network Protection

Discover the advanced features of FortiGate NGFW that provide comprehensive network protection, ZTNA integration, and AI/ML-based scalability.

Knowledge base 11/12/2024

Network access control: capabilities and benefits of FortiNAC

How does FortiNAC provide full control over network access?

Knowledge base 9/16/2024

Azure Security Best Practices — A Complete Guide to Microsoft Cloud Security

Azure Security Best Practices — Defender for Cloud, NSG vs Azure Firewall, Entra ID, Key Vault, CIS benchmark compliance. A practical guide for businesses.

Knowledge base 7/31/2024

Zero Trust in Practice — How to Implement the Zero Trust Model Step by Step

Complete zero trust guide: MFA, least privilege, microsegmentation, ZTNA/SASE. Build zero trust architecture with a clear strategic transformation roadmap.

Knowledge base 7/22/2024

ZTNA vs VPN: How is Zero Trust Network Access revolutionizing secure remote access?

For years, VPN was synonymous with secure remote access. But in the era of the cloud and working from anywhere, its trust-based model has become a huge risk. ZTNA (Zero Trust Network Access) reverses this philosophy, offering granular, identity-based access to applications rather than the entire net

Knowledge base 7/10/2024

Network microsegmentation: how to stop an attacker who has already gotten in?

Traditional network security resembles a castle with a massive defensive wall, but an open space inside. Once an enemy overcomes the wall, he is free to plunder the entire kingdom. Microsegmentation is the construction of internal walls, bulkheads and locks that isolate every valuable resource, prev

Knowledge base 6/12/2024

Security for remote and hybrid work: How to protect your business when the office is everywhere?

The office is no longer a building. It's the employee's laptop in the home living room, the smartphone in the coffee shop and the tablet on the train. This revolution in the way we work, while flexible, has completely destroyed the traditional security model based on the network perimeter. So how do

Knowledge base 6/10/2024

Zero Trust in practice - how to implement the zero trust model in your organization

Never trust, always verify. The Zero Trust model assumes the attacker is already in the network. Learn how to practically implement this strategy.

Knowledge base 5/19/2024

Zero Trust OT — Factory Implementation: A Step-by-Step Guide

Zero Trust is a revolution in cyber security, but how do you implement the

Knowledge base 4/24/2024

Remote access to SCADA: How to enable service technicians to work without opening the door for hackers?

It's two in the morning, and a key machine on the production line breaks down. The only specialist who can fix it is 500 kilometers away. Remote access can save production and prevent gigantic losses. But one unsecured connection can also open the door to an attack that will cause an even bigger dis

Knowledge base 1/11/2024

Zero Trust in Identity Management (IAM): A Defensive Strategy for Modern Organizations

Learn how Zero Trust strategy and identity management (IAM) work together to strengthen an organization's security by continuously verifying access and minimizing risk.

Knowledge base 12/23/2023

ISO 27001 Internal Audit: How to Maximize Benefits for Your Organization

Learn how ISO 27001 internal audits support ISMS improvement by identifying gaps and increasing organizational resilience to threats.

Knowledge base 12/15/2023

What Is Zero Trust Architecture? Implementation in Large Organizations

The traditional

Knowledge base 11/30/2023

Identity and Access Management (IAM): who, what, where, when and why

Learn how Identity and Access Management (IAM) supports the Zero Trust model, enhancing an organization's security through continuous verification and access control.

Knowledge base 2/3/2023

What is ZTNA - Zero Trust Network Access? Definition, Principles, Operation, Protocols, Technologies and Benefits

Learn about the principles of Zero Trust Network Access (ZTNA) and its benefits for network security in organizations.

Want to implement the Zero Trust model?

nFlo will help you design and implement Zero Trust architecture: current infrastructure audit, microsegmentation, ZTNA and continuous identity verification.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist