Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What are the signs that a legacy castle-and-moat…
Cyber Security

What are the signs that a legacy castle-and-moat model is failing?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Cyber Security

Common signs include growing dependence on remote access, inconsistent device trust, fragmented identity controls, and rising concern about lateral movement. If executives cannot explain who can access what, or if the organisation still assumes the internal network is safe by default, the old model is already misaligned with how work and attack paths now operate.

How the Castle-and-Moat Assumption Breaks Down

A legacy castle-and-moat model fails when trust is still granted because a user or device is “inside” the network rather than because access is continuously verified. That breaks first at the edges, where remote work, cloud services, contractors, third parties, and hybrid connectivity make the internal perimeter porous. The real signal is not one dramatic failure, but the growing gap between how access is granted and how work now happens.

Once that gap opens, the model starts to misdescribe the environment. A user may reach the network through one path and then move far beyond the intended scope through service accounts, API keys, OAuth tokens, certificates, and workload identities that were never designed around a perimeter. If the organisation still treats internal access as inherently trusted, it will miss the fact that access paths are now distributed, dynamic, and much harder to reason about from a flat network boundary.

The architecture also tends to fail quietly when the organisation cannot produce a clear picture of who or what can reach sensitive systems. That is not just a visibility issue, it is a control failure, because the castle-and-moat model depends on coarse trust decisions that stop being valid as identities, devices, and applications proliferate. NHIMG’s Ultimate Guide to NHIs is useful here because the same visibility, lifecycle, and privilege problems that affect machine access also expose why perimeter trust has become brittle. A supporting warning sign is the scale of unmanaged access material, for example NHIMG notes that 97% of NHIs carry excessive privileges, which shows how quickly broad trust becomes broad exposure.

Risk and Threat Considerations

The practical risk is that a breached user, device, or credential is no longer contained by a trusted internal zone. When lateral movement becomes easy, the old model converts a single access failure into a wider compromise, especially where flat networks, shared credentials, or weak segmentation still exist.

Failure mechanism: Once an attacker or compromised account gets an initial foothold, the perimeter no longer limits movement if internal systems are treated as trusted by default. That lets the compromise extend through reachable services, inherited permissions, and poorly separated administrative paths.

Impact: The likely outcome is broader system exposure, harder containment, and a much slower response because the organisation has to prove boundaries after the fact rather than enforce them up front.

What Practitioners Should Verify Before Trusting the Model

The most useful test is whether access decisions are still anchored to identity, device posture, and explicit authorization, rather than to network location. If “internal” remains the main trust signal, the model is already behind the threat and operating reality.

What to verify:

  • Can the business explain who can access which systems, from which device states, and under what conditions?
  • Are remote access paths treated as first-class production paths, not exceptions?
  • Are privileges and service credentials bounded tightly enough that a compromise does not spread laterally by default?
  • Do logs and access reviews reveal who actually used access, or only that the network was reachable?

Practitioner takeaway: The model is failing when trust is inferred from location instead of continuously justified by control, because that is when visibility, containment, and accountability all begin to drift apart.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identity and Credential ManagementCastle-and-moat failure is driven by weak identity-based access decisions.
PR.AC-4 — Access Permissions and AuthorizationsThe model fails when broad internal access and lateral reach are no longer constrained.
DE.CM-8 — Vulnerability and Exposure MonitoringMisaligned perimeter trust is often exposed through weak visibility into access paths and exposure.
Recommendation — Enforce identity-based access decisions instead of trusting network location. Restrict permissions so internal reach does not imply broad authority. Monitor access paths and exposure to detect when perimeter assumptions no longer hold.
NIST SP 800-63IAL — Identity Assurance LevelThe answer hinges on stronger verification than simple network presence or location trust.
Recommendation — Set identity assurance expectations that do not depend on network location.
NIST Zero Trust (SP 800-207)PL-1 — Zero Trust Architecture PlanningCastle-and-moat failure is the classic signal that a zero trust model is needed.
Recommendation — Plan for zero trust when internal network location is no longer a valid trust boundary.
CIS Controls v86.3 — Access Grants ManagementExcessive internal reach and unclear access ownership are central failure signs.
8.1 — Audit Log ManagementThe model's failure is often first visible in poor traceability of who accessed what.
Recommendation — Review and remove unnecessary access grants that persist under legacy trust assumptions. Centralise and review logs so access paths and misuse are visible.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementNon-human access material often expands beyond the moat and creates hidden reach paths.
NHI-03 — Authorization and PermissionsOverprivileged machine and service access amplifies lateral movement once perimeter trust fails.
NHI-07 — Visibility and DiscoveryA failing castle-and-moat model usually shows up as poor visibility into machine and service access.
Recommendation — Inventory and rotate non-human secrets that bypass perimeter assumptions. Reduce non-human privileges so compromised access cannot spread laterally. Discover and track non-human identities so hidden access paths are not missed.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org