The perimeter is dead. Every cybersecurity professional has heard that phrase, but the last two years have made it brutally concrete. When your workforce is distributed, your critical applications live in cloud instances you don’t physically own, and your customers access your systems through APIs you didn’t write, the idea of a walled fortress becomes not just outdated but dangerous. Protecting a business network now means defending an invisible, shifting surface that expands with every new SaaS subscription and remote hire.
Here is how the threat landscape changed, and what actually works to protect a modern business network right now.
The Attack Surface Has Exploded, and You’re Not Imagining It
It isn’t just that attackers have gotten more sophisticated. The number of entry points a mid-sized business presents to the internet has quietly tripled over the last few years. Every employee carries a phone with corporate email, messaging apps, and often direct access to internal systems. Every third-party vendor has some level of digital connection to your ordering, invoicing, or support platforms. The Internet of Things devices you may not even think about—conference room cameras, smart thermostats, networked printers—sit on the same network fabric as sensitive financial data.
External attacks now overwhelmingly exploit these forgotten edges. The 2024 Verizon Data Breach Investigations Report confirmed that the initial access vector in most breaches is no longer a direct server compromise; it’s stolen credentials, a phishing link opened on an unmanaged device, or an unpatched vulnerability in a perimeter appliance like a VPN gateway or firewall.
The takeaway isn’t to abandon these tools. It’s to accept that anything reachable from the internet is under constant, automated probing, and to architect as if compromise of any single edge node is inevitable.
Identity Is the New Battleground
If the network perimeter has dissolved, identity becomes the one control point that cuts across everything. This is why attackers have shifted decisively toward credential theft, session hijacking, and multi-factor authentication fatigue.
The password-only era is ending, but unevenly. Every business that still allows single-factor authentication on any externally accessible service is a soft target. Attackers are not cracking passwords by brute force; they are buying them in bulk from infostealer logs, harvested from malware-infected personal devices, and then spraying those credentials against corporate VPNs, Microsoft 365 tenants, and remote desktop gateways.
Mandatory multi-factor authentication is the baseline, but even that is now being actively subverted. Adversary-in-the-middle proxies, first popularized by the EvilGinx framework, can intercept a live session token after a user has fully authenticated with MFA. The token is then used immediately by the attacker, and the user sees a failed login page and assumes they mistyped something. The real protection against this is phishing-resistant MFA, specifically FIDO2 security keys or device-bound passkeys, which cryptographically bind the authentication to the legitimate domain and prevent proxy interception.
For businesses not yet on phishing-resistant MFA: accelerate the timeline. The attack tooling is commoditized, and the window between a credential being stolen and being abused is now measured in hours.
The Unmanaged Device Problem Is Now Unavoidable
Bring-your-own-device policies were once a perk. They are now the dominant reality, and they have introduced a class of exposure that traditional network defenses were never designed to handle.
An employee checks email on a personal phone that hasn’t received a security patch in six months. They download a PDF from what looks like a client, and a hidden infostealer scrapes every saved password in their browser, including the one for the corporate single sign-on portal. No intrusion detection system inside the office catches this, because the compromise happened entirely off the corporate network, on a device the IT team has never touched.
The practical answer, for most organizations, is an evolution toward Zero Trust Network Access. Instead of granting network-level access via a VPN, which inherently trusts any device that clears the credential check, ZTNA brokers access per application. The user authenticates, the device posture is checked—OS version, encryption status, absence of known malware signatures—and only then is a session established to that specific application. The device never gains visibility of the broader network, making lateral movement dramatically harder.
This is not only for large enterprises. The proliferation of managed ZTNA services aimed at the mid-market has made it accessible, and the alternative of maintaining a traditional VPN without device posture checks is an increasingly indefensible position.
Ransomware Has Industrialized, and Your Backups Are a Target
Ransomware groups now operate as professional enterprises with affiliate programs, help desks, and negotiated commission structures. Their focus has shifted from broad, untargeted spray to deliberate, researched attacks on organizations they know can pay. Law firms, manufacturers, healthcare providers, and local governments are the bullseye.
The initial entry is almost always external: an open remote desktop port with a weak credential, an unpatched file transfer appliance, a targeted phishing campaign against someone in accounts payable. Once inside, the dwell time—the period between initial compromise and detonation—is spent mapping the backup infrastructure. Attackers now methodically locate and destroy backup servers, offline replication targets, and even cloud backup accounts before encrypting production data.
A backup strategy that worked five years ago fails catastrophically here. If your backups live on a domain-joined system with the same authentication stack as production, they will be encrypted or deleted along with everything else. The standard that now applies is immutability—backups that cannot be modified or deleted within a retention window, even by a fully privileged administrator account. Offline air-gapped copies remain essential, but object-locked cloud storage that enforces write-once-read-many policies is becoming the practical defense for most.
Supply Chain Trust Is Being Weaponized
The path into your network increasingly runs through the software and services your business already trusts. The SolarWinds incident was the wake-up call, but the more common vector now is far less sophisticated: a compromised open-source library, a poisoned update to a widely used IT management tool, or a breached support portal at a critical vendor.
Defending against this starts with a brutally honest inventory. Most organizations cannot confidently list every third-party integration that holds a persistent connection, API key, or support tunnel into their environment. That list must exist, and it must be audited. Vendor risk assessments can no longer be a compliance checkbox; they require evidence of the vendor’s own incident response capability and their access control practices.
On the software supply chain side, the move toward Software Bills of Materials is gaining regulatory teeth. Knowing the dependency tree of every application running in the environment—down to the open-source logging library—is transitioning from a best practice to a contractual requirement and, in some sectors, a legal obligation. The tools to generate and verify SBOMs are maturing fast, and attackers are counting on the fact that most businesses haven’t adopted them yet.
Detection That Assumes You’re Already Inside
The legacy security model treated detection as a second line, behind prevention. That ordering is now inverted. A capable attacker will get past the firewall, the endpoint protection, and the spam filter. The question is whether your network notices them moving laterally before they reach the domain controller.
Extended detection and response platforms have matured to the point where they correlate signals from endpoint, identity, email, and cloud workloads in near-real time. A failed MFA attempt from an unusual geolocation, followed seconds later by a successful one and an immediate file share enumeration, now triggers an automated response: revoke the session, isolate the host, force a password reset, and open a prioritized ticket.
For smaller teams without 24-hour security operations centers, managed detection and response services fill this gap. They combine platform telemetry with outsourced threat hunting, and the economics of these services have improved to where they are viable for businesses that would never have considered a SOC just three years ago.
The Practical Path Forward
The defenses that matter most are also the least glamorous. Enable phishing-resistant MFA everywhere it is supported. Inventory and secure every internet-facing service, especially the forgotten ones. Implement application-level access controls that do not trust the network. Establish immutable backups and test the restore procedure, not just the backup. Map your supply chain dependencies and set a minimum security bar for vendors holding sensitive access.
There is no single product that delivers protection. The businesses that fare best in the current environment are those that treat security as an architectural property of how they build and connect systems, not as a layer added after the fact. Attackers are counting on inertia, on the assumption that what worked last year still works. It doesn’t.











