Skip to main content
zero trust security for businesses

1. Our company is too small for a sophisticated breach. Do we really need zero trust?

Small and mid-sized businesses are frequently targeted precisely because attackers expect lighter security. Credential-based attacks don’t discriminate by company size, and the consequences of a breach are proportionally more damaging for smaller organizations.

2. We already use MFA. Does that mean we're doing zero trust?

MFA is one component of zero trust, but not the whole model. Zero trust also requires device validation, least privilege access, network segmentation, and continuous session monitoring. MFA alone doesn’t address lateral movement or insider risk.

3. How long does it take for an MSP to implement zero trust for a 50-person business?

A phased implementation typically takes 6 to 12 weeks depending on the complexity of your current environment and the number of applications involved. Identity and MFA hardening can often be completed in the first two weeks.

4. Will zero trust affect how my employees log in and work every day?

There will be some adjustment, primarily around MFA prompts and occasional additional verification for sensitive systems. Well-implemented zero trust is designed to minimize friction for compliant users while creating meaningful barriers for unauthorized access.

5. Can zero trust help with compliance requirements like HIPAA, PCI-DSS, or SOC 2?

Yes. Zero trust principles directly address many compliance requirements around access control, audit logging, data segmentation, and incident detection. An MSP experienced in compliance frameworks can align your zero trust implementation to specific regulatory requirements.

John Angelotti

John Angelotti is the President of DCG Technical Solutions, beginning his technology journey on a Commodore 64 and at swap meets with his mother. For more than two decades, he has helped businesses grow through secure, strategic, and cost-effective IT leadership.

At DCG, he works to ensure clients can grow without worrying about downtime. As the leader of a security-forward MSP, he develops tailored solutions that safeguard each client’s operations and reputation.

John is known for making complex technology easy to understand and guiding organizations through key improvements, from cloud migrations to cybersecurity hardening. Outside of work, he enjoys building things with his hands, archery, hiking, and competitive custom car audio.