Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Should You Harden Your Perimeter or Assume Breach?Risk Analysis and Quantification
5 min readFor CISOs

Should You Harden Your Perimeter or Assume Breach?

The Financial Stability Board has warned G20 leaders that AI-driven cyberattacks pose a systemic threat to global financial markets. For CISOs, this raises a critical question: should you focus on preventing intrusions, or accept that breaches are inevitable and concentrate on detection and containment?

This isn't just theoretical. Your budget, staffing, and technology choices depend on which strategy you choose. With AI shortening the time from vulnerability discovery to exploitation, the stakes are higher than ever.

The Question at Hand

Traditional perimeter defense aims to keep attackers out. This involves building robust firewalls, enforcing strict access controls, aggressively patching, and monitoring entry points. Success means attackers never reach your core systems.

The assume-breach model, however, starts with the premise that attackers are already inside. It focuses on detecting lateral movement, using segmentation, employing behavioral analytics, and ensuring rapid containment. If you can't prevent the initial entry, you can at least limit the damage.

Both strategies claim to be the rational response to AI-driven threats, citing real incidents and investing heavily in controls that may not deliver the promised protection.

The Case for Hardening the Perimeter

Advocates for perimeter defense argue that prevention is cheaper than remediation. Stopping an attacker at the gate avoids costs like forensic investigations, regulatory disclosures, customer notifications, and operational downtime. It also prevents reputational damage from a confirmed breach.

This approach aligns with regulatory frameworks like NIST CSF and ISO 27001, which emphasize preventive controls such as vulnerability management (NIST CSF PR.IP-12), access control (ISO 27001 A.9), and secure configuration (CIS Controls 4 and 5). Auditors expect evidence of patching critical vulnerabilities within defined SLAs and blocking known attack vectors.

The perimeter model fits the structure of most financial institutions. Defined network boundaries, DMZs, and trust zones are standard. Third-party vendors connect through controlled interfaces, and employees access systems via VPN or zero-trust gateways. The architecture assumes "inside" is safer than "outside," and controls enforce that assumption.

There's also a practical argument: if you can't keep attackers out of your network, how will you keep them out of critical systems once they're inside? Lateral movement detection is challenging, behavioral analytics can generate false positives, and segmentation relies on a strong change management process. If your perimeter is weak, your internal defenses must be flawless.

The Case for Assuming Breach

Assume-breach proponents argue the perimeter is already obsolete. Employees work remotely, applications run in the public cloud, and vendors have direct API access to core systems. There's no "inside" anymore, so hardening a non-existent boundary is futile.

This model accepts that attackers will find a way in, whether through a zero-day vulnerability, stolen credentials, or a supply chain compromise. The Financial Stability Board's warning underscores this risk: AI can exploit vulnerabilities faster than your patch cycle can close them.

Accepting inevitable compromise shifts resources to detection and response. You deploy endpoint detection and response tools, monitor for abnormal authentication patterns, and segment your network to prevent a compromised workstation from reaching payment systems. You conduct tabletop exercises assuming the attacker is already inside.

This approach aligns with regulatory trends. The SEC's cybersecurity disclosure rules require public companies to disclose material incidents within four business days, assuming you'll detect breaches quickly enough to comply. If your budget focuses solely on prevention and you miss an intrusion, you're compromised and non-compliant.

Culturally, assume-breach forces organizations to take incident response seriously. If leadership believes the perimeter will hold, they'll underfund your security operations center and forensic readiness program. Accepting breaches will happen ensures investment in necessary capabilities when the alarm sounds.

Where Practitioners Actually Land

Most financial institutions use a hybrid model, though they may not admit it. They invest in perimeter controls because regulators and auditors expect them, and in detection and response because they've seen peers breached despite strong perimeters.

The split often depends on asset criticality. Payment processing systems receive full defense-in-depth treatment, while internal collaboration tools get basic hygiene, betting on catching any compromise before it spreads.

AI-accelerated attacks don't respect asset classification. An attacker compromising a low-value system can quickly pivot to a high-value target. John Strand's point is critical: attackers don't need advanced AI models to succeed. Open-weight models can automate vulnerability discovery and exploit development. Assuming only nation-state actors have these capabilities underestimates the threat.

Noelle Murata's observation about third-party dependencies is equally important. Your perimeter controls don't cover vendors' networks, and your assume-breach monitoring doesn't include their incident response workflows. If a vendor with API access to your core systems is compromised, you're exposed regardless of your security philosophy.

Our Take

You can't choose between prevention and detection; you need both. But as AI compresses response times, the balance should shift toward assume-breach.

Here's why: prevention is binary. Either your patch closes the vulnerability before the attacker finds it, or it doesn't. AI has tipped the odds against you. Automated tools can scan for vulnerabilities and develop exploits faster than your patch management can deploy updates.

Detection and containment are probabilistic. You won't catch every intrusion immediately, but detecting lateral movement within hours instead of weeks can contain damage before attackers reach critical systems. That's a realistic goal even in an AI-driven threat landscape.

This doesn't mean abandoning perimeter controls. You still need to patch critical vulnerabilities, enforce least-privilege access, and monitor network boundaries. But these are your first layer, not your only layer.

Operational priority should focus on validating recovery workflows and third-party dependencies at machine speed. Can you detect a compromised vendor credential within your SLA? Can you isolate a compromised system before the attacker pivots? Can you restore operations from backup if primary systems are encrypted?

These questions matter more than whether your firewall blocked the initial probe. In a world where cyberattacks happen at AI-driven speeds, the perimeter will eventually fail. Your response capability will determine whether you face a contained incident or a systemic market event.

Promotional banner for the Penetration Report Template Kit

You Might Also Like