Blog

What does Salt Typhoon tell us about the limits of perimeter-based security?

Salt Typhoon tells us that perimeter-based security fails the moment a trusted device or credential is compromised inside the boundary. The attackers did not blast through a firewall. They moved laterally through networks that had already let them in, exploiting the core assumption that anything inside the perimeter is safe. The questions below unpack exactly how that happened and what it means for organizations still relying on perimeter-first architecture.

How did Salt Typhoon move through hardened networks undetected?

Salt Typhoon gained access through legitimate entry points, then moved laterally across telecom and critical infrastructure networks by exploiting trusted relationships between systems. Because the traffic looked like normal administrative activity, existing monitoring tools did not flag it. The attackers spent months inside networks before detection, harvesting communications data at scale.

The key to their persistence was not a single spectacular exploit. It was patience combined with a structural weakness: once inside, there was very little to stop east-west movement. Routers, switches, and management interfaces that were never designed with internal threat models in mind became stepping stones. Credentials captured from one system unlocked the next. The perimeter held. Everything behind it did not.

This is not a story about a zero-day vulnerability or a nation-state with magic capabilities. It is a story about what happens when your security model assumes the threat is always outside.

What does ‘perimeter-based security’ actually assume about threats?

Perimeter-based security assumes that threats originate outside a defined boundary and that anything inside that boundary can be trusted. The model works by hardening the edge, typically with firewalls, intrusion detection systems, and access controls at network ingress points, while treating internal traffic as inherently safe.

That assumption made sense in an era when all your assets sat in one building and your employees worked from one location. It does not hold when your network spans cloud environments, remote workers, branch offices, and third-party vendors. Every one of those connections is a potential entry point. And once an attacker gets through any of them, the interior of a perimeter-based network is often wide open.

The deeper problem is implicit trust. Perimeter security grants access based on location, not identity or behavior. If you are inside the network, you are trusted. Salt Typhoon did not break that model. It used it exactly as designed.

Why are telecom and critical infrastructure especially exposed?

Telecom carriers and critical infrastructure operators are especially exposed because they run large, interconnected networks built on legacy equipment that was designed for availability and reliability, not security. Many of these systems carry significant technical debt in defense networks and industrial environments, meaning security controls were bolted on later rather than built in from the start.

The attack surface is enormous. Telecom networks connect millions of endpoints, route traffic for other organizations, and maintain peering relationships with carriers around the world. A compromise in one part of that ecosystem can propagate quickly. The same is true for power grids, water systems, and transportation networks, where operational technology (OT) and information technology (IT) increasingly share the same infrastructure.

There is also a regulatory and operational tension at play. Patching a core router in a live telecom network is not like patching a laptop. Downtime has real consequences. So systems run longer than they should on outdated software, and the technical debt compounds. Salt Typhoon exploited exactly this gap between what organizations know they should do and what they can operationally execute.

What’s the difference between perimeter security and zero trust?

Perimeter security grants access based on network location. Zero trust (ZT) grants access based on verified identity, device health, and context, regardless of where the request originates. The core difference is that zero trust eliminates implicit trust entirely. Every connection must be authenticated and authorized, every time.

In a perimeter model, getting past the firewall means you are in. In a zero trust model, getting past the firewall means nothing. You still need to prove who you are, what device you are using, and whether you are authorized to access the specific resource you are requesting. Lateral movement becomes dramatically harder because there is no “inside” to move through freely.

Zero trust is not a single product. It is an architectural principle. Implementing it typically involves microsegmentation (dividing the network into small, isolated zones), strong identity verification, least-privilege access controls, and continuous monitoring of all traffic, not just traffic at the edge. Software-defined networking (SDN) approaches, which build programmable, policy-driven networks in software rather than hardware, are a practical way to enforce zero trust principles at scale without ripping out existing infrastructure.

Which network controls would have limited Salt Typhoon’s reach?

Microsegmentation, encrypted overlay networks, and strict least-privilege access controls would have significantly limited Salt Typhoon’s lateral movement. If internal network segments cannot communicate freely with each other, a compromised device in one zone cannot reach systems in another without explicit authorization.

Specifically, several controls stand out:

  • Microsegmentation: Isolating workloads and systems so that lateral movement requires explicit policy approval, not just a valid credential.
  • Encrypted east-west traffic: Encrypting traffic between internal systems so that even a device on the same network cannot read communications it was not meant to receive.
  • Identity-based access: Requiring cryptographic identity verification for every connection, not just at the perimeter.
  • Continuous monitoring: Watching internal traffic for anomalous behavior, not just inbound traffic at the edge.
  • Network visibility: Maintaining a real-time map of what is connected and what is communicating with what, so unusual patterns surface quickly.

None of these controls would have made the initial intrusion impossible. But they would have contained the blast radius. The months-long dwell time Salt Typhoon achieved depended on the absence of these controls inside the network.

Should organizations replace perimeter tools or layer on top of them?

Organizations should layer zero trust controls on top of existing perimeter tools, not rip and replace them. Firewalls and perimeter controls still serve a purpose. They reduce noise and filter out opportunistic attacks. The problem is treating them as the primary or only line of defense.

A practical approach is to add an encrypted overlay network (a private, policy-controlled network built on top of existing infrastructure) that enforces identity-based access and microsegmentation without requiring hardware changes. This lets organizations modernize their security posture incrementally, without the operational risk of replacing core infrastructure all at once.

For defense industrial base (DIB) organizations and critical infrastructure operators, the urgency is higher. Compliance frameworks like CMMC (Cybersecurity Maturity Model Certification) and NIST SP 800-207 are pushing toward zero trust architectures explicitly. And with post-quantum cryptography (PQC) standards now finalized by the National Institute of Standards and Technology (NIST), organizations that have not started planning for quantum-resistant encryption are already behind.

The honest answer is that most organizations cannot afford a full infrastructure replacement. But they can afford to stop trusting the interior of their networks by default. That shift in posture, more than any single product, is what Salt Typhoon exposed as missing.

How ZeroTier helps limit lateral movement and enforce zero trust

ZeroTier is an encrypted overlay networking platform that enforces identity-based access and microsegmentation across any environment, without requiring new hardware or complex reconfiguration. For organizations responding to the lessons of Salt Typhoon, it addresses the structural gaps that made lateral movement so easy.

  • Encrypted east-west traffic: Every connection on a ZeroTier network is cryptographically authenticated and encrypted end-to-end, including internal traffic.
  • Microsegmentation by policy: Network segments are defined in software, so you control exactly which devices can communicate with which, and under what conditions.
  • No implicit trust: Devices must be explicitly authorized to join a network. Being on the same physical infrastructure grants nothing.
  • Post-quantum readiness: ZeroTier Quantum, ZeroTier’s next-generation platform, embeds hybrid post-quantum cryptography directly into the transport layer using the ZeroTier Transport Protocol (ZTP), meeting NIST and NSA CNSA 2.0 standards. For defense contractor network security and defense industrial base organizations, this addresses both current and emerging cryptographic threats.
  • Flexible deployment: ZeroTier can run as a cloud service, in a sovereign-gapped environment, or fully air-gapped, making it practical for regulated industries and government networks carrying sensitive workloads.

Salt Typhoon is a clear signal that the interior of your network needs the same scrutiny as the perimeter. If you are ready to close that gap, explore ZeroTier’s platform and see how fast you can get encrypted, policy-controlled connectivity running across your environment.

Related Articles

Sign up for our newsletter

Don’t miss an update. Sign up to receive occasional networking content and news.

By providing your email address, you agree to receive marketing communications from ZeroTier. We’ll make sure it’s awesome!

Our Privacy Policy has more information on how we use your personal information. You can unsubscribe from our communications at any time. Your communications, your choice.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.