Has anybody seen the classic film Gladiator? It opens with the general telling his troops that if they hold the line, the battle will be won. Traditional corporate security thinking pretty much aligns with this approach. The model has always been perceived as one of an internal-plus-external network with a defined edge, and the major task of defence was to keep that edge intact.

This perception carried over into the security strategy that shaped how budgets were set, tools were purchased, and how the board of directors understood the risk they were carrying. The trouble with this thinking is that in a cloud-first world, it is almost entirely obsolete.
When businesses run their operations across Microsoft 365, Azure, AWS and Google Cloud, there is no longer a single edge to defend. Data, applications and administrative control sit in environments the business does not own and cannot wall off. What replaces the perimeter is identity. The question is no longer whether an attacker can breach the wall, but whether they can present a valid login. Once they can, they are, as far as the system is concerned, a legitimate user.
Microsoft’s most recent Digital Defence Report reveals that the overwhelming majority of identity attacks are, at their core, password attacks, and that identity-based attacks rose sharply through the first half of last year. Verizon’s latest Data Breach Investigations Report, drawing on tens of thousands of incidents, found that compromised credentials feature at some point in a substantial share of breaches. This makes the stolen or guessed login the single most dependable route into an organisation. Attackers, in short, are not breaking down doors. They are letting themselves in with a key.
That key is increasingly easy to come by. A category of malware known as infostealers now harvests credentials – and, in many cases, the active session tokens that sit behind them – directly from employees’ browsers, often before those credentials are ever encrypted on a server. Researchers tracking this trade describe billions of stolen records in circulation, refreshed continuously. The uncomfortable implication is that many businesses already have valid credentials for their own environment sitting in a criminal marketplace and have no way of knowing it.
Is multi-factor authentication (MFA) the ultimate shield?
Even MFA, long treated as the decisive control, is no longer a guarantee. Adversary-in-the-middle techniques intercept the authentication process in real time, and a significant proportion of breaches that bypass MFA now rely on this method. MFA remains essential, but it is a lock, not a force field, and locks can be picked open.
None of this would matter so much if organisations could see it happening. The difficulty is that the cloud platform itself will not tell you. It will faithfully process a login from a compromised account exactly as it does a legitimate one, because, from its perspective, there is no difference. Knowing that a particular sign-in came from an improbable location, that a session token has been replayed, or that an administrator account is behaving in a way it has never behaved before requires deliberately and continuously monitoring identity activity. Most businesses do not have this vigilance in place and only discover the problem when consequences surface, frequently weeks or more later.
The exposure no longer stops with a company’s employees. Verizon’s data shows third-party involvement climbing steeply, now approaching half of all breaches. When a supplier, contractor, or managed provider is granted credentials to access your environment, their identity hygiene becomes your risk. The perimeter, such as it is, now runs through every business to which you have granted access.
If you cannot see it – how can you stop it?
For business leadership/executive management, this reframes the questions they should be asking. It is not "Is our firewall strong?" but rather, "Do we know who is accessing our environment?" And from where? Also, is that access legitimate?
These are questions around visibility and discipline, not about buying another tool. It is one that automation alone cannot answer: distinguishing a genuine account takeover from an employee logging in from an airport lounge is precisely the kind of judgement that still needs an experienced analyst who uses automation to surface the signal, augmented by human expertise to confirm what is real before it reaches a decision-maker.
This is the gap that continuous, expert-validated identity monitoring, the thinking behind our own Fusion Cloud service, is built to close: watching the login layer as closely as we once watched the network edge, and translating what it sees into something a leadership team can actually act on.
The wall has not disappeared, but it is no longer where the battle is fought. The organisations that will successfully navigate the current threat landscape are those that recognise the front door is now a login screen and guard it accordingly.
| Email: | [email protected] |
| www: | www.bluevision.co |
| Articles: | More information and articles about BlueVision |
© Technews Publishing (Pty) Ltd. | All Rights Reserved.