Zero trust, SASE, shared responsibility, and defence in depth are the frameworks shaping how organisations secure hybrid environments. This guide explains each model, why they are difficult to implement consistently, and how to close the gap between theory and practice.
Security models provide the conceptual foundation for how organisations protect their data, applications, and infrastructure. The gap between understanding these models and implementing them consistently across hybrid, multi-cloud, and legacy environments is where most security programmes struggle.
Organisations typically operate across multiple models simultaneously: applying zero trust principles to user access, adopting SASE for branch connectivity, and managing shared responsibility across AWS, Azure, and on-premises systems, all while maintaining audit trails for compliance frameworks. Without a unified approach to applying these models consistently, the result is security gaps, operational overhead, and compliance problems that compound over time.
This guide covers the four major security models, the common challenges that prevent effective implementation, and the misconceptions that cause organisations to misapply them.
Zero trust assumes that threats exist both inside and outside the network perimeter. Every user, device, and connection is treated as unverified until proven otherwise. Access is granted based on continuous verification of identity, device health, and context – not on network location.
Traditional perimeter-based security fails in hybrid environments where users, applications, and data exist across multiple locations and providers. Zero trust provides a framework for securing access regardless of where resources live or where users connect from.
Three principles define the model. First, verify explicitly using all available signals: identity, location, device health, workload classification. Second, apply least privilege access – grant only the minimum permissions required for the task. Third, assume breach and segment networks accordingly, monitoring continuously to contain potential compromises if they occur.
Our zero trust guide covers implementation in detail, including how ZTNA relates to the broader model.
Secure Access Service Edge (SASE) combines software-defined WAN capabilities with cloud-delivered security services – Secure Web Gateway, Cloud Access Security Broker, Firewall as a Service, and zero trust network access – into a unified platform.
SASE addresses the challenge that organisations no longer have a single, defined perimeter. Users, applications, and data are distributed across branches, remote workers, multiple clouds, and legacy data centres. SASE delivers security that follows users and workloads rather than being anchored to fixed network locations.
The practical benefits are consistent security policy enforcement regardless of where users or applications reside, reduced complexity from consolidating multiple security tools into one platform, and improved performance through cloud-delivered services closer to users. For organisations with multiple sites, remote workers, and cloud migrations underway, SASE principles address a class of problem that traditional approaches cannot.
Our SASE guide covers the architecture in depth, including the distinction between a genuine SASE platform and a bundled product set.
The shared responsibility model defines the division of security obligations between cloud providers and their customers. The provider secures the infrastructure – physical security, the hypervisor, and the network infrastructure underneath. Customers secure everything they deploy into the cloud: data, applications, identity management, and access controls.
Misunderstanding shared responsibility causes many cloud security failures. Organisations assume their cloud provider handles security comprehensively, only to discover – often following an incident – that data protection, access management, and application security remain their obligation.
The dividing line is consistent across AWS, Azure, and Google Cloud. Physical security and the virtualisation layer sit with the provider. Data encryption, identity and access management, application security, operating system patching, network traffic controls, and compliance evidence all sit with the customer. The cloud provider gives you the tools; configuring and governing them correctly is your responsibility.
Defence in depth applies multiple independent layers of security controls throughout an IT environment. If one layer fails, others remain to prevent or limit damage. The layers typically include perimeter controls, network segmentation, endpoint protection, application security, data encryption, and security monitoring.
No single security control is foolproof. Defence in depth ensures that a vulnerability in one area does not compromise the entire environment. For organisations handling sensitive data, the layered approach is also often a compliance expectation, not just a security preference.
In practice this means perimeter controls such as firewalls and DDoS protection, network segmentation and intrusion detection at the network layer, endpoint detection and response, web application firewalls and secure development practices at the application layer, encryption at rest and in transit for data, and multi-factor authentication and privileged access management for identity.
Understanding security models is one thing. Applying them uniformly across hybrid, multi-cloud, and legacy environments is where most organisations encounter real difficulty.
The gap between security theory and security practice closes when three things come together: unified visibility across the full estate, consistent policy enforcement regardless of where traffic originates, and an operating model that does not require security expertise at every point in the infrastructure.
Unified visibility means a single view of connectivity, security events, and traffic flows across cloud environments, data centres, branches, and remote users – giving security teams the access patterns and audit trail that zero trust and compliance frameworks require.
Consistent policy enforcement means applying the same security controls whether a user is in the office, at home, or connecting from a third-party site – and whether traffic is flowing between on-premises systems, cloud environments, or out to the internet. Integrated security that is built into the connectivity layer rather than layered on top of it is what makes this achievable at scale.
A managed operating model addresses the skills and complexity challenge directly. Defence in depth across a hybrid estate does not require in-house expertise across every security technology if the managed service is designed to provide that capability as part of the service.
Cloud Gateway delivers connectivity and security as an integrated platform, with the visibility, policy enforcement, and operational support that makes security models practical rather than aspirational. For more on how the platform supports regulated organisations across these requirements, see our Protect page and our platform page.