ISEC7 Digital Workplace Blog

Security Maturity Model Part 2: Enterprise and Zero Trust

Written by Remi Keusseyan | Oct 19, 2021, 7:30:00 AM

Reviewed and updated in October 2026.

How do you secure an environment that is already complex, and keep it simple enough for users that they do not work around the rules meant to protect them? Continuing our security maturity model series, this part looks at the additional needs of larger organizations and of organizations spread across several countries.

At levels 3 and 4 of a security maturity model, the basics are in place and the work shifts from adding products to making them work together: trained users, independent audits, continuous monitoring and, at the top, a Zero Trust architecture in which every access request is verified. That is also where formal models such as CISA's Zero Trust Maturity Model become useful as a yardstick. Levels 1 and 2 are covered in Security Maturity Model, Part 1.

Level 3: Small and medium-sized enterprises (SME)

Level 3 deals mainly with small and medium-sized enterprises. These companies have several locations around the country plus some permanent remote workers. There is a proper IT infrastructure, local, cloud-based (for example Microsoft 365) or hybrid, run by a small team of skilled staff who are fully responsible for maintenance, support and capacity management.

Everything from levels 1 and 2 still applies: insure your business, protect your data, protect your endpoints, manage your endpoints and protect your local network. These measures are added.

Educate your employees

Training makes sure your employees are not part of the problem. They need to know the processes in place and what is expected of them. Listen to their concerns and needs and build them into your policies instead of fighting them; that is also the best way to get policies adopted and followed. Always balance security and usability, so users understand why a rule exists. More on this in Why Training Is Important and Training as Your First Line of Defense.

Audit your security posture

Have an independent third party audit your security posture regularly, to validate it and find any flaws that need to be addressed.

Proactively monitor your organization

When you host corporate resources and services yourself, you need a monitoring solution that keeps them available and detects any service degradation or interruption early enough to react. Most solutions focus on servers and services. Consider one that also covers the mobile infrastructure and the endpoints, such as ISEC7 SPHERE, which monitors the systems, services, certificates and policies of a digital workplace across vendors in one console. That way you also know whether users can reach these resources from their mobile devices and work with their apps.

Availability monitoring is one half. The other is security event monitoring: collecting and correlating logs to detect attacks, usually in a Security Information and Event Management (SIEM) platform. Our article Human Oversight in the AI Era: Finding the Right Balance in TDIR and SIEM explains how detection and response work there.

Level 4: Large enterprises

Level 4 covers large enterprises with offices and employees in other countries. They face an extra layer of complexity: technical, such as connecting all offices securely; organizational, with different IT teams, languages, work cultures and time zones; and legal, with different labor and data protection laws.

Everything from levels 1 to 3 still applies, including training, audits and monitoring. One fundamental change is added.

Adopt a Zero Trust approach

As you move to the cloud to decentralize your infrastructure and make it available to all employees, wherever they are and whatever device they use, it is time to adopt Zero Trust. Its motto is "never trust, always verify". The Zero Trust architecture in a nutshell article summarizes the principles.

In practice, Zero Trust combines several security capabilities, among them risk-based authentication, multi-factor authentication (MFA), Conditional Access and Zero Trust Network Access (ZTNA).

Risk-based authentication continuously evaluates the risk of a request based on location, device, time of day, the data accessed and other signals. It then decides whether the request is legitimate or needs additional verification, for example through MFA, before access is granted. Where possible, use phishing-resistant MFA such as FIDO2 security keys or passkeys.

When services move to the cloud, they become reachable, though not accessible, from anywhere on the internet, unlike before, when they sat behind well-guarded walls. This is where ZTNA comes in: VPN-like control for cloud resources and SaaS on desktop and mobile devices, without getting in the user's way. How this extends to smartphones and tablets is explained in How to Extend ZTA to Your Mobility Infrastructure.

The right solution starts with your business

Whatever the size or reach of your organization, understanding your business and its operational needs is the basis for addressing your specific vulnerabilities. Cheap solutions save money immediately; after an attack that saving is gone, if they did not cover all of your vulnerabilities.

Frequently asked questions

What changes at level 3 of the security maturity model?

The technical basics are in place, so the focus moves to people and processes: employee training, regular independent audits and proactive monitoring of availability and security events.

Why should a third party audit the security posture?

An internal team tends to overlook gaps in what it built itself. An independent auditor validates the posture against an outside standard and finds flaws before an attacker does.

What does Zero Trust mean in a maturity model?

Zero Trust is the top level: no user, device or network is trusted by default, and every access request is verified. CISA's Zero Trust Maturity Model describes this progression in four stages from traditional to optimal across five pillars: identity, devices, networks, applications and workloads, and data.

What is the difference between risk-based authentication and MFA?

MFA asks for an additional factor. Risk-based authentication decides when to ask for it, based on signals such as location, device and time of day, so low-risk requests stay smooth and unusual ones are challenged.

ISEC7 supports organizations at every level, from endpoint security and endpoint management to trainings, and can provide an objective assessment of what your organization needs. Contact us.