Quiz Entry - updated: 2026.09.28
Why is the assumption behind security-by-isolation unrealistic for most systems today?
Because a system needs interaction to do its job, modern software is not designed for isolated operation, isolated systems are hard to operate (monitoring, updates, patches, backup…), and the business demands remote access and ever more digital interaction.
The concept assumes that every interaction can be prevented. That fails because:
- The cyber system fulfils a task and needs interaction for it.
- Modern IT software is generally not designed to run isolated.
- Operating an isolated system is hard. For monitoring, alerting, user management, name resolution, time sync, updates, patches, backup and recovery you must either build a local solution, break the isolation in a controlled way, or do without the function. Doing without is highly critical for security patches.
- Business requirements: remote maintenance access saves costs, and progressing digitalisation in all business areas demands more digital interaction.