Rebuilding Success Magazine Features - Fall/Winter 2026 > Zero Trust for Trustees: What It Is, and Why Your Firm Needs It
Zero Trust for Trustees: What It Is, and Why Your Firm Needs It
![]() |
By Michael Turcsanyi, CEO, TruPoint · Sponsored content
Sponsored Content

Over the past two years in these pages we have looked at the pieces of a secure practice: meeting the Superintendent’s electronic record requirements, using AI without exposing client information, and hardening Microsoft 365 beyond its out-of-the-box settings. This article is about the idea that ties those pieces together. It has a plain, slightly severe name — Zero Trust — and it has quietly become the standard that insurers, regulators and larger referral partners now expect. Here is what it means, and why it matters for a trustee’s firm.
The office boundary has disappeared
For a long time, firm security worked like a walled town: a barrier around the office, a firewall at the edge, and an assumption that anything inside the barrier could be trusted. That model made sense when the people and the files you needed to protect all sat in the same building on the same network. They no longer do. Your administrators work from home some days. You review a file from a boardroom or a debtor’s kitchen table. Estate records live in Microsoft 365, in email, and in your case-management system, and software such as Ascend is reached over the internet rather than from a server down the hall. The barrier around the office cannot protect any of that, because the work has moved outside it.
What Zero Trust actually means
Zero Trust replaces the barrier with a simpler rule: never trust, always verify. Rather than trusting a request because it came from inside the office network, a Zero Trust system checks every request, every time — who is this user, is this a device we manage, is this a normal thing for them to be doing — before it grants access to a particular application or file. Think of it as a building where a pass is checked at every door, not just the front entrance, and where each pass only opens the rooms that person actually needs. Access is granted to one application at a time, for as long as it is needed and no longer. It is less a product you buy than a way of designing how people reach their work.
Why it matters for a trustee’s firm
A trustee holds some of the most sensitive information a person will ever hand over: social insurance numbers, bank records, income, debts, and the details of a difficult moment in someone’s life. A single stolen password should never be enough to open an entire estate — and under a Zero Trust model it is not, because the password alone does not satisfy the checks.
There is a compliance dimension as well. Directive No. 32R expects electronic records to be kept with integrity, with controlled access and a reliable audit trail. A Zero Trust system produces that almost as a side effect: because every access is verified and recorded, you have a clear account of who opened which file and when. The same is increasingly true of cyber insurance. The questionnaires that arrive at renewal now ask whether you enforce multi-factor authentication, whether access is controlled and logged, and whether someone is watching for intrusions. Those are Zero Trust controls by another name, and firms that cannot demonstrate them are being surcharged or declined.
For a smaller practice the stakes are not abstract. A breach involving debtor information is not only a business problem; it is a regulatory and reputational one, and a firm without a large balance sheet may not easily absorb it.
What it looks like in practice
In day-to-day terms, Zero Trust does three things continuously. First, it verifies: every user and device is confirmed before it reaches an application, which is where multi-factor authentication and conditional access — the subject of our last article — actually live. Second, it protects: the device, the email and the files are monitored, and when something looks wrong there is a person able to act on it, not just an alert scrolling past in a log. Third, it proves: because access is checked and recorded as work happens, the evidence a regulator or an insurer asks for is already there, rather than something you assemble in a hurry before a deadline.
Consider a trustee opening Ascend from a laptop at a debtor’s home. In a Zero Trust setup the software runs on a hosted desktop rather than on that laptop; the person’s identity and device are verified before the session opens; and the estate data stays in one controlled, monitored place instead of being copied onto a machine that might be left on a train. The convenience is the same. The exposure is much smaller.
You do not need a national firm’s IT department
Zero Trust used to be an enterprise idea — not because the technology was exotic, but because assembling it took a security team most firms do not have. That has changed. A small or mid-size practice can now obtain the same controls delivered as a managed service, without hiring anyone. Two things are worth insisting on when you do. Keep the debtor data in Canada, on infrastructure whose location you can actually point to, so that a residency question from a client or a regulator has a straight answer. And take it as one coherent service rather than a drawer of disconnected tools, so that the team that secures your environment is the same one that supports it and documents it.
This is the thinking behind how we built our own service — TruWorkspace SSC, where support, security and compliance run as one, and TruCloud, our Canadian hosting, where applications such as Ascend and a firm’s files can run on infrastructure that stays in the country. But the principle matters more than any one provider: whatever you choose, choose something that verifies every request, keeps your data in Canada, and can show its work.
A standing offer
We have worked alongside the insolvency community for several years, and we are always glad to talk through where a firm stands, with no obligation and no sales sequence. If you would like to understand your own exposure, or simply see how Zero Trust would apply to your practice, you can arrange a discovery call at trupoint.com/CAIRP.
Michael Turcsanyi is the CEO of TruPoint, a Canadian managed service and cloud provider that runs the security, compliance and IT of firms handling sensitive information, and operates two Canadian private clouds for the workloads that need to stay in the country.
This content has been provided by the sponsor. CAIRP does not endorse and is not responsible for the views, opinions, products, services, or claims expressed herein.

