They matter because users now connect from many locations and devices, while data lives across cloud apps, internet services, and private applications. A perimeter-only model cannot reliably see uploads, downloads, risky app use, or sensitive content movement. People-centric controls let security teams enforce access, inspect traffic, and apply DLP where the activity actually happens.
Why perimeter security breaks down in hybrid work
Perimeter-based security assumes users, devices, and applications live mostly inside a controllable network edge. Hybrid work dissolves that assumption. People sign in from homes, offices, airports, and partner networks, while work moves through SaaS platforms, browsers, collaboration tools, and private apps that are no longer behind one firewall.
That shift matters because the security question is no longer “Is the connection on the inside?” but “Who is accessing what, from where, under what conditions, and with what data movement?” A perimeter can still matter as one signal, but it is no longer the control point that consistently follows the user, the session, or the content.
The practical result is that perimeter-only models miss the places where risk now concentrates: browser sessions, unmanaged endpoints, shadow SaaS, and uploads or downloads that cross trust boundaries without ever touching a traditional internal choke point. IAM and IGA Basics is useful here because the access decision has become more important than network location.
What people-centric access control actually changes
People-centric access controls shift enforcement to the identity and the activity itself. Instead of trusting an internal IP range, they evaluate the person, device posture, application, and context at the moment of access. That is what allows teams to apply least privilege, step-up checks, and conditional access where the work happens, rather than where the network happens to terminate.
This is also where inspection and data protection become more effective. If the control follows the session, security teams can see risky application use, block high-risk transfers, and apply DLP to content moving through approved and unapproved paths. In hybrid environments, the control point is often the browser, identity plane, or cloud access layer, not the old network boundary.
For practitioners, the main architectural change is that access policy becomes dynamic and context-aware. It can distinguish a managed laptop in a corporate office from an unmanaged device at home, or a normal document edit from a bulk export of sensitive records. That is a materially better fit for hybrid work than a static network trust model. CIS Controls v8 aligns well with this access and account-management emphasis, while NIST SP 800-53 Rev 5 Security and Privacy Controls captures the access-control, authentication, and audit expectations behind it.
Why this approach fits hybrid work better than legacy perimeter thinking
Hybrid work changes the unit of protection from the office network to the person and their session. That is a better match for how work is done now: mobile, distributed, cloud-mediated, and often outside direct corporate network ownership. People-centric controls let security policy travel with the user, which means the same identity can be governed consistently across managed and remote environments.
It also improves resilience. When control depends on one edge appliance or one internal network, a user outside that boundary can become either over-trusted or awkwardly blocked. When control is tied to identity, device state, and content sensitivity, the organisation can keep access open for legitimate work while tightening the highest-risk actions. CSA Cloud Controls Matrix and ISO/IEC 27001:2022 Information Security Management both support this broader shift toward control over access, data handling, and cloud usage rather than network proximity alone.
That does not mean perimeter controls disappear. Firewalls, VPNs, and network segmentation still matter for some workloads and threat scenarios. The difference is that hybrid work makes them incomplete as the primary trust model. The stronger design is layered: identity-led access, device and session checks, and inspection where data actually moves, with network controls retained as one part of the overall posture.
Risk and Threat Considerations
The main risk in perimeter-only thinking is blind spots. If the user, device, and application no longer sit behind one controlled edge, attackers and careless insiders can move data through sanctioned cloud services, personal devices, or unmanaged browsers without tripping traditional boundary controls.
Failure mechanism: Access is granted because a connection appears to come from a “trusted” network, while the real decision points, identity, device state, and content flow, are not checked closely enough.
Impact: Sensitive data can be uploaded, copied, or exfiltrated from legitimate sessions, and security teams may discover the activity only after loss has already occurred.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication, and Access Control | Hybrid work requires identity-led access decisions instead of perimeter trust. |
| PR.DS-01 — Data-at-Rest is Protected | People-centric controls must protect data moving across cloud and endpoint boundaries. | |
| Recommendation — Enforce identity-based access decisions before granting hybrid sessions. Apply data protection controls to sensitive content regardless of network location. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Hybrid work depends on managing access by user, device, and context. |
| Recommendation — Restrict access paths using context-aware access control rules. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Hybrid access hinges on policy-driven access decisions across locations and devices. |
| Recommendation — Define and enforce access rules based on user and asset sensitivity. | ||
| OWASP ASVS | V8 — Authorization | Session and application authorization must replace assumptions about trusted networks. |
| Recommendation — Verify authorization decisions remain correct outside the corporate perimeter. | ||
Practitioner Guidance
What to prioritise: Treat identity, device posture, and application context as the primary control inputs for hybrid access. If a policy still depends mainly on “inside versus outside,” it is already lagging the operating model.
What to verify: Confirm that the control can inspect browser and cloud activity, not just network entry. A useful test is whether it can distinguish normal collaboration from sensitive-data movement and risky app use.
Practitioner takeaway: Hybrid work changes the defender’s unit of control from the perimeter to the person and session, so the best security model is the one that can follow access and data flow wherever work actually happens.
Related resources from NHI Mgmt Group
- What is the difference between a perimeter-based security model and access-centric cloud identity controls?
- How should security teams adapt access controls when remote work becomes a permanent operating model?
- What is the difference between role-based access and API key governance for NHI security?
- How should security teams modernize privileged access controls in hybrid environments without relying on vault-centric PAM alone?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org