Security without walls: What enterprises must do next - TalkLPnews Skip to content

Security without walls: What enterprises must do next

GUEST OPINION: Enterprise security has long operated on a simple premise: build walls around your network, keep the bad guys out, and everything inside those walls will stay safe. That is far from the reality today.

The network perimeter is effectively dead. In FY2024–25, the Australian Signals Directorate’s Australian Cyber Security Centre received more than 84,700 cybercrime reports – roughly one report every six minutes[i]. However, many enterprise security teams in ANZ are still operating as if those walls exist, managing firewalls for networks that dissolved years ago and enforcing password complexity for users who access dozens of cloud applications the security team doesn’t even know about. They’re focused on preventing attackers from getting in, when they should be focusing on how fast they can act when they do. Malicious or criminal attacks accounted for 59% of all data breaches reported to the OAIC in the first half of 2025.[ii]

This denial has to end. Not because of some revolutionary new threat – though there are plenty of those as well – but because the gap between security strategy and business reality in ANZ has become impossible to ignore. SaaS applications don’t respect network perimeters. Contractors logging in from their home office aren’t sitting behind your firewall.

Here’s what security leaders need to accept and act on, in the year ahead.

The old guard: Password-based authentication must go

Passwords have long been the first line of defense in perimeter security. But when there are no walls left to protect, why are we still enforcing them?

While compliance frameworks in ANZ continue to mandate complex password policies, forward-thinking organisations should abandon passwords entirely. The password requirements that may have made sense a decade ago are now holding back security progress.

Instead of continuing to ask employees to strengthen their passwords, CISOs should begin planning the complete elimination of them in favor of passkeys, platform authentication, and biometric systems. 

Not only is it significantly more secure, but it’s also dramatically more user-friendly, eliminating the frustrations and risks that come with managing a slew of passwords.

Some compliance frameworks may continue to emphasise passwords, but security teams should work with compliance teams to demonstrate how these new authentication methods are more secure.

The new reality: Your attack surface is someone else’s infrastructure

The perimeter didn’t disappear because security teams abandoned it. It dissolved because business operations moved to interconnected SaaS platforms that exist outside any network boundary you can control.

The interconnected world of SaaS applications will soon become the number one vulnerability for enterprises. As we continue to move to cloud-based solutions, threat actors are shifting their focus from traditional infrastructure to third-party and even fourth-party supplier risks.

To add to this concern, adversaries are leveraging AI to accelerate their ability to identify and exploit vulnerabilities across these complex supplier networks – turning what were once time-consuming surveillance efforts into automated processes.

Advertisement

CISOs have to prioritise speed in securing their supplier ecosystem. The challenge isn’t just identifying which applications are in use across departments – it’s understanding them quickly enough to secure them before the gaps are exploited. That is done by getting the foundational security posture right for each application, rather than attempting comprehensive security programs that take months or quarters to implement.

The foundation: Identity is the only perimeter left

In a world without network boundaries, identity becomes everything. Not just who can access what, but how you verify that identity at every connection point across an ecosystem that you don’t have complete control over. Identity fraud remained the top reported cybercrime in Australia in FY2024–25.[iii]

Many enterprises still haven’t fully embraced identity as their new security foundation, but that will soon change. Companies will recognise that single sign-on (SSO) isn’t optional – it’s fundamental, and the refusal to implement SSO across all enterprise applications will increasingly be seen as a critical security failure rather than a vendor management decision.

Identity must be secured end-to-end without exception. Beyond SSO, companies must establish transparency around supporter and administrator identities within the tools. That means employees should be able to easily verify who is connecting to their systems, creating the trust framework necessary for secure operations across organisational boundaries.

Beyond the perimeter

The perimeter-based security model is dead, and 2026 must be the year organisations stop pretending otherwise.

This shift requires more than just new tools. It requires CISOs to fundamentally rethink what security means when you can’t control the network, when your applications run on someone else’s infrastructure, and when users are everywhere except behind your firewall. It means building security programs around identity verification, visibility, and the speed of detection.

The organisations that make this shift – that stop trying to rebuild walls and start securing the interconnected reality we actually operate in – will be dramatically ahead of their peers. Not because they’ve invested more in security, but because they’ve finally aligned their security strategy with how businesses actually work.

Nearly half of Australians surveyed for the Australian Cybercrime Survey experienced at least one form of cybercrime in the previous 12 months.[iv] The perimeter is dead. It’s time to build something better.

[i] Annual Cyber Threat Report 2024-2025 | Cyber.gov.au. (2024). Cyber.gov.auhttps://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025

[ii] OAIC. (2025, November 3). OAIC launches new dashboard for data breaches. OAIC. https://www.oaic.gov.au/news/media-centre/oaic-launches-new-dashboard-for-data-breaches?

[iii] Annual Cyber Threat Report 2024-2025 | Cyber.gov.au. (2024). Cyber.gov.auhttps://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025

[iv] Australian Institute of Criminology. (2025, August 14). AIC research reveals extent of cybercrime in Australia. Australian Institute of Criminology. https://www.aic.gov.au/media-centre/news/aic-research-reveals-extent-cybercrime-australia?

Advertisement

https://itwire.com/guest-articles/guest-opinion/security-without-walls-what-enterprises-must-do-next