The perimeter is gone. Security has to follow the data.

sasha85ru / Getty Images

COMMENTARY | Many zero trust plans are still anchored to the old idea of the border. That protects a version of government IT that no longer exists.

For years, federal security rested on one idea: the perimeter. Agencies drew a line around their networks and watched that line closely. They trusted what was inside while treating everything outside as a threat. That worked when systems stayed in government buildings and people worked from a desk down the hall, but it doesn’t match how agencies work today.

Washington has already admitted this, at least on paper. The Federal Zero Trust Strategy moved agencies away from that old model years ago. It replaced trust at the border with constant checks on every user, device and app. The strategy set clear goals — like logins that resist phishing — and pushed real progress across a famously messy IT landscape. 

But hitting the established goals doesn’t necessarily close the gap. Many agencies can show they meet the new rules, while their budgets and tools still center on the old line. The mandate moved past the perimeter, but the systems underneath are still catching up.

Defending a line that no longer holds anything

Most agencies still spend the bulk of their security budget guarding a line that data crosses every day. Mission data moves through cloud systems, sits on edge devices that support teams in the field and feeds the artificial intelligence models that agencies are racing to build. Watching traffic at a border the data has already crossed will not close that gap. It doesn’t matter how many tools sit at the edge. The result looks fine on a compliance report, but it leaves agencies open everywhere their data has actually gone.

Security has to travel with the mission, not wait at the border

The fix relies on taking a different approach. If mission data does not stay in one place, protection can’t either. That means building detection into the storage layer, where the data actually lives. Catch odd activity early, before it spreads, instead of after a breach report lands on the CIO’s desk. It means controls that travel with the data, no matter which cloud or system it reaches. And it means one recovery plan that works across local systems, hybrid setups,and many clouds at once, rather than a patchwork built for separate eras of IT.

This is what real data infrastructure modernization means for security. Agencies need to decide where protection truly needs to live, then build out from there.

AI is expanding the attack surface agencies have to defend

AI speeds up every part of this problem. Agencies are standing up new models for logistics, fraud detection and mission planning. As they do, their data spreads across more systems at once. The Cybersecurity and Infrastructure Security Agency recently issued fresh guidance on this point. Old perimeter defenses fall short in these settings. Aging gear, sensors and smart devices now share the same network. The data that powers an agency’s best AI work is also its biggest weak spot, so protecting it has to happen at the layer beneath those workloads.

Attackers have noticed this shift too. Microsoft has reported that AI-written phishing emails now get clicked more than half the time. Older phishing emails only got clicked about 12% of the time. That is a jump of more than four hundred percent. This kind of edge for attackers makes it clear that defense cannot rely on stopping every attempt at the door. It has to hold up even when something gets through.

When data crosses agencies, so does the question of who protects it

Government data rarely stays inside one agency anymore. It moves across shared systems, outside providers and cloud platforms built for joint work. As data spreads, ownership gets harder to pin down. A system nobody clearly owns tends to be a system nobody fully defends. The fix is to build protection into the data itself, as opposed to building it into whatever system happens to hold the data that day. That removes the confusion. 

Resilience has to be designed in, not bolted on later

The agencies that come out ahead will be the ones that treat cyber resilience as a data problem, not a perimeter problem. They will build protection in from day one instead of bolting it on after an incident report. 

Many zero trust plans are still anchored to the old idea of the border. That protects a version of government IT that no longer exists. Real resilience gets built into the data itself from the start. That holds true through every stage of cloud transformation and modernization. When the edge gets crossed, as it someday will, something solid sits underneath it. Mission data stays protected, public trust holds and government services keep running for the people who depend on them.

Riccardo Di Blasio is the Senior Vice President, North America Sales at NetApp.