The perimeter has dissolved – and security must follow, explains Philip Ingram MBE.
The fence, the badge and the firewall used to be three separate problems, handled by three separate teams who rarely spoke to one another.
Not anymore.
Now, they are one problem – and the organisations still running them separately are the ones getting caught out.
Start with the numbers, because they are worse than most boards realise.
59% of security professionals now name AI-driven social engineering as their principal worry for the year ahead, according to research from the security manufacturer, Pelco.
Around 94% of companies worldwide are pursuing cloud adoption in some form.
Put those together and you get a workforce being targeted by deception that is harder to spot than it used to be, sitting on infrastructure that is more spread out and more interconnected than it has ever been.
A locked door and a firewall rule tell you almost nothing useful about where an organisation’s boundary actually lies any more.
I have spent long enough around physical and information security to know why the two disciplines were kept apart for so long: organisational habit, not logic.
Separate budgets, separate reporting lines, separate incident logs.
That habit is now a liability, because a compromised credential opens a door just as easily as it opens a network share; a stolen access card can be the first rung on a ladder that ends in a server room.
An adversary who has joined the two up does not care which of your departments owns the failure.
The attack surface has changed
Credential theft is still how most attackers get in, and it is worth dwelling on why.
Phishing remains the entry point for more than 90% of successful cyber-attacks, says Cyber Tec Security’s 2026 assessment.
Once a credential is stolen, the consequences compound quickly: Proofpoint’s figures show 86% of data breaches now involve compromised credentials, that this class of attack rose 71% year-on-year, and that 94% of passwords in circulation are reused or duplicated somewhere else.
None of that should be surprising.
What should worry people more is that generative AI has made the lures harder to spot, not easier – it strips out the clumsy phrasing and the mistimed urgency that used to give a phishing email away.
Insider risk makes matters worse. IBM’s research puts the average cost of a breach caused by a malicious insider at close to £4m and finds that 56% of insider incidents are not malicious at all – a lost laptop, a misdirected email, a shortcut around a control that felt unnecessary at the time.
It takes organisations an average of 85 days just to spot and contain one of these.
Then there is bring-your-own-device working: 60% of IT professionals cite security as their principal concern, and 84% worry about shadow IT they cannot see, let alone control.
Put simply, the attack surface has grown faster than most organisations’ ability to watch it.
Then there is the state threat, which is not theoretical in the slightest. Richard Horne, Chief Executive of the National Cyber Security Centre, told the Royal United Services Institute’s annual security lecture this year that the NCSC had managed more than 200 cyber-incidents affecting the UK’s critical national infrastructure and supporting ecosystem in the year to May, and that around three-quarters of those were believed to be linked to hostile states.
It is hard to improve on that as a summary of why access control now belongs in the boardroom rather than the facilities budget.
Technology is closing the gap
It is not all grim reading, though, and it would be wrong to leave it there.
Biometric authentication has matured considerably, particularly through liveness detection, which works out whether it is looking at a genuine human being rather than a photograph, a mask or a synthetic replica.
These systems are tested against ISO/IEC 30107, the international standard for presentation attack detection and the market for face liveness technology alone is forecast to grow significantly.
Static, role-based permissions are giving way to attribute-based access control, which weighs job function, data sensitivity, location and time of day for every single request in real time.
It is a far closer fit to zero-trust thinking than any fixed rulebook could ever manage.
There are further developments worth watching closely. Network access control is becoming AI-assisted: systems that profile devices by type and behaviour, flag anything that drifts from a learned baseline and isolate a misbehaving device automatically rather than waiting for an analyst to notice one more alert among thousands.
That matters most for the Internet of Things, where devices still ship, far too often, with default passwords and firmware nobody has patched in years.
Identity itself is also being reimagined through blockchain, holding credentials across a distributed network rather than a single central database and letting someone prove they are over eighteen, or hold the right clearance, without handing over the underlying document at all.
Neither idea is universal yet. Both point the same way: verification that never really stops.
Cryptography, meanwhile, is being rebuilt for a threat that has not arrived but cannot be wished away.
In August 2024, the US National Institute of Standards and Technology published its first three post-quantum cryptography standards – ML-KEM for key establishment, and ML-DSA and SLH-DSA for digital signatures.
IBM contributed to two of the three and has built post-quantum capabilities into its z16 systems.
NIST plans to start deprecating today’s vulnerable algorithms, including RSA and elliptic-curve cryptography, from 2030, and disallow them outright by 2035.
Ten years sounds a long way off. For anyone holding data that needs to stay secret for a decade or more, it already isn’t.
The most persuasive evidence for convergence, though, is commercial rather than technical.
The IBM Institute for Business Value surveyed a thousand security executives across 21 industries and found that organisations running a genuinely unified platform – video, access control and cyber-telemetry sharing one system rather than stitched together with middleware – achieve an average return on investment of 101%, against 28% for those still running fragmented tools.
The unified group detect incidents 72 days faster and contain them 84 days faster.
That is not a marginal improvement – it is the difference between an incident that gets caught quietly and one that ends up on the front page.
The principal underneath all of this is not complicated, even if the execution is: assume the credential will be stolen, assume the device will be compromised and build systems that keep checking rather than ones that trust once and walk away.
The fence, the badge and the firewall are one problem now.
Organisations that have understood that will still be standing when the next incident lands. The rest will be explaining themselves.