Zero trust replaces the old "castle and moat" model — where anything inside the corporate network was trusted — with a simple principle: never trust, always verify. Every request to access a resource is authenticated and authorised on its own merits, regardless of where it comes from, because "inside the network" is no longer a meaningful boundary once people work remotely and systems live in the cloud.
In practice it means strong identity, least-privilege access (each user and service gets only what it needs), and continuous verification rather than a single login at the perimeter. It is a direction of travel and a set of principles more than a product you buy, and applying it well is about design, not a single switch.
Related terms