Quiz Entry - updated: 2026.09.18
In what order did the cyber security eras arrive, and what should you take from the fact that none of them disappeared?
Security-by-obscurity → perimeter security → AAA/IAM and security-on-the-system → macro-perimeter → micro-perimeter and zero trust. None of them ended: they layer, and a real estate contains several at once.
* Every bar reaches today: the eras layer on top of each other instead of replacing one another. *
The sequence, with the pressure that forced each step:
| Era | Core idea | What broke it |
|---|---|---|
| Security by obscurity | Nobody knows about my system | Knowledge spreads; the first bad interactions |
| Perimeter security | Only allow safe networks | Forgeable addresses, malicious payload in allowed protocols |
| Enhanced perimeter | Inspect the content too (smart security tools) | Security becomes elaborate and costly |
| AAA security | Who may do what — authenticate the actor | Stolen and forged identities, hijacked sessions |
| Security on the system | Reduce the attack surface at the target | Not every system can carry the load (OT) |
| Macro-perimeter | Restore the border at scale — VPN, SASE | Lock-in; public services cannot take part |
| Micro-perimeter / zero trust | Many small borders; accept the outside | Complex and invasive |
Two things to take from the layering:
- It is additive, not a succession of replacements. Nobody removed the firewalls when IAM arrived. An estate therefore holds several eras side by side, each maintained to a different standard, and the oldest layers tend to be the least watched.
- Each era's weakness became the next era's purpose — which is why the eventual answer is combination. The list above is, read differently, a list of what each approach cannot do, and that is what a review should look for.
Tip: placing a system on this timeline is a fast diagnostic. Once you can say "this part of the estate is in the perimeter era", you know both what it assumes and which attacks it was never designed to see.
Go deeper:
Wikipedia — Defense in depth (computing) — the name for what the accumulated layers become when they are combined deliberately rather than by accident.