
Zero Trust for SMBs: skip the marketing, start with identity
Zero Trust is not replacing your entire firewall tomorrow. A realistic roadmap for a services company in PR on a finite budget.
Vendors sell Zero Trust as a single suite; NIST SP 800-207 describes it as continuous trust architecture, not a product. For a 40-person SMB in Guaynabo, we start where it hurts: strong identity, asset inventory, and minimal access to critical apps — not datacenter microsegmentation you do not have.
Step one: honest inventory
Step one: honest inventory. Who accesses what from where? SaaS, legacy VPN, direct RDP to the remote accountant — map it. Step two: universal MFA on email, VPN, and cloud consoles. Step three: replace implicit-trust VPN with conditional access — compliant device, expected location, session risk.
Pragmatic segmentation: VLAN for guest WiFi, separate networ
Pragmatic segmentation: VLAN for guest WiFi, separate network for IP cameras and office IoT, firewall between servers and workstations. You do not need enterprise SD-WAN; you need to stop treating the internal network as sanctuary.
Identity monitoring: alerts when admins are created, when someone downloads 10GB from SharePoint at 3am, when a legacy user without active employment still authenticates. CISA Zero Trust Maturity Model is useful reading to prioritize without buying the whole catalog.
Zero Trust for LatAm SMBs is a two-year evolution, not a big-bang project. Each quarter close one measurable gap. Your insurance broker and enterprise clients will eventually ask — better to have an answer before the RFP.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


