Cybersecurity · 10 min read
Zero Trust Sounds Strict. Asia Mid-Market Reality Is Messier
Zero trust is not a product SKU. It is a sequence of identity, device, and network decisions that mid-market firms must stage without freezing the business.
Vendors love the phrase zero trust. Boards ask for it after a headline breach. Engineers inherit a spreadsheet of tools and a deadline. The gap between slogan and practice is where many APAC mid-market programs stall. The spreadsheet grows. The shared passwords linger. The diagram looks finished while the estate does not. Zero trust means continuous verification of identity, device posture, and context before access, with least privilege as the default. It does not mean buying every category in a Gartner magic quadrant on the same purchase order. Sequence beats shopping. Shopping without sequence is how budgets vanish into overlapping agents that nobody tunes.
Where to start without theater
Identity first. Centralize SSO for SaaS. Kill shared admin passwords. Enforce MFA that resists basic phishing. A hospital group in Chennai began there. Phishing still happened. Blast radius shrank because compromised passwords no longer opened the entire estate. The help desk hated the first month. The security team slept better by the third.
Next, segment admin paths. Privileged access should not ride the same network assumptions as general staff browsing. Jump hosts and just-in-time elevation feel inconvenient. They are cheaper than a ransomware weekend. Device posture follows. You cannot claim zero trust while unmanaged personal laptops have lasting VPN routes into production. Start with corporate devices for high-sensitivity roles, then expand with clear exceptions and expiry dates.
A concrete failure mode
A Hong Kong professional services firm rolled out a new secure access broker and left legacy VPN accounts active "for a transition month." Attackers used the legacy path. The new broker logs looked clean. The lesson is dull and important: parallel access paths defeat the control plane. Transitions need forced cutovers with monitored exceptions, not polite overlap that never ends.
Caution: aggressive lock-downs without change management create shadow IT. People will invent workarounds with consumer file sharing. Security that ignores workflow becomes security theater with extra steps. Pair every control with a supported alternative path that is only slightly less convenient than the unsafe habit you are killing.
Sequencing for mid-market teams
- Inventory critical apps and data; protect the crown jewels first.
- Replace shared credentials before buying exotic detection toys.
- Measure mean time to revoke access when someone leaves.
- Run tabletop exercises that include identity compromise, not only malware.
- Publish a quarterly access review that executives actually attend.
Vendors, metrics, and the long middle
Mid-market teams should resist the urge to buy a full zero-trust suite on day one. Identity modernization plus path reduction often delivers more risk reduction per dollar than an advanced analytics package nobody has time to tune. Ask vendors for deployment stories in companies of your size in your region. Global reference logos from banks with thousand-person security teams are entertaining and not transferable.
Track a short list of outcome metrics: percentage of apps behind SSO, percentage of privileged sessions that are just-in-time, mean time to revoke access, and number of standing VPN exceptions. Publish them to leadership quarterly. When the metrics stall, you have a program problem, not a slide problem. Zero trust is a direction of travel. Pretending you arrived after one purchase order is how exceptions become the real architecture. Across APAC markets, the constraint is rarely a lack of tools. It is a lack of sequenced decisions that survive contact with procurement, language reality, and peak-season load. Sequence the decisions. Publish the owners. Revisit the sequence when the metrics stall instead of buying another overlapping category. A useful internal test is whether a skeptical finance partner can understand the unit economics without a translator from engineering slang. If the story only works in a specialist room, it is not ready for production funding. Translate early. Funding follows comprehension more often than it follows novelty.
Takeaway
Treat zero trust as a multi-quarter program of identity hygiene, path reduction, and least privilege. Buy tools to support that program. Do not buy a slogan and hope the diagram becomes reality. Messy estates get cleaner in stages. The stages that stick are the ones the business can still operate through.
More from the desk
Asia AI Adoption Reality: Pilots Everywhere, Production Where the Data Is Ready
Board decks claim AI transformation. On the ground across Asia, winners invest in data quality, workflow redesign, and measured use cases—not model names.
Read →Developer Experience Is a Competitive Edge Hiding in Your Build Times
Slow CI, flaky tests, and tribal setup docs tax every feature. Asian tech firms that treat DX as strategy ship calmer releases and hire with less friction.
Read →IoT for Connected Operations: Sensors Are Easy. Decisions Are Hard
Factories and logistics fleets across Asia are full of devices. Value appears only when data becomes timely decisions with clear owners and safe controls.
Read →