TechKnowSurge
CompTIA Security+ 3.1 ISC2 CISSP 4.1 NIST CSF PR.IR-01
VideoSecurityFree

Deperimeterization

Deperimeterization is a modern network security mindset that shifts focus away from perimeter defenses like firewalls toward protecting the entire network from within. Policy-driven approaches such as zero trust and network access control are central to this strategy.

Complete this video to capture a CTF flag worth 1 point.

About this video

Traditional network security treated the perimeter as the primary line of defense, concentrating resources on firewalls and boundary controls to keep threats from reaching the internal network. This approach, often compared to protecting the center of an onion, assumed that a well-secured outer layer would keep core assets safe. Defense in depth added internal layers, but the perimeter remained the dominant focus. Deperimeterization challenges that assumption by recognizing that the attack surface is far more complex. Threats frequently originate from within the network itself, particularly through users who click malicious links or open infected attachments, granting external actors access that bypasses perimeter controls entirely. Rather than a well-layered onion, the modern network is better compared to an artichoke, with many overlapping surfaces where an attacker might gain a foothold. The deperimeterization mindset does not call for removing firewalls or abandoning perimeter controls. Those tools still contribute meaningful protection. Instead, it reframes security priorities around the assumption that perimeter defenses alone are insufficient. Organizations adopting this model implement policy-driven controls such as zero trust networking and network access control to govern what users and devices can access, regardless of where they are on the network. The result is a security posture that emphasizes protecting core resources at every layer, reinforcing the principle of defense in depth across the entire environment.

What you'll learn

What's covered

Deperimeterization

Aligned to

CompTIA Security+
3.1 Compare and contrast security implications of different architecture models.
ISC2 CISSP
4.1 Apply secure design principles in network architectures
NIST CSF
PR.IR-01 Networks and environments are protected from unauthorized logical access and usage.

Key terms

Deperimeterization
A security mindset that shifts focus away from perimeter-based defenses toward holistic, layered protection of internal network resources and assets.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Defense-in-Depth
Defense-in-Depth is a security architecture strategy that layers multiple independent controls across technical, physical, and administrative domains so that the failure of any single control does not result in a complete security breach.
Zero Trust
A security model that assumes no user or device is trusted by default and requires continuous verification.
Firewall
A network security device that monitors and controls incoming and outgoing traffic based on predefined security rules.
Network Segmentation
The practice of dividing a network into smaller segments to improve performance and limit the spread of security threats.

Topics

Deperimeterization Zero Trust Network Access Control Defense In Depth Network Security

Transcript

In today's age, we do not put as much focus on the perimeter and perimeter security, and we call this deperimeterization.

What The Perimeter Is

The perimeter just means the outside. When we think of a perimeter of a circle, that is the circumference, or the outside of a circle. So when it comes to the perimeter of our network, this is all the entry points into our network. Where can people enter in and access our network? And the firewall was a big one that we put up as far as a defense to protect the rest of our network.

Really the focus in the past has been around this perimeter and making sure that all of those devices are protecting our internal network. Think of it like an onion. What we would have is the center, and we would want to protect the center. As long as our outside perimeter was really well protected, then that is what we cared most about. And then we would have some layers in there, because we want to practice defense in depth, but we really focused a lot on that perimeter.

Why The Perimeter Is Not Enough

But not only are there holes in the perimeters, such as vulnerabilities that our firewalls have or our access points have, but we are finding a big access is through users on our network. They have access to our network. We have granted them access to the network, and they are the ones that are opening up attachments that they should not be opening up in emails, or clicking links which then download certain applications which affect all of our network. It opens up all of our network to whatever they have opened up or whatever they have done.

So we now view our attack surface more like an artichoke, that there are all of these different surfaces that somebody could creep into and gain access to our system.

Reducing The Threat

So how do we reduce the threat? That is where we have some sort of policy-driven access control, things like network access control and zero trust networks. We implement that on the network. But this allows us to not focus as heavily on that perimeter, but on overall security of our network, and really get at what is happening on our network and how we solve issues even if somebody were to get into our network, how do we solve issues at that point.

We call this deperimeterization. Like the name suggests, it is kind of like we are getting rid of the firewall. Do not do that. Please keep your firewalls there. It does definitely add to the security. Our focus just is not that this is going to protect us. Our focus is this idea that we need to take active steps to protect the heart of our network and all of its resources, and just consider that maybe the firewall is not there at all.

So it is more of a mindset. Deperimeterization is more of a mindset that we are not going to focus so much on the outside perimeter, but we are going to focus on security as a whole. And it really reinforces that defense in depth.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →