Access Control Maturity: From Passwords to Zero Trust for Mid-Market Businesses

Published May 20, 2026

A firm principal at a civil engineering practice asked a direct question at the end of a client meeting last year: “Zero trust keeps coming up. What does it actually mean, and do I need it, or is it something only Fortune 500 companies should care about?”

Fair question. Zero trust is one of the most overused terms in cybersecurity marketing. The underlying concept is solid, but the vendor messaging has been so heavy that a lot of real buyers cannot tell what the actual control set is or how to evaluate whether their firm needs it.

The honest answer for mid-market manufacturers and civil firms is: you do not need to rush to zero trust, but you do need to be moving in that direction. Access control sits on a maturity curve. Where your firm is on that curve determines your actual exposure. This post walks through the curve so you can evaluate your position and know what the next steps look like.

The Problem: Access Control Gets Layered, Never Replaced

Most mid-market businesses did not design their access control. It accumulated. A typical mid-market environment still has layers built from:

  • Active Directory on-premises, from when the firm had a server room
  • Microsoft 365 or Google Workspace, added when email went to the cloud
  • A handful of SaaS apps, each with their own login
  • A VPN for remote access, set up when people started working from home
  • Some MFA, usually applied to email and the VPN, often not applied to everything
  • Password policies from 2015 that are still in effect
  • A pile of shared service accounts that nobody wants to touch because “something might break”

This layered environment has real weaknesses. Users have too many passwords. Shared accounts obscure accountability. MFA gaps create attacker-exploitable paths. Remote access patterns are rooted in the office-perimeter model that no longer reflects how people work. Each layer made sense when it was added, but the combined state is less secure than any single layer would be if it had been designed on its own.

The direction of travel in access control for the past decade has been from the perimeter model (trust the network, do not trust outsiders) to the identity model (trust nothing by default, verify every access). Zero trust is the current name for the identity model’s mature form.

Why It Matters to You Specifically

For the owner, CFO, or operations leader making IT decisions, access control maturity affects four areas:

Cyber Insurance and Client Requirements

As covered in CISA’s zero trust maturity model, the direction is clear: insurers, customers, and regulators expect increasing maturity over time. Firms that stay at the “passwords and maybe some MFA” level will face pressure that firms with mature controls will not.

Ransomware Defense

The most common initial access vectors for ransomware are credential compromise, phishing leading to credential compromise, and exploitation of weak remote access. Each of these is an access control problem. Stronger access controls reduce the likelihood of initial access significantly. The FBI IC3 Annual Reports consistently show credential-based attacks at the top of the attack vector list.

Compliance

NIST SP 800-171, which underpins CMMC 2.0, has detailed access control requirements. So do most industry-specific compliance frameworks. A firm with immature access controls has many compliance gaps, not just one.

Operational Efficiency

Mature access control is often simpler for users, not more complex. Single sign-on, passwordless options, and properly implemented zero trust can reduce the friction users experience while increasing security. Done poorly, access controls are onerous. Done well, they are invisible.

The Maturity Curve

Access control maturity in mid-market businesses tends to follow a consistent progression. The levels are not rigid; firms often have mixed maturity across their environment. But as a general reference:

Level 1: Passwords Only

Users have usernames and passwords. Some are long. Some are short. Some get reused across services. Password policies exist but may be outdated. No multi-factor authentication. This is an indefensible position in 2026. Any firm still here has an urgent problem.

Level 2: MFA on Email and VPN

Multi-factor authentication is enforced on email and on remote access. Other applications still use passwords alone. Most mid-market firms are somewhere in this range today. It is a significant improvement over Level 1 and blocks many common attacks, but gaps exist.

Level 3: MFA Everywhere That Matters

MFA is enforced on essentially all business applications, including SaaS apps, internal tools, privileged accounts, and backup systems. Identity provider (Microsoft Entra ID / Azure AD, Okta, Google) is used for single sign-on. Administrative accounts are separated from regular user accounts. This is the current floor for a defensible access posture.

Level 4: Conditional Access and Device Trust

Beyond MFA on login, conditional access policies evaluate context: Is the user signing in from a known device? From an expected location? At an expected time? From a device that meets compliance requirements (up-to-date OS, disk encryption, EDR installed)? If any condition is not met, access is challenged with additional verification or denied outright. This is where firms start moving into “zero trust” territory in practical terms.

Level 5: Identity as the Security Perimeter

Network location becomes irrelevant to access decisions. Whether a user is in the office or at a coffee shop, the same identity verification, device checks, and context evaluations apply. The traditional office VPN is retired in favor of zero trust network access (ZTNA) solutions that evaluate every access request individually.

Level 6: Just-in-Time, Least-Privilege Access

Standing access to sensitive systems is the exception, not the rule. Privileged actions require elevation that is granted for specific tasks, for specific durations, with logging and session recording. Automated policies grant and revoke access based on role and context. Zero standing privilege for administrators is a stretch goal at this level.

What Good Looks Like for a Mid-Market Firm

For most mid-market civil firms and manufacturers, the practical target is solid Level 4 with elements of Level 5. This gets you:

  • MFA enforced universally, with modern methods (authenticator apps, passkeys, Windows Hello for Business) replacing SMS where possible
  • A primary identity provider used for single sign-on to business applications
  • Conditional access policies that evaluate device health and user context
  • Administrative access separated from regular access, with MFA and logging
  • Remote access increasingly through ZTNA rather than traditional VPN
  • No shared accounts for any sensitive purpose
  • Quarterly access reviews to remove accounts that are no longer needed

Reaching this target is a multi-quarter project, not a weekend. For most firms it involves licensing changes, technology migration, policy updates, and user communication. A well-run program gets it done within 12 to 18 months and produces material improvements as each milestone is reached.

Practical Takeaways

  1. Assess where your firm currently is on the curve. An honest assessment usually lands somewhere between Level 2 and Level 3, sometimes with pockets of Level 4. Be specific about which systems are at which level.
  2. Identify the highest-risk gaps first. MFA missing on email, VPN, or administrative accounts is the most urgent. Fix those before worrying about conditional access.
  3. Consolidate identity. If the firm has three different places users log in (AD, M365, various SaaS apps), consolidating through an identity provider with SSO is both a security and usability win.
  4. Plan phased elevation toward conditional access. Once MFA is universal, layering conditional access policies gets you to Level 4 without major new infrastructure.
  5. Retire legacy remote access on a schedule. Traditional VPNs are not inherently bad, but zero trust network access products provide better security and usability for most current use cases. Budget for a phased migration.

Zero trust is not a single product or a sudden transformation. It is a direction of travel that every firm, mid-market included, is on whether they know it or not. The firms that approach it deliberately come out with lower risk, lower operational friction, and better positioning for insurance and compliance conversations. The ones who ignore it get pushed along by external pressure anyway, usually less gracefully.

If you want a conversation about assessing your firm’s access control posture and mapping a practical path forward, the HVR Cloud team works with mid-market firms on exactly this kind of maturity journey. Get in touch and we can walk through your current state.