Cybersecurity
By Compulink Technologies, Inc. · 6 min read
Zero trust is no longer a buzzword for government IT. It is a mandate. The real question isn't whether your agency will adopt it, but where to begin without ripping out everything you already own.
Talk to any government IT leader about zero trust and you'll hear the same two reactions. First: "We know we have to do this." Federal directives, CISA guidance, NIST 800-207, and cyber insurance requirements have all made that clear. Second: "We have no idea where to start."
That hesitation is understandable. Zero trust is often presented as a complete architectural overhaul, which sounds like a multi-year, multi-million-dollar project. For an agency running legacy applications, shared workstations, and a network built over two decades, that framing is paralyzing.
Here's the good news: zero trust is not a product you buy or a project you finish. It is a set of principles you apply in stages, and the first stages are far more achievable than most agencies assume. After four decades supporting public sector networks across the Tri-State region, here is where we tell our clients to begin.
Understand What Zero Trust Actually Means
Strip away the vendor marketing and zero trust comes down to one principle: never trust, always verify. No user, device, or application gets access to anything simply because it is inside the network perimeter. Every request is authenticated, authorized, and continuously evaluated.
CISA's Zero Trust Maturity Model breaks this into five pillars, and it is the framework most agencies should anchor to:
| Pillar | The question it answers |
| Identity | Is this really the person they claim to be? |
| Devices | Is this device known, healthy, and compliant? |
| Networks | Can a breach in one segment spread to others? |
| Applications | Is access to each app limited to who needs it? |
| Data | Is sensitive data classified, encrypted, and tracked? |
You do not need to advance all five pillars at once. You need a starting point that reduces the most risk for the least disruption. For nearly every agency, that starting point is identity.
Start with Identity: The Highest-Impact First Move
The overwhelming majority of successful attacks on government networks begin with a compromised credential, not a sophisticated exploit. A phished password on a legacy VPN can hand an attacker the keys to everything behind the perimeter. That is exactly the failure zero trust exists to prevent.
Three identity moves deliver the most protection per dollar:
Phishing-resistant MFA everywhere
Not just for remote access. Email, admin consoles, HR systems, and legacy apps too. Prioritize phishing-resistant methods over SMS codes, which attackers now bypass routinely.
Least-privilege access
Audit who can access what, and remove standing permissions nobody uses. In most agencies we assess, a large share of accounts hold access they haven't touched in a year. Every one is unnecessary attack surface.
Privileged account cleanup
Admin accounts, service accounts, and contractor logins that outlived their contracts. These are the accounts attackers hunt first, and the ones agencies most often forget.
Key takeaway
If your agency does only one thing this year, make it phishing-resistant MFA plus a privileged account audit. It is the single biggest zero-trust win available.
You Can't Protect What You Can't See
The second move is visibility. Zero trust requires deciding, for every access request, whether the device making it should be trusted. That is impossible if you don't know what devices exist.
Government networks accumulate endpoints the way basements accumulate boxes: workstations from three refresh cycles ago, building sensors nobody documented, printers with open management ports, and personal devices that found their way onto staff Wi-Fi. Each unknown device is a blind spot.
A network discovery and asset inventory exercise gives you the map. From there, device compliance becomes enforceable: patched operating systems, current endpoint protection, and encryption before a device touches sensitive systems. If you followed our earlier guidance on planning hardware refreshes around your funding cycle, you already have the foundation, because a lifecycle inventory and a zero-trust asset inventory are largely the same exercise.
Segment the Network to Stop Lateral Movement
Ransomware doesn't devastate agencies because one machine gets infected. It devastates them because one infected machine can reach hundreds of others. Flat networks turn a single phished workstation into an agency-wide incident.
Segmentation is the network pillar of zero trust, and it doesn't have to start with full microsegmentation. Start coarse: separate public-facing services from internal systems, isolate finance and HR from general staff networks, and put building systems and IoT devices on their own segments. Then verify that traffic between segments is inspected and restricted to what's actually needed.
Modern firewall platforms from partners like Fortinet make this far more manageable than it was a decade ago, with policies that follow users and applications rather than just IP addresses. Much of the capability may already exist in equipment you own; it simply was never configured.
Phase It, Fund It, and Put It in Writing
Zero trust fails in government when it's pitched as one giant project. It succeeds when it's phased across budget cycles, with each phase delivering measurable risk reduction on its own.
A realistic multi-year shape looks like this:
Two funding notes from the procurement side. First, make zero trust a visible, named line in your budget request; compliance-driven investments buried in general IT are the first to get cut. Second, use the contract vehicles available to you. Cooperative purchasing agreements, state contracts like NYS OGS, and MBE procurement pathways can compress months of buying process into weeks, which matters when a directive comes with a deadline.
Rule of thumb
Every phase should stand on its own: funded in one budget cycle, deployed in months, and reducing real risk even if the next phase slips.
Where to Start
If this still feels like a lot, remember that the first step is neither expensive nor disruptive: a zero-trust readiness assessment. It maps your current environment against the CISA maturity model, identifies which gaps carry the most risk, and produces a phased roadmap your agency can actually fund.
Compulink Technologies has spent 40 years securing and supporting government, education, and healthcare networks across the Tri-State region. As an MBE-certified partner with 35+ manufacturer relationships and access to state and cooperative contract vehicles, we help agencies move from mandate to roadmap to deployment, one funded phase at a time.
Ready to map your path to zero trust?
Contact our team for a zero-trust readiness assessment.
Schedule Your Assessment+1 (212) 695-5465 · sales@compu-link.com

