LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

Google's 2017 move away from perimeter security is a standard example of a top-management-driven architecture change. What happened, and why is it cited?

Google replaced its VPN-and-internal-network model with a zero-trust architecture (BeyondCorp) — a radical rebuild of its cyber security architecture that only happened because the top of the company pushed it.

The old model was the industry norm: applications lived on an internal corporate network, and being on that network — in an office or dialled in over VPN — was what earned you access. BeyondCorp inverted the assumption. Access decisions were moved to the individual request and made on the strength of who the user is and what state their device is in, with no trust granted by network location at all. Internal applications were published so that an employee in a café reached them exactly as they would from a desk, because neither location conferred anything.

Why the example keeps being used:

  • It is a paradigm change, not a product purchase. Every application's access path, the device fleet's management, the identity system and the network's role all had to change together. No department could have done it alone, and no security team could have imposed it on the business.
  • It shows the sponsor's function concretely. Multi-year programmes with no feature output survive only while someone with authority keeps defending the budget. Management as client is the difference between a rebuild and a pilot that quietly stops.
  • It set the vocabulary. "Zero trust" as a deployable architecture rather than a slogan dates from this and comparable work, and it is now the reference point for every discussion of what replaces the perimeter.

Tip: the transferable lesson is not "do what Google did" — it is that a change of paradigm has a prerequisite that is organisational, not technical.

Go deeper:

From Quiz: CSARCH / What Cyber Security Architecture Is, and Who It Is For | Updated: Sep 18, 2026