It’s hard for me to write a post that does not become an advertisement for Network Box. After all, I am one of the original founders of Network Box USA and I have been doing this for 23 years now. However, I will try.
The problem with perimeter protection, now as it was 23 years ago, is that we continue to think that we can install it and forget it, and that we can delegate the configuration to people who are not in the security industry, have no idea of the actual threats, and, to be blunt, often have no idea what they’re doing. Don’t shoot please – 23 years in cyber security, I have seen plenty of horror stories to back my statement.
I find that perimeter protection continues to suffer from 3 fundamental issues: 1) software that is not up to date; 2) signatures that are not up to snuff; and 3) improper configurations. There is a 4th one: weak devices. I will leave that for another time.
Let’s check the first: software that is not up to date. CVEs are a fact of life. We are humans; humans make mistakes. Yes, AI is changing this paradigm, but no one can foresee what will happen when all of us will be using Codex or other similar tools to write code. For now, most of it has been written by humans and many are still writing code and correcting it themselves.
So, what do we do about this? UPDATE! PATCH! And don’t wait. I cannot tell you how many times we scan networks and find devices that are missing patches that are 6 months old. I think it is obvious what that means, but I’ll make it clear: that is a window of 6 months that hackers have had to try and get through your firewall! Period. Seems obvious? But then, why do people not patch? Why do we find so many devices with old vulnerabilities that should have been patched months ago? What is so difficult about setting up a routine process that requires your devices to be up to date all the time. Stay informed and update.
Second: Signatures. OK, don’t shoot. I am using this as a loose term here, for lack of a better one. Call it protection, call it what you will. It’s that part of the software that allows our systems to identify a threat. These days it would even be an AI model that has been updated. The sooner you ensure your devices are up to date with the latest threat intelligence, the lower the probability of an attack.
It’s all about closing the window of opportunity. The best option is to subscribe to a threat intelligence service and ensure your devices have, as quickly as possible, the latest threat intelligence installed. Do not underestimate this. If an IP is known to be distributing ransomware, the sooner you block it, the sooner your users can’t get to it and harm themselves.
Third: Improper configuration. Here I risk getting a lot of flack and pushback. But I will say what I need to say anyway. We need to stop allowing anyone to configure security devices.
In 2026 we still see firewalls configured with “LAN to any allow all”. It’s been since 2004 that the FBI issued a memo stating “do not trust the LAN”. On which planet do these people live? The LAN is NOT a trusted environment.
The concept of Zero Trust is not new. The concept in modern days is attributed to John Kindervag who formalized it in 2010. But the idea was not new. First talks of trust go as far back as 1999. And yet, we still fight with this concept in so many ways. We see devices with 3389 open from the Internet. We see firewalls with practically no configuration. We see so many ‘horror stories’. Then the perimeter gets the blame and we all think we may just as well resign ourselves to the fact that threats cannot be stopped.
It is my strong opinion that before someone is allowed to touch the configuration of a firewall, they should have extensive cyber security training. And I do not mean a week to learn the language of a product. I mean training around the fundamentals; to be sure they fully understand the consequences of their actions.
To put this in spoken language terms, if you do not know what you want to say, knowing another language isn’t going to help you. But if you are deep into philosophy discussions, you will learn how to express that in any language you learn. If your brain knows what it wants to say, it’ll say it in any language it knows. But if you know many languages and have nothing to say, nothing will come out. Apply this to FW languages. It does not matter how many firewalls you can configure. If you do not understand the consequences of your configurations, you will make mistakes and cause serious security issues.
There is a lot more to say here, but I am going to stop here for now. Until next time.
Pierluigi Stella