The education and research sector faces significant cyber resilience challenges. One is: how to make your institution's IT environment technically cyber resilient. One handle for this is the zero trust principle: "never trust, always verify". What exactly does zero trust mean, and how do you apply it in practice?