Perimeter Security is Dead, Long Live Resilience
As information and network systems become ubiquitous worldwide, the attack surface is growing increasingly complex, rendering traditional perimeter defense mechanisms ineffective against modern threats. We continue to see an influx of system vulnerabilities and APT attacks, which are nearly impossible to completely eliminate. Meanwhile, the continued proliferation of ransomware groups poses a direct threat to the continuous operations of businesses and organizations, severely impacting critical infrastructure such as healthcare, transportation, energy, and telecommunications. Since it is impossible to achieve 100% protection against all attacks, the key challenge in cybersecurity today is ensuring that systems can adapt to emerging cyber threats, maintain operations and withstand cyber threats, and recover quickly after an incident. This is the core principle of Cyber Resilience.
Since HITCON 2018: "Transforming: Cybersecurity and Resilience", resilience has once again taken center stage. In recent years, events such as the Russia-Ukraine war and the sabotage of undersea cables have underscored the importance of communication security, in addition to traditional cybersecurity. Critical infrastructure, such as undersea cables and low-earth orbit (LEO) satellites, introduces new challenges and discussions in the realm of resilience.
Furthermore, this theme aligns with the Cyber Resilience Act introduced by the European Union. For Taiwan, a major producer of consumer electronics, integrating the Secure-by-Default concept into product development—embedding security into design rather than relying on post-facto mitigation—will be a critical issue worthy of further exploration.