Security Architecture & Threat Strategy

The Threat
Doesn't Wait

CVEs doubled in five years. AI agents now execute attack chains autonomously in minutes. SASE and ZTNA are necessary — but neither is sufficient. The case for intent-driven security architecture, and why outcomes drive the only value that matters.

INCIDENTTIMELINErecon to exfil:under 4 hoursCVEs / YEAR20192020202120222023202429K+AI ATTACK CHAINRecon · automatedExploit · minutesLateral · secondsExfil · completeSASE / ZTNAthe response architectureStops lateral movementCredential ≠ network accessContinuous session verifyPolicy enforced in secondsno human reaction time neededattacker window: minutesSASE response: millisecondsCVEs DOUBLED IN 5 YEARS · AI EXECUTES ATTACK CHAINS IN MINUTES

Every day, new vulnerabilities are published. Every day, threat actors — and now autonomous AI agents — are scanning, probing, and exploiting them faster than most security teams can track. The threat landscape is not growing at a linear rate. It is compounding. And the organizations that are most exposed are not the ones that lack security tools. They are the ones whose security tools are deployed without a clear architectural intent — without a defined answer to the question: what, specifically, are we protecting, from what, and how will we know if it is working?

This article makes the threat environment visible with data, explains the responsibilities of the teams tasked with defending against it, and then confronts the harder question: why SASE and ZTNA — despite being the right architectural foundations — are still not enough on their own, and what the missing layer is.

Chart 01 — CVE Volume
Total CVEs published per year (2018–2024) with critical/high severity breakdown
40,308
CVEs published in 2024
a 39% single-year increase
40,308 vulnerabilities were published in 2024 — a 39% increase in a single year and the highest annual total ever recorded (CVEdetails.com). The five-year trend from 2020 to 2024 shows a 120% increase in total CVE volume. 80% of exploits are published before their corresponding CVE, giving attackers a median 23-day head start before defenders are even aware of the vulnerability. 75% of attacks in 2024 used vulnerabilities that were at least two years old — meaning patch management remains as critical as threat detection.
Chart 02 — Threat Dwell Time
Median attacker dwell time (days) vs. % breaches found by external parties (2019–2024)
181
avg. days a breach goes
undetected (IBM 2025)
Median attacker dwell time has improved dramatically from 416 days in 2011 — but rose back to 11 days in 2024 for the first time since Mandiant began tracking (M-Trends 2025). The average breach still goes undetected for 181 days, and 57% of compromises are discovered by external parties, not the organization's own security team (Mandiant 2025). Organizations with active threat hunting programs reduce average dwell time by 35% compared to those relying solely on automated detection (SANS 2025). The breach lifecycle from identification to containment averages 241 days — at an average cost of $4.88M (IBM 2024).
Chart 03 — AI-Powered Threat Acceleration
Key metrics showing AI's impact on the attack-defense timeline (2022–2025)
265+
named adversaries tracked
by CrowdStrike (2025)
AI-driven exploits can now execute a full ransomware kill-chain in 25 minutes (Unit 42, 2025). Voice phishing attacks surged 442% in H2 2024 as AI-generated voices enable mass-scale social engineering (CrowdStrike). Cloud intrusions increased 136% in H1 2025 compared to all of 2024. CrowdStrike now tracks more than 265 named adversaries and 150+ activity clusters. Attackers achieve mass exploitation of critical vulnerabilities within 5 days of disclosure; organizations take a median of 38 days to remediate (Verizon 2025 DBIR). 81% of interactive intrusions in 2025 were malware-free — attackers use legitimate tools and credentials, making signature-based detection blind to the majority of active attacks.

Red Team & Blue Team: The Complementary Architecture of Defense

Security is not a product. It is a discipline that requires two distinct but complementary activities running simultaneously: one that continuously attempts to break the defenses, and one that continuously operates and improves them. These are the Red Team and Blue Team functions — and the gap between organizations that treat them seriously and those that treat them as checkbox exercises is the gap between organizations that discover breaches internally and those that learn about them from external notification.

Red Team — Offensive
Simulate. Exploit. Report.
  • Reconnaissance and OSINT mapping of the attack surface
  • Penetration testing across network, applications, and endpoints
  • Social engineering and phishing simulations
  • Exploitation of vulnerabilities before threat actors do
  • Lateral movement and privilege escalation exercises
  • Physical security testing and unauthorized access attempts
  • Post-engagement reporting with remediation priorities
  • Validation of compliance frameworks (HIPAA, PCI, CMMC, NIST)
Blue Team — Defensive
Monitor. Detect. Respond.
  • Continuous monitoring of network, endpoint, cloud, and identity
  • SIEM management, log correlation, and alert triage
  • Threat hunting — proactive search for undetected adversaries
  • Incident response: containment, eradication, recovery
  • Vulnerability assessment and patch prioritization
  • Firewall and ACL policy management and optimization
  • Security tool tuning to reduce false positives
  • GRC compliance monitoring and audit evidence generation
// The coverage gap

Only 41% of organizations conduct or utilize red team services (Core Security Penetration Testing Survey 2024). Organizations with purple team collaboration — where red and blue operate jointly — report 88% effectiveness against ransomware, versus 52% for siloed programs. The majority of organizations are running a defense with no one actively testing whether it actually works.

Threat Hunting: Finding What Automation Misses

Automated detection is designed to catch known threats with known signatures. Threat hunting is designed to find the threats that automated tools were never designed to question. The distinction matters because modern attackers — particularly AI-augmented ones — are increasingly operating without malware signatures at all. 81% of interactive intrusions in 2025 were malware-free. Living-off-the-land (LOTL) techniques use legitimate system tools, real credentials, and normal-looking traffic to move through environments undetected.

Threat hunting assumes the attacker is already inside. It works backwards from that assumption — forming hypotheses about how an adversary might be operating, and then searching for behavioral evidence across logs, network telemetry, endpoint data, and identity systems. The SANS 2025 Threat Hunting Survey found that 76% of organizations have encountered LOTL techniques from nation-state actors, and nearly half of ransomware attacks in 2024 used LOTL methods.

"Proactive threat hunting closes the gap between what automated tools catch and what adversaries are actually doing. The median dwell time of 11 days assumes someone is actively looking. Most aren't."

// The detection gap every organization should be measuring

The ROI case for threat hunting is measurable: organizations with mature programs reduce mean time to detect from months to hours, and SANS 2024 data shows a 10:1 ROI through breach prevention and reduced incident costs. The barrier is not methodology — it is analyst capacity and organizational commitment to treating security as a continuous practice, not a periodic audit.

SASE and ZTNA: The Right Foundation, Incompletely Implemented

Secure Access Service Edge (SASE) and Zero Trust Network Access (ZTNA) represent a genuine architectural advancement over legacy perimeter security. They are the right direction. But they are not a destination — they are an infrastructure layer, and like all infrastructure layers, their value depends entirely on how well they are implemented, governed, and aligned to the organization's actual security intent.

SASE converges networking (SD-WAN) and security (SWG, CASB, ZTNA, FWaaS) into a cloud-delivered platform. ZTNA implements the principle that no user or device is trusted by default — access is granted per-application, per-session, based on continuous verification of identity, device posture, and context. Together, they eliminate the castle-and-moat model that collapsed the moment remote work became the default.

The market has consolidated around a clear set of leading platforms, each with a distinct architectural philosophy:

Zscaler
Cloud-proxy SSE / ZTNA pioneer

Strength: Zero-trust architecture built from the ground up, 150+ global PoPs, market-leading ZIA (internet) + ZPA (private access) combination. Strongest ZTNA pedigree and SWG capabilities. Dominant in large enterprise with complex internet access requirements.

Limitation: No native SD-WAN; limited hardware connectivity; proxy architecture can introduce latency for non-web protocols. Separate management portals for ZIA and ZPA create operational complexity.

Gartner SSE MQ Leader 2025 (top position) · Forrester SASE Wave Leader
Palo Alto Networks Prisma SASE
Network-native SASE / SecOps integrated

Strength: Deepest SecOps integration — Prisma Access feeds directly into Cortex XSIAM/XDR/XSOAR for a single investigation loop. Blocks 11.3B attacks per day via cloud-delivered NGFW. Strongest for organizations already in the Palo Alto ecosystem. 3× Gartner MQ SASE Leader.

Limitation: Higher cost ($14–$22/user/month). Complexity of integrating multiple acquisitions. Less forward-looking on future SASE challenges per Forrester.

Gartner SASE MQ Leader · Forrester SASE Wave Leader · 3× consecutive recognition
Netskope
Data-centric SSE / SASE platform

Strength: Best-in-class DLP and CASB with 3,000+ data identifiers across 2,100+ file types. NewEdge private backbone across 75+ regions, 120+ data centers. Strongest for organizations where data protection and AI governance are the primary concern. Gartner Leader in both SSE and SASE.

Limitation: ZTNA (NPA) is newer and less mature than Zscaler or Palo Alto for complex legacy protocol environments. Client can be resource-intensive on older endpoints.

Gartner SSE & SASE MQ Leader · Forrester #1 SASE Wave 2025 · IPO pending at $6.5B valuation
Cato Networks
True single-vendor SASE / private backbone

Strength: Built as a single platform from day one — SD-WAN, SSE, ZTNA, and monitoring in a unified console with a single client. Own private global backbone. Fastest "VPN-off" path for organizations consolidating infrastructure. Strong for mid-market and multi-site deployments.

Limitation: Less mature enterprise feature depth compared to Zscaler or Palo Alto for complex financial or healthcare compliance requirements. Smaller partner ecosystem.

Forrester SASE Wave Strong Performer · Gartner SASE recognition · $200M+ ARR (private)
Cisco Secure Access
Hybrid ZTNA + legacy integration

Strength: Best fit for Cisco-heavy environments — integrates with Duo MFA, ISE, Meraki, and the Cisco identity stack. Supports hybrid ZTNA + VPNaaS for awkward legacy protocols that pure cloud ZTNA cannot handle. Miercom named Cisco #1 in efficacy, manageability, and performance ahead of Zscaler, Palo Alto, and Netskope.

Limitation: Split management interface (Meraki for networking, Secure Access for security) creates operational friction. Not a Forrester SASE Wave inclusion — still consolidating interfaces into a unified platform.

Miercom Performance Leader 2024 · Strong fit for existing Cisco ecosystem · Unified platform in progress
Fortinet FortiSASE
SD-WAN-native SASE / branch-focused

Strength: Best fit for organizations already running FortiGate / FortiSD-WAN. SWG, ZTNA, CASB, FWaaS, and DLP in a unified platform. 99.999% uptime SLA with latency assurance. 300+ global PoPs. User-based model (min. 50 licenses). Strong for distributed branch environments.

Limitation: SSE/ZTNA capabilities trail Zscaler and Netskope for cloud-first organizations. Best value when the FortiGate SD-WAN estate is already in place.

Forrester SASE Wave Strong Performer · Gartner SSE MQ recognition · FortiGate ecosystem fit
Dimension SASE ZTNA
Scope Full platform: networking + security converged (SD-WAN + SSE + ZTNA + FWaaS + CASB) Access control only: user/device → application, per-session, per-verification
Architecture Cloud-delivered service from vendor PoP network; replaces hub-and-spoke WAN Software-defined perimeter; can be cloud-delivered or on-prem component
What it solves WAN complexity, inconsistent security enforcement across locations, VPN fragility Implicit trust in network access; VPN replacement; over-permissive lateral movement
What it doesn't solve Post-access lateral movement; insider threat; misconfiguration; AI-agent attacks operating with legitimate credentials Network-level threats; data security; cloud application governance; branch connectivity
Best vendor fit Netskope, Palo Alto, Zscaler, Cato, Fortinet, Cloudflare Zscaler ZPA, Palo Alto Prisma, Cisco Secure Access, Netskope NPA
Missing layer Intent validation: neither architecture guarantees that what is permitted is what is intended — or that what is happening is what policy specifies

The Intent Fabric: What SASE and ZTNA Don't Provide

SASE and ZTNA are infrastructure architectures. They define how access is granted and how traffic is secured in transit. What neither provides — and what organizations consistently mistake for having when they deploy them — is continuous validation that the intent behind the policy is being achieved in practice.

This is the "intent fabric" concept: a continuous, mathematically modeled layer that sits across the network and security architecture and answers a question neither SASE nor ZTNA can ask: is the network doing what we designed it to do?

Consider what this means concretely. A ZTNA policy can permit a specific user, on a verified device, to access a specific application. What it cannot tell you is whether the ACL governing traffic between that application and the database behind it has drifted from policy. Whether a routing configuration change last Tuesday opened a path that shouldn't exist. Whether a firewall rule added six months ago for a now-decommissioned service is still active and creating a cross-security-boundary exposure.

// What the intent fabric provides

A network digital twin — a mathematical model of the actual network state, not the intended state — continuously verifies that what the network is doing matches what the security policy specifies. It does not replace SASE or ZTNA. It validates them. It is the difference between a firewall policy document and proof that the firewall is enforcing it.

This approach was the foundation of the work I performed at Forward Networks — building the human-in-the-loop analysis layer that turned a digital twin into actionable security intelligence. Black hole routes, cross-boundary access, BGP misconfigurations, stale ACLs creating unintended exposure — none of these are visible in a SASE dashboard. All of them are visible in a continuously modeled network intent architecture.

Outcomes Drive Value. Nimble Architectures Enable Adoption.

The security market is full of platforms that do more than any organization uses, and organizations that have deployed more platforms than any team can manage. The result — as the complexity blog in this series documented — is a security environment that generates noise, not clarity, and cost without measurable protection improvement.

Two principles cut through this consistently.

Outcomes drive value. A SASE deployment is not a security outcome. Reduced attack surface, measured dwell time, verified policy compliance, documented reduction in exploitable exposure — these are outcomes. Every security investment should be scoped to a measurable outcome before it is selected. The platform follows from the outcome. It does not define it.

Nimble architectures enable adoption. The most sophisticated security platform in the world provides no value if the organization cannot operate it. Complexity defeats adoption at every level: security teams that cannot effectively manage the tool, network teams that cannot integrate it with existing infrastructure, leadership that cannot interpret its outputs, and compliance teams that cannot map its logs to the frameworks they are required to satisfy. Architecture designed for the organization's actual operational maturity — not for the vendor's feature catalogue — is the architecture that actually gets used.

"The threat doesn't wait for your architecture to mature. But an architecture that cannot be adopted is worse than no architecture — it creates the illusion of protection without the substance."

// The adoption gap that most security deployments ignore

This is the work that produces security that actually works: starting from the outcome, selecting the architecture that achieves it with the least operational friction, validating that the architecture is doing what it is intended to do, and maintaining the human expertise required to interpret what the tools cannot tell you on their own.

AI agents are already working in clusters to develop and deploy threats autonomously. The defense requires both the right infrastructure and the right human analysis layer. Neither alone is sufficient. Both, aligned to defined outcomes, is what protects organizations that actually intend to stay protected.

// Continue the conversation

Is your security architecture aligned to outcomes?

If you're deploying or evaluating SASE, ZTNA, or threat hunting programs and want an independent assessment of whether the architecture matches the intent — let's talk directly.

// References & Sources
  1. 01NVD / NIST National Vulnerability Database
  2. 02Gartner SSE Magic Quadrant 2025
  3. 03Forrester SASE Wave 2025
  4. 04CVEdetails.com Vulnerability Statistics
  5. 05Skybox Security Vulnerability Trends Report 2024
  6. 06CISA Known Exploited Vulnerabilities Catalog
  7. 07Palo Alto Networks Unit 42 Threat Report 2025
  8. 08NIST Cybersecurity Framework 2.0
Start a Conversation Read More Articles