From network diagrams to people
For years, cyber security strategy started with a network diagram. Draw the office, the firewall, the VPN. Decide what was “inside” and “outside” and pile controls on the border. That model was already creaking under cloud and hybrid work; by 2026, it is largely a comforting illusion. For modern attackers, the real perimeter is not the network at all. It is the identity: the human, the account, the token.
The initial foothold in serious breaches is rarely a Hollywood-style zero-day. It is someone being tricked into doing something that looks almost normal: a crafted email, a Teams message, a login prompt that appears just like the real thing. Once the attacker has a valid account – especially one with elevated permissions – the firewalls and VPN concentrators become background scenery.
When MFA isn’t enough
Multi-factor authentication was supposed to save the day. For a while, it did raise the bar. But as more organisations rolled MFA out, attackers adapted. Rather than give up, they added a step to the playbook: MFA fatigue and push-bombing attacks, where users are bombarded with prompts until they tap “approve” just to make the noise stop. Add a phone call pretending to be IT support, and the second factor becomes just another human decision point that can be manipulated.
When that fails, there is token and cookie theft. Once a user has logged in, their browser holds the keys in memory. Modern phishing kits and infostealers can harvest session tokens and replay them elsewhere. From the cloud provider’s perspective, nothing looks amiss; a valid token is being used, and the usual controls are satisfied. The attacker is now “inside” without ever knowing the victim’s password.
This is why the old perimeter mindset is so dangerous. If you still think in terms of “trusted internal network” and “untrusted external network”, you will miss the fact that the attacker is not trying to storm the walls. They are borrowing someone’s face and walking in through the staff entrance.
How modern platforms are abused
For UK tech firms, this shift is most visible in how common platforms are abused. Microsoft 365 tenants where invoicing is quietly hijacked through inbox rules and forwarding. Google Workspace estates where OAuth consent is abused to grant a malicious app broad access to mail and files. Developer teams targeted through GitHub and GitLab, with attackers stealing personal access tokens rather than trying to crack the hosting platform itself.
The stories have a familiar rhythm. First, a convincing phish or malicious link via a channel the victim is used to trusting. Then, a prompt for consent or authentication that looks routine. Once the attacker has a foothold, they do not rush. They watch how the business operates, who approves payments, which suppliers are regular, which executives travel a lot and are less responsive. Only then do they start to monetise access, often by changing bank details on invoices, rerouting payments or exfiltrating data quietly over weeks.
Defenders who still frame their world as boxes and arrows will struggle to see any of this. Defenders who frame it as identities and relationships have a better chance.
What identity‑first defence looks like
An identity‑first defence starts by treating “MFA enabled” as a starting point, not a destination. The real questions are what kind of MFA, applied where, with what checks around it. Phishing‑resistant methods such as FIDO2 security keys or platform authenticators tied to the device are harder to bypass than SMS codes or simple push approvals. Conditional access policies that look at device health, location and risk signals can do more still, challenging for step‑up authentication when something looks off rather than blindly trusting every successfully presented token.
Next, cloud identity providers need to become the centre of gravity. For many organisations, the identity provider – whether Azure AD, Okta, Google or another platform – is effectively the new domain controller. Logs from those systems should be treated as primary telemetry. Who is logging in from where, with what device? Which applications have consent to read mail, access storage or manage configurations? Which accounts hold admin rights they do not need?
Automation and the human factor
Attackers use automated tooling to scale reconnaissance and phishing; defenders can and should use automation to scale detection and response. That does not have to mean a full‑blown SOAR platform. Even modest organisations can benefit from rules that disable accounts exhibiting certain patterns, flag unusual consent grants, or alert when an impossible travel pattern appears. AI‑driven tools that summarise long audit logs or surface anomalies can be powerful helpers for understaffed security teams, as long as they are treated as copilots, not autopilots.
Finally, there is the human side. Identity is not just an entry in a directory; it is a person trying to do their job. Security controls that constantly get in the way will be worked around or quietly disabled. Security teams need to spend as much time on user experience as on policy: clear communication about changes, simple explanations of why prompts appear, and fast, respectful support when something goes wrong.
The cliché is that “the perimeter is dead”. In reality, it has moved. It now wraps itself around every account, every token, every authenticated session. The firewall still matters, but if your map of the world starts there, you are defending the wrong border.