Hold the line

August 2026 Information Security, Editor's Choice

Has anybody seen the classic film Gladiator? It opens with the general telling his troops that if they hold the line, the battle will be won. Traditional corporate security thinking pretty much aligns with this approach. The model has always been perceived as one of an internal-plus-external network with a defined edge, and the major task of defence was to keep that edge intact.


Christo Coetzer

This perception carried over into the security strategy that shaped how budgets were set, tools were purchased, and how the board of directors understood the risk they were carrying. The trouble with this thinking is that in a cloud-first world, it is almost entirely obsolete.

When businesses run their operations across Microsoft 365, Azure, AWS and Google Cloud, there is no longer a single edge to defend. Data, applications and administrative control sit in environments the business does not own and cannot wall off. What replaces the perimeter is identity. The question is no longer whether an attacker can breach the wall, but whether they can present a valid login. Once they can, they are, as far as the system is concerned, a legitimate user.

Microsoft’s most recent Digital Defence Report reveals that the overwhelming majority of identity attacks are, at their core, password attacks, and that identity-based attacks rose sharply through the first half of last year. Verizon’s latest Data Breach Investigations Report, drawing on tens of thousands of incidents, found that compromised credentials feature at some point in a substantial share of breaches. This makes the stolen or guessed login the single most dependable route into an organisation. Attackers, in short, are not breaking down doors. They are letting themselves in with a key.

That key is increasingly easy to come by. A category of malware known as infostealers now harvests credentials – and, in many cases, the active session tokens that sit behind them – directly from employees’ browsers, often before those credentials are ever encrypted on a server. Researchers tracking this trade describe billions of stolen records in circulation, refreshed continuously. The uncomfortable implication is that many businesses already have valid credentials for their own environment sitting in a criminal marketplace and have no way of knowing it.

Is multi-factor authentication (MFA) the ultimate shield?

Even MFA, long treated as the decisive control, is no longer a guarantee. Adversary-in-the-middle techniques intercept the authentication process in real time, and a significant proportion of breaches that bypass MFA now rely on this method. MFA remains essential, but it is a lock, not a force field, and locks can be picked open.

None of this would matter so much if organisations could see it happening. The difficulty is that the cloud platform itself will not tell you. It will faithfully process a login from a compromised account exactly as it does a legitimate one, because, from its perspective, there is no difference. Knowing that a particular sign-in came from an improbable location, that a session token has been replayed, or that an administrator account is behaving in a way it has never behaved before requires deliberately and continuously monitoring identity activity. Most businesses do not have this vigilance in place and only discover the problem when consequences surface, frequently weeks or more later.

The exposure no longer stops with a company’s employees. Verizon’s data shows third-party involvement climbing steeply, now approaching half of all breaches. When a supplier, contractor, or managed provider is granted credentials to access your environment, their identity hygiene becomes your risk. The perimeter, such as it is, now runs through every business to which you have granted access.

If you cannot see it – how can you stop it?

For business leadership/executive management, this reframes the questions they should be asking. It is not "Is our firewall strong?" but rather, "Do we know who is accessing our environment?" And from where? Also, is that access legitimate?

These are questions around visibility and discipline, not about buying another tool. It is one that automation alone cannot answer: distinguishing a genuine account takeover from an employee logging in from an airport lounge is precisely the kind of judgement that still needs an experienced analyst who uses automation to surface the signal, augmented by human expertise to confirm what is real before it reaches a decision-maker.

This is the gap that continuous, expert-validated identity monitoring, the thinking behind our own Fusion Cloud service, is built to close: watching the login layer as closely as we once watched the network edge, and translating what it sees into something a leadership team can actually act on.

The wall has not disappeared, but it is no longer where the battle is fought. The organisations that will successfully navigate the current threat landscape are those that recognise the front door is now a login screen and guard it accordingly.


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...
Ungoverned AI agents and deepfakes pose critical threats
Information Security Security Services & Risk Management
Global study reveals 64% of South African organisations already deploy autonomous AI agents with little to no governance, while 63% of employees admit they are unlikely to be able to spot attacks such as deepfakes

Read more...
How ‘TikTok Brain’ is breaking legacy security training
Training & Education Information Security
Between doomscrolling, rapid-fire Slack notifications, and algorithmic video feeds, the average employee is trapped in an aggressive, highly engineered dopamine loop that automatically shuts down in traditional training situations.

Read more...
Quantum is coming
Infrastructure Information Security
The global cybersecurity landscape is approaching a turning point as quantum computing accelerates faster than most organisations realise; the shift is not a distant, theoretical concern, but a present-day business risk that demands immediate action.

Read more...
Outpacing cyberthreats in the age of AI
SMART Security Solutions Technews Publishing News & Events Information Security
SMARTpod talks to Fred Streefland, Global Field CISO for EMEA at Check Point Software Technologies, about framing modern cyber defence around adaptability, rapid decision-making, and the OODA loop adapted for cybersecurity.

Read more...
Prompt injection is the new phishing
Information Security Security Services & Risk Management
AI security is heading in an uncomfortable direction following Microsoft’s research showing how prompt injection can be chained to remote code execution vulnerabilities in AI agent frameworks, including work involving Semantic Kernel

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.