---
title: Zero Trust Whitepaper - KPMG AG Wirtschaftsprüfungsgesellschaft
description: The Zero Trust model regularly reviews and evaluates authorizations and access to corporate data, meeting the security challenges of the new world of work and new technologies.
image: https://hub.kpmg.de/hubfs/LandingPages-Coverbilder/Trust_SoMe-1200x627.png
---

[![logo-plain-kpmg-2.png](https://hub.kpmg.de/hs-fs/hubfs/System/KPMG/logo-plain-kpmg-2.png?width=180&name=logo-plain-kpmg-2.png "logo-plain-kpmg-2.png")](https://home.kpmg.com/de/en/home.html)

# Zero Trust: Principles and implementation routes for a sustainable security architecture

## The Zero Trust model regularly reviews and evaluates authorizations and access to corporate data, meeting the security challenges of the new world of work and new technologies.

![Trust_Digital Hub_450x660](https://hub.kpmg.de/hubfs/LandingPages-Coverbilder/Trust_Digital%20Hub_450x660.jpg "Trust_Digital Hub_450x660")

Home office, digitalization, and the migration of processes and data to the cloud have changed the way we are working resulting in a higher risk exposure of companies. Many accesses to systems and data of employees no longer take place within the protected company. Consequently, the classic perimeter-based protection approach to defend against external threats is no longer sufficient to continue to effectively exclude all risks of unauthorized access.

The zero-trust approach is based on the continuous verification of whether an activity can be considered ordinary and legitimate. In this context, authorizations, once granted and reviewed, are not considered permanent, but are regularly assessed for context (i.e., time, location, device, etc.) before being granted again. Zero Trust goes beyond classic access rights management.

This paper explains the principles on which Zero Trust is based and how they help to reduce risks. Furthermore, the implementation of a Zero Trust architecture is outlined and the preconditions that must be in place in the company are illustrated. Finally, possible steps of an introduction of the required processes and technologies are shown.

- [ Legal ](https://home.kpmg/de/en/home/misc/legal.html)
- [ Privacy ](https://home.kpmg/de/de/home/misc/privacy.html)
- [ Contact ](https://home.kpmg/de/en/home/misc/contact.html)
- [ Company information ](https://home.kpmg/de/en/home/misc/company-information.html)

- [![](https://hub.kpmg.de/hubfs/System/KPMG/Social_Icons/social_icon_fb.jpg) ](https://www.facebook.com/KPMG.AG.WPG)
- [![](https://hub.kpmg.de/hubfs/System/KPMG/Social_Icons/social_icon_twit.jpg) ](https://twitter.com/KPMG_DE)
- [![](https://hub.kpmg.de/hubfs/System/KPMG/Social_Icons/social_icon_xing.jpg) ](https://www.xing.com/companies/kpmgagwirtschaftspr%C3%BCfungsgesellschaft/updates)
- [![](https://hub.kpmg.de/hubfs/System/KPMG/Social_Icons/social_icon_linkin.jpg) ](https://www.linkedin.com/company/kpmg-deutschland)
- [![](https://hub.kpmg.de/hubfs/System/KPMG/Social_Icons/social_icon_yt.jpg) ](https://www.youtube.com/user/KPMGinDeutschland)

 © 2026 KPMG AG Wirtschaftsprüfungsgesellschaft, a corporation under German law and a member firm of the KPMG global organization of independent member firms affiliated with KPMG International Limited, a private English company limited by guarantee. All rights reserved.   
 For more detail about the structure of the KPMG global organization please visit [https://home.kpmg/governance](https://home.kpmg/governance).