A comprehensive framework defining security controls, policies, and technologies that protect systems, infrastructure, user data, and digital assets through defence-in-depth strategies including authentication, encryption, access control, threat monitoring, and zero-trust principles.

Semantic Classification

Content

Security Layers

  • Network perimeter security
  • Identity and access management
  • Application security controls
  • Data protection and encryption
  • Endpoint security

Key Principles

  • Zero trust network architecture
  • Defence in depth strategy
  • Least privilege access
  • Security by design
  • Continuous monitoring

Current Landscape (2026)

  • In June 2026 CISA published “The Journey to Zero Trust: Using Secure Access Service Edge in a Modern TIC 3.0 Solution”, explicitly naming SASE as a compliant replacement for legacy TIC 2.0 gateways and MTIPS; the shift is from prescribing where controls live to prescribing what they must achieve, provided agencies feed equivalent telemetry to CISA’s Comprehensive Log Aggregation Warehouse (CLAW).
  • A notable architectural reversal: CISA now describes routine TLS/SSL break-and-inspect as “no longer a universally recommended solution”, pointing instead to AI/ML analysis of encrypted traffic — reshaping how enterprise reference architectures handle inspection and visibility.
  • Post-quantum cryptography moved from theory to mandated migration: after NIST finalised FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) in August 2024 and selected HQC as a backup KEM in 2025, crypto-agility and a Cryptographic Bill of Materials (CBOM) are now baseline architectural requirements, with CNSA 2.0 deadlines (2027 acquisition preference, full NSS enforcement by 2031) and NIST IR 8547 targeting removal of quantum-vulnerable algorithms by 2035.
  • The dominant design pattern of 2025–2026 is the “agentic SOC”: CrowdStrike’s September 2025 Fal.Con release reframed Falcon as an agentic security platform with mission-ready AI agents and no-code Charlotte AI AgentWorks, using the Model Context Protocol (MCP) as the governed connective tissue between first-party, customer-built and third-party agents.
  • Securing AI agents themselves has become a distinct architectural layer, as vendors acknowledge autonomous agents act as persistent, privileged actors with access to filesystems and credentials that traditional EDR/EPP models do not cover — driving acquisitions such as Palo Alto’s Protect AI (Prisma AIRS), Check Point’s Lakera and Palo Alto’s agentic-endpoint startup Koi.
  • Massive platformisation and consolidation is redrawing vendor architectures: Google’s 25bn CyberArk deal (closed 11 February 2026, unifying identity, network, cloud and SOC pillars) headline roughly $96bn of M&A across about 400 deals in 2025 — a c.270% year-on-year jump in deal value.
  • Open challenges as of 2026 include maintaining CISA/regulatory visibility without default TLS decryption, retrofitting crypto-agility into long-lived IoT/OT and PKI estates ahead of “Q-Day”, governing multi-agent and non-person-entity identities at machine speed, and the concentration risk of consolidating an entire security estate onto a single platform vendor.

References

Provenance