A Lightweight Zero-Trust Framework for Small-to-Medium Enterprises on AWS–Azure Hybrid Clouds

Authors

  • Bibek Kumar Katwal Islington College, Nepal Author
    Competing Interests

    No

  • Rajesh Chhetry Author

DOI:

https://doi.org/10.67556/qmvvay81

Keywords:

Zero Trust Architecture, hybrid cloud security, open-source cybersecurity, identity-centric access control, SME security economics

Abstract

Small-to-medium enterprises (SMEs) in developing economies are digitizing rapidly while their security capacity lags, leaving credential-based attacks and cross-cloud misconfiguration largely uncontested. Zero Trust Architecture (ZTA) is the recognized response, yet documented implementations assume enterprise budgets and specialist teams that resource-constrained firms cannot match. This study designed and empirically evaluated a four-component lightweight ZTA framework, an identity service using the Open Authorization (OAuth) 2.0 standard, a rule-based Role-Based Access Control (RBAC) policy engine, an access gateway, and an administrative dashboard with an append-only audit log, built entirely from open-source software and free-tier cloud services. A pragmatist, design-science approach combined Agile development, load testing across 5, 25, and 50 concurrent users, threat modelling using the Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege (STRIDE) method, and a structured SME feasibility self-assessment. The prototype achieved 100% access-control accuracy across 500 test requests and a mean end-to-end authentication latency of 187 milliseconds at peak load, within the 200-millisecond target, though the 95th-percentile latency reached 341 milliseconds. The total monthly deployment cost was approximately 43 United States dollars, one to two orders of magnitude below the recurring cost of comparable commercial ZTA platforms. Five of six STRIDE threat categories were fully mitigated. The framework demonstrates that a credible, standards-aligned Zero Trust posture is technically and economically feasible for SMEs without specialist security personnel, contributing a deployable open-source artefact and a validated cost–performance model for similar organizations across emerging economies.

##plugins.themes.default.displayStats.downloads##

##plugins.themes.default.displayStats.noStats##

References

Asian Development Bank (2020) Small and medium-sized enterprises in Nepal. ADBI Working Paper 1166. Tokyo: Asian Development Bank Institute. Available at: https://www.adb.org/sites/default/files/publication/623281/adbi-wp1166.pdf (Accessed: 15 December 2025).

Bryman, A. (2016) Social research methods. 5th edn. Oxford: Oxford University Press.

Buck, C., Olenberger, C., Schweizer, A., Völter, F. and Eymann, T. (2021) ‘Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust’, Computers & Security, 110, p. 102436. Available at: https://www.sciencedirect.com/science/article/abs/pii/S0167404821002601 (Accessed: 28 April 2026).

CERT-NP (2021) Annual report 2020/2021. Kathmandu: CERT-NP. Available at: https://www.cert.gov.np/uploads/files/Annual%20Report%202077-78.pdf (Accessed: 27 November 2025).

Creswell, J.W. and Creswell, J.D. (2018) Research design: Qualitative, quantitative, and mixed methods approaches. 5th edn. Thousand Oaks, CA: SAGE Publications.

ENISA (2021) Cybersecurity for SMEs: Challenges and recommendations. Athens: European Union Agency for Cybersecurity. Available at: https://www.enisa.europa.eu/publications/cybersecurity-for-smes (Accessed: 3 January 2026).

Ferraiolo, D., Kuhn, D.R. and Chandramouli, R. (2007) Role-based access control. 2nd edn. Norwood, MA: Artech House.

Gartner (2023) Gartner survey reveals 63% of organizations worldwide have implemented a zero-trust strategy. Press release, 17 April. Stamford, CT: Gartner Inc. Available at: https://www.gartner.com/en/newsroom/press-releases/2023-04-17-gartner-survey-reveals-63-percent-of-organizations-worldwide-have-implemented-a-zero-trust-strategy (Accessed: 28 April 2026).

Gilman, E. and Barth, D. (2017) Zero trust networks: Building secure systems in untrusted networks. Sebastopol, CA: O’Reilly Media.

Government of Nepal, Ministry of Communication and Information Technology (2019) Digital Nepal framework: Unlocking Nepal’s growth potential. Kathmandu: Government of Nepal. Available at: https://mocit.gov.np (Accessed: 14 December 2025).

Hardt, D. (ed.) (2012) The OAuth 2.0 authorization framework. RFC 6749. Fremont, CA: IETF. Available at: https://www.rfc-editor.org/rfc/rfc6749 (Accessed: 28 April 2026).

Jones, M., Bradley, J. and Sakimura, N. (2015) JSON Web Token (JWT). RFC 7519. Fremont, CA: IETF. Available at: https://www.rfc-editor.org/rfc/rfc7519 (Accessed: 28 April 2026).

Kathmandu Post (2024) ‘Cybercrime cases spike in Nepal’, Kathmandu Post, 21 August. Available at: https://kathmandupost.com/national/2024/08/21/cybercrime-cases-spike-in-nepal (Accessed: 7 May 2026).

Kindervag, J. (2010) No more chewy centers: Introducing the zero trust model of information security. Cambridge, MA: Forrester Research.

Kshetri, N. (2020) ‘Cybersecurity in emerging economies: In search of a solution’, Computer, 53(3), pp. 74–78. Available at: https://ieeexplore.ieee.org/document/8952576 (Accessed: 28 April 2026).

Locust (2023) Locust: An open-source load testing tool. Available at: https://locust.io/ (Accessed: 28 April 2026).

Mehraj, S. and Banday, M.T. (2020) ‘Establishing a zero-trust strategy in cloud computing environment’, in Proceedings of the International Conference on Computer Communication and Informatics (ICCCI). IEEE.

Rose, S., Borchert, O., Mitchell, S. and Connelly, S. (2020) Zero trust architecture. NIST Special Publication 800-207. Gaithersburg, MD: NIST. Available at: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf (Accessed: 27 November 2025).

Sandhu, R.S., Coyne, E.J., Feinstein, H.L. and Youman, C.E. (1996) ‘Role-based access control models’, IEEE Computer, 29(2), pp. 38–47. Available at: https://ieeexplore.ieee.org/document/488924 (Accessed: 28 April 2026).

Saunders, M., Lewis, P. and Thornhill, A. (2019) Research methods for business students. 8th edn. Harlow: Pearson Education.

Shostack, A. (2014) Threat modeling: Designing for security. Indianapolis: John Wiley and Sons.

Syed, N.F., Shah, S.W., Shaghaghi, A., Anwar, A., Baig, Z. and Doss, R. (2022) ‘Zero Trust Architecture (ZTA): A comprehensive survey’, IEEE Access, 10, pp. 57143–57179. Available at: https://ieeexplore.ieee.org/document/9773102 (Accessed: 28 April 2026).

Thapa, G.B. (2025) ‘Cybersecurity challenges in small and medium enterprises (SMEs) in Nepal’, International Journal of Multidisciplinary Innovative Research, 2(6). Available at: https://ijmir.com/v2i6/Doc/5.pdf (Accessed: 7 May 2026).

Downloads

Published

2026-06-08

Issue

Section

Articles

How to Cite

A Lightweight Zero-Trust Framework for Small-to-Medium Enterprises on AWS–Azure Hybrid Clouds. (2026). Islington Journal of Multidisciplinary Research, 1(1), 41-49. https://doi.org/10.67556/qmvvay81

Similar Articles

You may also start an advanced similarity search for this article.