← All Insights
Cloud

Zero Trust Implementation Guide for Philippine SMEs: Where to Start

August 29, 2026 · 7min read  · Technica Solutions Inc.

Zero Trust Implementation Guide for Philippine SMEs: Where to Start

Zero trust is not a product you buy. It is a security posture you build — one control at a time. The Bangko Sentral ng Pilipinas now mandates zero trust architecture for supervised financial institutions, and the National Privacy Commission's guidance on data governance applies the same principle to any organisation handling personal data under the Data Privacy Act. For Philippine SMEs, the question is no longer whether to adopt zero trust, but where to start without disrupting operations.

The answer is phased implementation, beginning with identity — the single control that stops the most breaches.

For background on what zero trust means and the regulatory context, read Technica's zero trust overview for Philippine businesses first. This article is the implementation companion: what to do, in what order, and at what cost.

Phase 1: Identity — The Highest-ROI First Step

Over 80% of data breaches involve compromised credentials. Fixing identity costs almost nothing if your organisation already has Microsoft 365 or Google Workspace — it is a configuration change, not a procurement project.

Actions for M365 businesses (Microsoft Entra ID):

  1. Enable MFA for every account — no exceptions, including shared accounts and service accounts. The minimum is Microsoft Authenticator app-based MFA; SMS OTP is being deprecated following BSP Circular 1213. Follow Technica's M365 MFA setup guide for the exact steps.
  2. Eliminate shared credentials — each person must have their own licensed account. Shared mailboxes are acceptable for incoming mail routing but must not be used as login credentials.
  3. Apply Conditional Access policies — require compliant devices and block sign-ins from high-risk locations. Start with a policy that blocks access from countries your team never works from. This is available in Microsoft Entra ID P1 (included in M365 Business Premium).
  4. Enable Microsoft Entra ID Protection — automatically detects risky sign-ins and risky users. Available in Entra ID P2 or M365 E5. For SMBs, the P1 Conditional Access policies cover most scenarios.

Actions for Google Workspace businesses:

  1. Enable 2-Step Verification and enforce it organisation-wide via the Admin Console → Security → 2-Step Verification → Enforcement.
  2. Enable Google's Advanced Protection Program for executives and administrators.
  3. Configure Context-Aware Access (available in Business Plus and above) to restrict access based on device and location.

What not to do at this phase: Do not buy a dedicated zero trust platform or ZTNA appliance before identity is secured. A compromised password bypasses any network control — identity is the perimeter now.

Phase 2: Devices — Block Unmanaged Endpoints

Once identity is secured, the next risk surface is unmanaged personal devices accessing corporate data.

For M365 organisations: Deploy Microsoft Intune to enrol corporate devices and define compliance policies — minimum OS version, encryption enabled, screen lock active, no jailbreak. Use Conditional Access to require device compliance as a condition of access. Unmanaged personal devices can be limited to browser-only access via Microsoft's App Protection Policies (no download, no copy-paste to personal apps).

For Google Workspace organisations: Use Google's endpoint management (Admin Console → Devices) to enforce screen lock, encryption, and block unapproved devices. Mobile devices can be managed without installing a full MDM agent for basic controls.

Philippine context: Remote and hybrid work is now standard across Philippine SMBs following 2020–2022 normalisation. The device fleet accessing corporate data typically includes a mix of company-issued laptops, personal mobile phones, and home computers — all connecting over residential broadband with no network-level filtering. Phase 2 controls close this gap without requiring a VPN.

Phase 3: Network — Remove Implicit Trust from the Internal LAN

The traditional assumption that "inside the office network = trusted" is the core flaw zero trust fixes. An attacker who reaches the internal LAN via a phishing email or compromised device can move laterally without restriction in a flat network.

Actions:

  1. Segment the network — separate staff workstations, servers, CCTV/IoT devices, and guest Wi-Fi into VLANs. A FortiGate or Palo Alto firewall with inter-VLAN policies enforces this at the network level.
  2. Deploy ZTNA for remote access — replace the traditional VPN with Zero Trust Network Access. Microsoft Entra Private Access provides per-application access without exposing the full network to remote users. Users authenticate through Entra ID; only the specific application they need is accessible, not the entire internal network.
  3. Enable DNS filtering — block connections to known malicious domains at the DNS layer. Microsoft Defender for Endpoint includes DNS filtering; FortiGate includes FortiGuard DNS filtering as part of its subscription.

Phase 4: Data — Classify, Label, and Audit

The final phase targets the data itself: knowing what you have, who can access it, and whether that access is being used appropriately.

Actions:

  1. Classify sensitive data — use Microsoft Purview (included in M365 Business Premium and E3) to identify and label documents containing personal data, financial records, and confidential business information.
  2. Apply Data Loss Prevention policies — prevent accidental sharing of labelled documents via email, Teams, or OneDrive to external recipients.
  3. Enable audit logging — M365 Unified Audit Log captures all user activity across Exchange, SharePoint, Teams, and Entra ID. Retain logs for at least 90 days (NPC breach notification requirements assume you can reconstruct what happened).

NPC alignment: The NPC's advisory on data breach notification requires organisations to notify affected parties within 72 hours of discovering a breach. Having audit logs in place is not optional — it determines whether you can meet that deadline.

Implementation Timeline for a Typical Philippine SMB

PhaseEffortElapsed TimeCost (if M365 Business Premium)
Phase 1: Identity1–2 daysWeek 1₱0 — configuration only
Phase 2: Devices3–5 daysWeek 2–3₱0 — Intune included
Phase 3: Network1–2 weeksMonth 2FortiGate/PA subscription cost
Phase 4: Data2–4 weeksMonth 3₱0 — Purview included

The entire Phase 1 and Phase 2 implementation is available within an existing M365 Business Premium licence. Most Philippine SMBs underutilise the security features already included in licences they pay for every month.

Technica Solutions Inc. implements zero trust for Philippine SMBs across all four phases — identity hardening, Intune device management, network segmentation, and Purview data governance.


Related reading

Talk to our Cloud & I.T. team
Related Insights

More on Cloud

← Back to Insights