LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

What is the closing verdict of the historical survey — is there a best cyber security architecture?

No. Reality needs a mixture of different architectures, and good cyber security architecture is achieved by clever combination.

The argument is made by analogy, and the analogy is exact: just as no single architectural design serves every type of building, no single security architecture serves every kind of cyber system. What follows is a matching rule rather than a ranking:

  • Older cyber architectures — as found in legacy systems, OT and on-premises estates — need a cyber security that fits them. Applying a modern identity-centric design to a controller that cannot authenticate produces an exception list, not security.
  • Cloud services, and public cloud especially, need a modern approach. Wrapping a perimeter around a service designed for many tenants produces either a broken service or a fictional boundary.

The two supporting statements are worth keeping together:

  1. The Basic Cyber Security Model helps with practical design and review — it gives you the same three questions for a new design and for an inherited one.
  2. Good cyber security architecture is reached by clever combining — the skill being assessed is not knowledge of the newest model, but judgement about which approach fits which part of the estate, and how the parts meet.

Tip: the trap this warns against is the single-paradigm rollout — "we are doing zero trust now" applied uniformly to an estate containing a 1990s plant controller. The result is a modern architecture with a large, permanent exception, which is worse than an honest hybrid.

Go deeper:

From Quiz: CSARCH / A Short History of Cyber Security Architecture | Updated: Sep 18, 2026