When the Perimeter Stopped Being a Place

GRAY | 360° — 2024

When the Perimeter Stopped Being a Place

Two decades of technology strategy and support, tracking how cyber security moved from a contained technical problem to a question of design and human behaviour.

Category

infrastructure

Tags

Cyber SecurityZero TrustAccess ControlSystems Strategy

Year

2024

Overview

GRAY has been involved in providing technology strategy and support to its clients for more than two decades. During that time, cyber security has changed from a relatively contained technical problem into something considerably more complex.

Early network security had a reassuringly physical logic. There was an inside, an outside, and a relatively small number of doors between them. VPN and SSL VPN provided controlled remote access. Barracuda and RedBox appliances protected deliberately limited attack surfaces. Access could be defined, monitored and restricted because the network itself still had reasonably clear edges.

Then the edges began to move. The arrival of the iPhone and rapid adoption of smartphones changed not simply the devices people carried, but their expectations. Email, documents and business systems were suddenly expected to be available anywhere, from devices and networks the organisation did not necessarily control.

GRAY worked with clients as their policies and infrastructure evolved in response. Device management, authentication and increasingly granular access controls addressed genuine vulnerabilities. But each additional layer also introduced complexity. And complexity has consequences.

The more secure an environment becomes, the more effort legitimate users may have to expend navigating it. When security obstructs ordinary work, people improvise. They find shortcuts, create parallel processes or quietly work around controls intended to protect them. The human element cannot simply be patched.

Zero Trust is a logical response to the disappearance of the traditional perimeter: trust nothing implicitly, verify continuously and grant only the access required. But its implementation raises a question that is as much about design and organisational behaviour as technology — how do you create an environment that trusts nothing without creating one in which nobody can work?

GRAY's role has increasingly been to help clients navigate that balance — between security and accessibility, policy and practice, technical risk and human behaviour. The technology has changed considerably. The underlying principle has not: security works best when the people expected to use it are considered part of the system, rather than an inconvenience to be controlled.