Never Trust, Always Verify
The era of the perimeter-based security model is over. Attackers rely on harvested credentials, compromised identities, and the implicit trust organisations extend inside their networks. VSS's Zero Trust Cybersecurity Framework provides a structured, repeatable, and business-aligned methodology for guiding customers through a complete Zero Trust transformation.
As a Microsoft Gold Partner with certified expertise across Microsoft Entra, Intune, Defender, Sentinel, and Purview, VSS translates the complexity of Zero Trust architecture into a practical, phased, affordable adoption journey — from initial strategy through to continuous operational maturity.
End-to-end Zero Trust security across all six pillars.
VSS Zero Trust Framework
Aligned to MCRA (April 2025), NIST CSF v2, and CISA Zero Trust Maturity Model.
Six pillars: Identity, Devices, Applications, Data, Networks, and SecOps.
Nine structured services from assessment to annual SLA support.
15+ years of cybersecurity practice across East Africa.
Core Security Services
2–3 day readiness workshop
Entra ID, MFA, PIM, Conditional Access
Intune, Defender for Endpoint
Sentinel SIEM, Defender XDR
Verify Explicitly. Least Privilege. Assume Breach.
Implement a security architecture that verifies every access request using all available signals — identity, device, location, and risk.
Read MoreSix Pillars
Identity to SecOps coverage.
Four Stages
Foundation to optimisation.
Compliance
KDPA, GDPR, NIST, ISO 27001.
AI-Integrated
Security Copilot & Sentinel AI.
The Threat Reality
Why the perimeter-based security model is over
The era of the perimeter-based security model is over. Attackers no longer rely on sophisticated zero-day exploits — they rely on harvested credentials, compromised identities, and the implicit trust that organisations still extend inside their own networks. For VSS's customers across East Africa and beyond, this threat reality is compounded by:
The VSS Position
VSS is uniquely placed as a Microsoft Gold Partner (MPN ID: 6255974) with certified expertise across Microsoft Entra, Intune, Defender, Sentinel, and Purview to translate the complexity of Zero Trust architecture into a practical, phased, affordable adoption journey that creates measurable value for customers at every stage. Grounded in 15+ years of cybersecurity practice and the Microsoft Cybersecurity Reference Architecture (MCRA), our framework provides a structured, repeatable, and business-aligned methodology for guiding customers through a Zero Trust transformation.
What Zero Trust Actually Means
Zero Trust is not a product — it is a security strategy and architecture philosophy
Verify Explicitly
Every access request — from any user, any device, any location — must be authenticated and authorised using all available signals: identity, device health, location, application, and data sensitivity.
VSS Implementation
Microsoft Entra ID + Conditional Access + MFA + Identity Protection
Use Least Privilege
Access is granted with the minimum permissions required, for the shortest time necessary. Just-In-Time (JIT) and Just-Enough-Access (JEA) replace standing broad permissions.
VSS Implementation
Entra ID Governance, PIM/PAM, Conditional Access, Intune Compliance
Assume Breach
Design every system assuming attackers are already inside. Minimise blast radius through network segmentation, encrypt everything, and operate with continuous detection, response, and recovery readiness.
VSS Implementation
Microsoft Sentinel, Defender XDR, Purview, Backup & Recovery, Incident Response Playbooks
Five Zero Trust Business Scenarios
Adapted from the Microsoft Security Adoption Framework (SAF)
Secure Remote & Hybrid Work
Users working from unmanaged devices and uncontrolled networks; credential theft through phishing; password fatigue
Identify & Protect Sensitive Business Data
Client data, financial records, and PII exposed through uncontrolled sharing, unsanctioned apps, and no classification
Rapidly Modernise Security Posture
No visibility into security health; unsure what is exposed; failing regulatory audits; no baseline to measure against
Meet Regulatory & Compliance Requirements
Growing compliance obligations under KDPA 2019, GDPR, ISO 27001, and sector-specific regulations
Prevent / Reduce Breach Damage
No incident response plan; no detection capability; no segmentation; attackers can move laterally unchallenged
Four-Stage Implementation Model
Progressive stages aligned to the Microsoft SAF staging model
Foundation & Visibility
Assess current state. Identify risks, gaps, and regulatory requirements. Establish MFA, SSO, and basic identity hygiene. Deploy Microsoft Secure Score. Set leadership expectations and define KPIs.
Controls & Hygiene
Deploy device management (Intune), implement Conditional Access, introduce DLP and classification labels, inventory digital estate, begin compliance tracking.
Automation & Detection
Deploy SIEM (Sentinel) and XDR capabilities. Automate labelling and DLP enforcement. Implement insider risk management. Establish security dashboards and threat hunting.
Continuous Optimisation
Passwordless authentication rollout. Extend protection to SaaS and on-premises. Formalise incident response playbooks. AI-assisted threat monitoring. Ongoing Secure Score reviews.
The Six Zero Trust Pillars
VSS implements controls across all six interconnected pillars, aligned to MCRA and NIST SP 800-207
VSS Zero Trust Service Portfolio
Structured services that can be scoped and combined to match each customer's budget, maturity level, and risk priorities
| Service | Delivery Format | Description |
|---|---|---|
| Zero Trust Readiness Assessment | 2–3 Day Workshop | Current state architecture review across all six pillars. Secure Score baseline. Regulatory gap analysis. Prioritised remediation roadmap delivered as a formal written report with executive summary. |
| Identity & Access Modernisation | 4–8 Weeks | End-to-end Entra ID deployment: MFA, SSO, Conditional Access, Hybrid AD Connect, PIM. Includes device registration, basic Intune compliance, and knowledge transfer to IT admins. |
| M365 Security Premium Uplift | 2–4 Weeks | Licensing upgrade from M365 Business Standard to Premium. Activation of Defender for Business, Intune, AIP, and advanced compliance features included in Premium SKU. |
| Data Protection & DLP Programme | 4–8 Weeks | Purview sensitivity label taxonomy design, DLP policy deployment, Teams secure configuration, Compliance Manager regulatory tracking. Includes user training on data classification. |
| Endpoint Security & Intune | 3–5 Weeks | Full Intune MDM/MAM deployment: device enrolment, compliance policies, App Protection for BYOD, Defender for Endpoint EDR, and Conditional Access device compliance integration. |
| Microsoft Sentinel SIEM Deployment | 4–8 Weeks | Sentinel workspace setup, data connector configuration, analytic rules, UEBA, incident management workflow, and 30-day threat hunting engagement. Includes incident response playbook templates. |
| Zero Trust Network Access (ZTNA) | 2–4 Weeks | Microsoft Entra Private Access and Internet Access deployment replacing legacy VPN. Identity-aware network access control with device compliance enforcement. |
| Security Awareness Training Programme | Ongoing | Microsoft Cybersecurity Awareness Kit deployment, phishing simulation campaigns via Defender Attack Simulator, and quarterly training completion reporting. |
| Annual Zero Trust SLA | 12-Month Retainer | Quarterly Secure Score reviews, monthly Sentinel threat summary, patch management advisory, policy update service, and prioritised support SLA (P1: 1hr, P2: 4hr, P3: 8hr response). |
AI and Zero Trust — The Symbiotic Imperative
AI and Zero Trust have a symbiotic relationship — each strengthens the other
How AI Changes the Threat Landscape
- AI amplifies attackers: More convincing phishing, automated credential stuffing, deepfake social engineering at scale
- AI increases data sensitivity: AI queries against poorly governed data can surface sensitive information to unintended users
- New attack surface: Prompt injection, data leakage, and model manipulation risks from AI applications
How VSS Leverages AI for Defence
- Security Copilot: AI-powered incident summarisation, threat intelligence correlation, and guided incident response
- Sentinel AI Analytics: ML-powered multi-stage attack detection correlating signals across identity, device, and network
- Defender XDR AI: Automatic investigation and correlation of alerts into incidents, reducing analyst triage time
Four AI Security Imperatives (MCRA 2025)
Regulatory Compliance & Zero Trust
VSS maps Zero Trust controls to the regulatory frameworks most relevant to customers in East Africa
Kenya Data Protection Act 2019
Kenya
Data discovery and classification (Purview), DLP policies, data subject rights support, encryption, audit trails, breach notification readiness
GDPR
EU / Global
Sensitivity labels with rights management, DLP policies, data residency controls, eDiscovery and audit, consent and subject rights management
ISO/IEC 27001
International
Comprehensive security management via Compliance Manager with built-in ISO 27001 assessment across all six Zero Trust pillars
NIST CSF v2
International
Full alignment: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — mapped across all Zero Trust pillars
PCI-DSS v4.0
Payment Industry
Network segmentation, encryption, strong authentication (MFA/CA), access logging (Sentinel), vulnerability management
SWIFT CSP
Financial Sector
Privileged access security (PIM, PAWs), endpoint hardening, anomaly detection (Sentinel UEBA), network segmentation
Trust Indicators
Microsoft Gold Partner
MPN ID: 6255974 with security specialisation
Certified Professionals
CEH, CCNP, CRISC, ITIL certified team
15+ Years Experience
Cybersecurity practice across East Africa
Framework Aligned
MCRA, NIST CSF v2, CISA ZT Maturity
Success Story
98% Reduction in Phishing Susceptibility
A leading banking institution in East Africa partnered with VSS to transform their security posture. Through comprehensive security awareness training, Microsoft Defender deployment, and Zero Trust implementation, we dramatically reduced their vulnerability to social engineering attacks.
Recommended First Steps
Zero Trust Readiness Assessment
2–3 day workshop producing a written readiness report with Secure Score baseline, gap analysis, and prioritised 12-month roadmap.
Sponsor Alignment Session
90-minute executive briefing to align CEO/CIO/CISO on the Zero Trust business case, regulatory obligations, and investment roadmap.
Identity & MFA Quick Win
Deploy Microsoft Entra MFA and Conditional Access for all users within 30 days — the fastest and most impactful security investment available.
Licensing Review
Microsoft 365 licensing review to identify security features you've already paid for but haven't activated (Defender, Intune, AIP, Compliance).
Start Your Zero Trust Journey
Zero Trust is a journey, not a destination. Every customer starts somewhere — and every improvement matters. VSS meets you where you are, prioritises based on real risk, and delivers controls that work invisibly for your users.
Get a Free Zero Trust AssessmentFrequently asked questions
Common questions about cybersecurity and Zero Trust for businesses in East Africa.
