VOOZH about

URL: https://thenewstack.io/why-the-castle-and-moat-approach-to-security-is-obsolete/

⇱ Why the Castle and Moat Approach to Security Is Obsolete - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-06-21 05:30:17
Why the Castle and Moat Approach to Security Is Obsolete
sponsor-torq,sponsored,sponsored-ebook-custom,zero-trust-security-ebook,
Security

Why the Castle and Moat Approach to Security Is Obsolete

The old ways of securing a network won't work for a distributed system. This excerpt from our new ebook explores the reasons why, and what works instead.
Jun 21st, 2022 5:30am by Emily Omier
👁 Featued image for: Why the Castle and Moat Approach to Security Is Obsolete
Featured image by Artem Sapegin on Unsplash.
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
The following is an excerpt from The New Stack’s latest ebook, “Trust No One and Automate (Almost) Everything: Building a Modern Zero Trust Strategy.” Register here to get your free download of our ebook, sponsored by Torq.

Once upon a time, IT resources lived in castles (also called “data centers”) and were protected by moats (firewalls) and knights (your friendly security specialists). In these days of yore, the assumption was simple: everything in the castle was warm and fuzzy; everything outside the castle walls was hostile wilderness.

This worked well in the long-ago time, before the 1990s. Though zero trust, as either a practice or theory, didn’t evolve until much later, it was in the ‘90s that the cracks started to show in the castle walls.

This context is important because although zero trust is often discussed in terms of cloud native systems, the need for zero trust and the move away from perimeter-based security started much earlier.

The Castle

When the entire IT system lived in one central data center, network security was much easier.

“The perimeter type of approach, the historical approach, was working fairly OK,” said Jonas Iggbom, director of sales engineering at Curity, an IAM and API security technology provider. “It was one point of entry that the firewall could control.”

With all of the IT assets on a segment of the network that was protected by a firewall, and limited access points that could be strictly patrolled, the system worked acceptably well. There were still limitations — if the firewall was ever breached, there was no security inside the network, so breaking through the firewall once gave attackers near-complete control over the system.

The problem first started with laptops and road warriors. What should the IT security think of the files on their salespeople’s 20-pound laptops? What about when you access your corporate email from a Blackberry?

“Should we treat it as if it was inside?” asked Leonid Belkind, chief technology officer and co-founder of Torq, a security automation company. “The reality of businesses being digital — adopting mobility, allowing people to work from everywhere, from every device — is that this deteriorated this whole approach of a very clear ‘who’s outside, who’s inside.’”

Then came the cloud, he noted, in the form of both Software as a Service (Saas) and Infrastructure as a Service (IaaS).

The castle was sliding into ruins before the rise in containers or microservices or anything that we would call cloud native now. It requires a completely different approach to security.

A Fortress of One

At first, the shift in security strategy went from protecting one, single castle to a “multiple castle” approach. In this scenario, you’d treat each salesperson’s laptop as a sort of satellite castle.

SaaS vendors and cloud providers played into this idea, trying to convince potential customers not that they needed an entirely different way to think about security, but rather that, by using a SaaS product, they were renting a spot in the vendor’s castle.

The problem is that once you have so many castles, the interconnections become increasingly more difficult to protect. And it’s harder to say exactly what is “inside” your network versus what is hostile wilderness.

Zero trust assumes that the castle system has broken down completely, so that each individual asset is a fortress of one. Everything is always hostile wilderness, and you operate under the assumption that you can implicitly trust no one.

It’s not an attractive vision for society, which is why we should probably retire the castle and moat metaphor. Because it makes sense to eliminate the human concept of trust in our approach to cybersecurity and treat every user as potentially hostile.

Adopting Zero Trust

Ninety-six percent of security decision-makers consider zero trust critical to an effective security posture, according to a survey published by Microsoft in July 2021. But while support for the idea of zero trust is close to universal, vanishingly few companies are implementing it effectively.

Sixty-five percent of companies use shared logins and 42% use shared SSH keys, according to a 2022 survey by strongDM; both practices run absolutely counter to zero trust principles. Zero trust requires not just rethinking your security program but also re-architecting your application to make the new strategy possible.

Implementation starts with granular authentication systems, which means forcing any users, human or server, that want to access a resource to prove that they are who they say they are.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq

Once you’ve authenticated a user, the next step is to follow that up with authorization or enforcement: Is that user allowed to perform the action it wants to perform? According to Iggbom, authentication is fairly widely adopted, but far fewer organizations follow that up with zero trust authorization systems.

Most systems would previously have been set up so people could authenticate into a castle — a group of actions. One of the things that sets zero trust apart is that it requires extreme granularity, allowing users to access or alter only the very specific resource they’ve requested access to, at the specific time they’ve requested that access.

Torq is a no-code automation platform for security and operations teams. Easy workflow building, endless integrations, and out-of-the-box templates deliver value in minutes — not weeks. Torq and TNS are under common control.
Learn More
The latest from Torq
TRENDING STORIES
Emily helps open source startups accelerate revenue growth with killer positioning. She writes about entrepreneurship for engineers, and hosts The Business of Open Source, a podcast about building open source companies.
Read more from Emily Omier
Torq sponsored this post. Insight Partners is an investor in Torq and TNS.
SHARE THIS STORY
TRENDING STORIES
Curity is a sponsor of The New Stack.
TNS owner Insight Partners is an investor in: Pragma, Torq.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.