Why Firewalls Don't Stop Modern Attacks
Your firewall is blind to breaches that start with legitimate credentials. Here's why the perimeter defense model is broken.
The Problem: You're Defending Yesterday's Threat
Your organization is still purchasing firewalls first, implementing firewalls first, and treating them as the foundational layer of security. Enterprise IT still talks about firewall upgrades the way boards talk about succession planning. Non-negotiable. Critical. Essential.
Here's the uncomfortable truth: your firewall is not stopping the breach that will hurt you.
It's not because firewalls are poorly designed. They're not. Firewalls are extremely good at exactly one thing: stopping unauthorized traffic from entering your perimeter. They've been extremely good at this for twenty years.
The problem is that the threat moved.
When Firewalls Actually Worked (And Why They Don't Anymore)
Two decades ago, firewall architecture made perfect sense. Every system that mattered lived inside your network. Everything dangerous was outside. An attacker's only path forward was to crack the perimeter: port scans, exploit kits, buffer overflows, worm propagation. Breaking through the firewall meant breaking into the network.
The model worked because it was accurate. Threats were external. Firewalls were the moat.
Then everything changed:
- Vendors live outside your perimeter but inside your systems. Your integrations, APIs, and SaaS applications run on other companies' infrastructure.
- Contractors and third-party staff access your data from anywhere. Not from your office. Not from your VPN. From Manila, Mumbai, Eastern Europe, wherever their employer is based.
- Employees use personal devices. Your employees work from home on networks you don't control, accessing production systems from outside your castle walls.
- Ex-employees sometimes still have active credentials months after leaving, usually by accident.
Your perimeter no longer contains everything that matters. And worse: attackers no longer need to breach the perimeter at all.
The 2025 Qantas Breach: Legitimate Access, Wrong Hands
In 2025, Qantas Airways suffered a significant data breach. The attack path tells you everything you need to know about modern threat models:
Day 1–180: A call center employee in Manila logs into Qantas systems every day. Windows device. Company-issued. 9 AM to 5 PM Philippine time. The firewall sees exactly what it should see: routine, predictable, authorized traffic from a known location doing a known job.
Day 181: That employee's credentials were compromised. An attacker now has their username and password.
Day 182: The attacker logs in at 11 PM from a Linux device in Russia using the stolen credentials. Same authorization level. Same account. Everything else is different: time of day, device type, geolocation, access pattern.
The firewall stopped nothing.
Not because the firewall failed. Because the traffic was legitimate on paper. The employee was authorized to have that access. The account was authorized to make that request. The session was coming from someone with the right credentials.
Your firewall can't stop what it's designed to allow.
Why The Perimeter Model Broke
The firewall's entire value proposition rested on two assumptions:
- Everything that matters stays inside your perimeter.
- If someone is inside, they're either an authorized employee or they're doing something obviously malicious.
Neither assumption is true anymore.
When your perimeter included everything, a firewall was sufficient. When your perimeter now extends across dozens of vendors, contractors, SaaS platforms, and cloud integrations, when "inside" and "outside" no longer mean anything, the perimeter itself becomes the weakest link.
An attacker with legitimate credentials doesn't behave like an attacker in ways a firewall can detect. They behave like an employee. Or a contractor. Or a third-party vendor. They use the access they were given. They perform the job they're supposed to perform.
The firewall sees normal traffic from a normal user accessing normal data.
Cognitive Lag: Why We Still Act Like It's 2005
Firewalls still dominate security budgets. They still dominate compliance frameworks. Your board still asks about perimeter defense like it's the primary attack surface.
This isn't stupidity. This is institutional momentum. Firewalls were the foundation for so long that they became the foundation in how we think about security. Vendors sell them that way. Compliance frameworks emphasize them. Your IT team was trained on them. The muscle memory is deep.
But muscle memory isn't strategy.
We're defending against outsiders trying to break in, which firewalls stop extremely well. For the last decade, the real attack has been coming from people who already look like they belong, because they have legitimate credentials.
What Actually Stops Modern Breaches
The modern attack path doesn't require cracking the perimeter:
- Buy a credential (from a breach, phishing, or social engineering).
- Get access granted through normal business processes (no perimeter attack needed).
- Wait for the noise to die down (blend in with legitimate traffic).
- Use the access you've been given (in ways that matter to your environment).
This is why firewalls are blind to it.
A call center employee downloading the entire customer database at 2 AM instead of pulling records for individual cases. A contractor accessing systems they were never supposed to touch. A vendor's API integration running queries it's never run before. A SaaS account that an employee abandoned when they switched teams but never revoked.
All legitimate. All authorized. All invisible to a firewall.
The only signal that matters is behavior. Does this identity's access pattern match what this identity normally does?
That's identity and access behavior monitoring. Not perimeter defense. Not firewall rules. Understanding the baseline of every single identity in your environment—human, vendor, contractor, non-human service account, everyone—and detecting the moment legitimate access starts behaving illegitimately.
This is the actual first line of defense.
Three Practical Truths for Your Security Program
Firewalls still matter. They stop some attacks. They prevent certain classes of threats. They're part of defense-in-depth. But they're not the top priority anymore.
The threat is inside your authorization model. Your risk now lives in shadow access: who has credentials they shouldn't have, who has access they've outgrown, which vendors still have production permissions from five years ago.
Behavioral visibility is non-negotiable. You need to know what normal looks like for every identity. You need more context in your security. The moment normal changes—the moment a contractor accesses data they've never touched, or a vendor integration queries a database it's never queried—that's your signal.
If you haven't mapped your third-party access landscape, start there. You probably have dozens of vendors, contractors, and non-human accounts you can't account for. That's where the breach is hiding.
The Path Forward
Your firewall is still there. It's just no longer where the threat is.
The shift from perimeter defense to identity and behavior defense isn't controversial anymore. Every major breach this year followed the same pattern: legitimate credentials, legitimate access, illegitimate behavior. We've documented every major third-party breach this year. They're all the same story.
The firewall let the traffic through because it was supposed to. That's not a firewall failure. That's a fundamental change in where you need to focus.
Want to see which third-party identities in your environment pose the highest risk? Start with our External Access Report. It'll show you the vendor and contractor access you're probably blind to.