Phase 1 — identity is the perimeter
Before buying another appliance, consolidate every human and service identity into one directory, enforce MFA on remote access and admin consoles, and kill shared credentials. In most audits we run, this single phase stops the attack paths that actually get exploited — phishing, VPN abuse, and orphaned admin accounts.
Phase 2 — segment what hurts most
Full micro-segmentation is a multi-year programme. Instead, draw two boundaries first: user networks away from server VLANs, and finance/HR systems away from everything. East-west traffic logging on those two boundaries gives auditors and incident responders 80% of the visibility at a fraction of the tooling cost.
Phase 3 — make it provable
Zero-trust that cannot be demonstrated fails vendor assessments and Bangladesh Bank ICT reviews alike. Keep a living matrix of identity → resource access, run quarterly access recertification, and capture evidence as you go rather than reconstructing it before an audit.




