
Zero Trust networking: practical microsegmentation for SMBs
Less "trust the internal network," more VLANs, NAC, and identity-based policies. Zero Trust without buzzword bingo.
Zero Trust is not a product you buy; it is stopping the assumption that "inside the Hato Rey office" means safe. NIST SP 800-207 defines principles: verify explicitly, least privilege, assume breach. For a 60-person SMB, that means achievable microsegmentation, not overnight enterprise ZTNA deployment.
Start with logical VLANs: guest, corporate, servers, IoT/cameras. Firewall between segments with default deny rules. CISA publishes segmentation guidance for ransomware defense — a compromised reception laptop should not reach accounting NAS or multifunction printers storing credentials.
Identity as perimeter: traditional VPN extended flat network to home; replace with per-application access (M365, cloud ERP) with MFA and conditional access. Bruce Schneier has criticized Zero Trust term fetishization, but underlying controls — not trusting internal IP — are healthy for Puerto Rico SMBs with post-2020 hybrid work.
Light NAC: 802.1X where switches allow, or at minimum DHCP inventory and unused port blocking. Host microsegmentation with local firewall on critical stations is a cheap intermediate step. You do not need Illumio; you need an updated network diagram and documented rules.
Measure progress: tabletop where simulated attacker moves laterally from guest WiFi. If they reach the domain controller in minutes, your Zero Trust is a slide deck. Puerto Rico SMBs in shared buildings with neighbor WiFi — segmentation is not luxury, it is hygiene.

Operations and execution — connecting strategy with what the team ships every week.


