Security Architecture & Threat Strategy
The Threat
Doesn't Wait
CVEs doubled in five years. AI agents now execute attack chains autonomously in minutes. SASE and ZTNA are necessary — but neither is sufficient. The case for intent-driven security architecture, and why outcomes drive the only value that matters.
Security · SASE · ZTNA · Threat Hunting
Every day, new vulnerabilities are published. Every day, threat actors — and now autonomous AI agents — are scanning, probing, and exploiting them faster than most security teams can track. The threat landscape is not growing at a linear rate. It is compounding. And the organizations that are most exposed are not the ones that lack security tools. They are the ones whose security tools are deployed without a clear architectural intent — without a defined answer to the question: what, specifically, are we protecting, from what, and how will we know if it is working?
This article makes the threat environment visible with data, explains the responsibilities of the teams tasked with defending against it, and then confronts the harder question: why SASE and ZTNA — despite being the right architectural foundations — are still not enough on their own, and what the missing layer is.
Red Team & Blue Team: The Complementary Architecture of Defense
Security is not a product. It is a discipline that requires two distinct but complementary activities running simultaneously: one that continuously attempts to break the defenses, and one that continuously operates and improves them. These are the Red Team and Blue Team functions — and the gap between organizations that treat them seriously and those that treat them as checkbox exercises is the gap between organizations that discover breaches internally and those that learn about them from external notification.
// The coverage gap
Only 41% of organizations conduct or utilize red team services (Core Security Penetration Testing Survey 2024). Organizations with purple team collaboration — where red and blue operate jointly — report 88% effectiveness against ransomware, versus 52% for siloed programs. The majority of organizations are running a defense with no one actively testing whether it actually works.
Threat Hunting: Finding What Automation Misses
Automated detection is designed to catch known threats with known signatures. Threat hunting is designed to find the threats that automated tools were never designed to question. The distinction matters because modern attackers — particularly AI-augmented ones — are increasingly operating without malware signatures at all. 81% of interactive intrusions in 2025 were malware-free. Living-off-the-land (LOTL) techniques use legitimate system tools, real credentials, and normal-looking traffic to move through environments undetected.
Threat hunting assumes the attacker is already inside. It works backwards from that assumption — forming hypotheses about how an adversary might be operating, and then searching for behavioral evidence across logs, network telemetry, endpoint data, and identity systems. The SANS 2025 Threat Hunting Survey found that 76% of organizations have encountered LOTL techniques from nation-state actors, and nearly half of ransomware attacks in 2024 used LOTL methods.
"Proactive threat hunting closes the gap between what automated tools catch and what adversaries are actually doing. The median dwell time of 11 days assumes someone is actively looking. Most aren't."
// The detection gap every organization should be measuring
The ROI case for threat hunting is measurable: organizations with mature programs reduce mean time to detect from months to hours, and SANS 2024 data shows a 10:1 ROI through breach prevention and reduced incident costs. The barrier is not methodology — it is analyst capacity and organizational commitment to treating security as a continuous practice, not a periodic audit.
SASE and ZTNA: The Right Foundation, Incompletely Implemented
Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) represent a genuine architectural advancement over legacy perimeter security. They are the right direction. But they are not a destination — they are an infrastructure layer, and like all infrastructure layers, their value depends entirely on how well they are implemented, governed, and aligned to the organization's actual security intent.
SASE converges networking (SD-WAN) and security (SWG, CASB, ZTNA, FWaaS) into a cloud-delivered platform. ZTNA implements the principle that no user or device is trusted by default — access is granted per-application, per-session, based on continuous verification of identity, device posture, and context. Together, they eliminate the castle-and-moat model that collapsed the moment remote work became the default.
The market has consolidated around a clear set of leading platforms, each with a distinct architectural philosophy:
| Dimension |
SASE |
ZTNA |
| Scope |
Full platform: networking + security converged (SD-WAN + SSE + ZTNA + FWaaS + CASB) |
Access control only: user/device → application, per-session, per-verification |
| Architecture |
Cloud-delivered service from vendor PoP network; replaces hub-and-spoke WAN |
Software-defined perimeter; can be cloud-delivered or on-prem component |
| What it solves |
WAN complexity, inconsistent security enforcement across locations, VPN fragility |
Implicit trust in network access; VPN replacement; over-permissive lateral movement |
| What it doesn't solve |
Post-access lateral movement; insider threat; misconfiguration; AI-agent attacks operating with legitimate credentials |
Network-level threats; data security; cloud application governance; branch connectivity |
| Best vendor fit |
Netskope, Palo Alto, Zscaler, Cato, Fortinet, Cloudflare |
Zscaler ZPA, Palo Alto Prisma, Cisco Secure Access, Netskope NPA |
| Missing layer |
Intent validation: neither architecture guarantees that what is permitted is what is intended — or that what is happening is what policy specifies |
The Intent Fabric: What SASE and ZTNA Don't Provide
SASE and ZTNA are infrastructure architectures. They define how access is granted and how traffic is secured in transit. What neither provides — and what organizations consistently mistake for having when they deploy them — is continuous validation that the intent behind the policy is being achieved in practice.
This is the "intent fabric" concept: a continuous, mathematically modeled layer that sits across the network and security architecture and answers a question neither SASE nor ZTNA can ask: is the network doing what we designed it to do?
Consider what this means concretely. A ZTNA policy can permit a specific user, on a verified device, to access a specific application. What it cannot tell you is whether the ACL governing traffic between that application and the database behind it has drifted from policy. Whether a routing configuration change last Tuesday opened a path that shouldn't exist. Whether a firewall rule added six months ago for a now-decommissioned service is still active and creating a cross-security-boundary exposure.
// What the intent fabric provides
A network digital twin — a mathematical model of the actual network state, not the intended state — continuously verifies that what the network is doing matches what the security policy specifies. It does not replace SASE or ZTNA. It validates them. It is the difference between a firewall policy document and proof that the firewall is enforcing it.
This approach was the foundation of the work I performed at Forward Networks — building the human-in-the-loop analysis layer that turned a digital twin into actionable security intelligence. Black hole routes, cross-boundary access, BGP misconfigurations, stale ACLs creating unintended exposure — none of these are visible in a SASE dashboard. All of them are visible in a continuously modeled network intent architecture.
Outcomes Drive Value. Nimble Architectures Enable Adoption.
The security market is full of platforms that do more than any organization uses, and organizations that have deployed more platforms than any team can manage. The result — as the complexity blog in this series documented — is a security environment that generates noise, not clarity, and cost without measurable protection improvement.
Two principles cut through this consistently.
Outcomes drive value. A SASE deployment is not a security outcome. Reduced attack surface, measured dwell time, verified policy compliance, documented reduction in exploitable exposure — these are outcomes. Every security investment should be scoped to a measurable outcome before it is selected. The platform follows from the outcome. It does not define it.
Nimble architectures enable adoption. The most sophisticated security platform in the world provides no value if the organization cannot operate it. Complexity defeats adoption at every level: security teams that cannot effectively manage the tool, network teams that cannot integrate it with existing infrastructure, leadership that cannot interpret its outputs, and compliance teams that cannot map its logs to the frameworks they are required to satisfy. Architecture designed for the organization's actual operational maturity — not for the vendor's feature catalogue — is the architecture that actually gets used.
"The threat doesn't wait for your architecture to mature. But an architecture that cannot be adopted is worse than no architecture — it creates the illusion of protection without the substance."
// The adoption gap that most security deployments ignore
This is the work that produces security that actually works: starting from the outcome, selecting the architecture that achieves it with the least operational friction, validating that the architecture is doing what it is intended to do, and maintaining the human expertise required to interpret what the tools cannot tell you on their own.
AI agents are already working in clusters to develop and deploy threats autonomously. The defense requires both the right infrastructure and the right human analysis layer. Neither alone is sufficient. Both, aligned to defined outcomes, is what protects organizations that actually intend to stay protected.