Skip to main content

Assume Breach

Design as if one identity, credential, workload, route, or control will fail, then limit movement and impact.

Protection objective

Assume breach means designing the system so that one compromised identity, device, workload, credential, route, policy component, or network segment does not grant uncontrolled access to the rest of the environment. It is a design principle and threat-model assumption. It is not a claim that every component is already compromised.

The protected objective is bounded consequence. A failure must remain within named resources, actions, identities, time, and recovery limits.

Security principle

Treat each trust decision as local and limited. Authenticate and authorize access to a named resource. Apply least privilege. Separate high-impact duties. Segment independent failure domains. Protect control-plane changes. Limit credential audience and lifetime. Preserve evidence outside the component that can fail.

Ask what an attacker can do after the control succeeds for them. Strong authentication limits account takeover. It does not limit the authority of a correctly authenticated compromised account. A gateway protects traffic that uses it. It does not stop a direct origin or stolen downstream credential.

Enforcement mechanism

  1. Select one credible initial compromise.
  2. Trace reachable identities, credentials, network paths, resources, actions, control planes, evidence, and recovery systems.
  3. Place independent boundaries that limit movement or effect.
  4. Remove shared authority and broad ambient reachability.
  5. Detect the compromise or abnormal use through independent signals.
  6. Revoke and isolate the affected authority without depending on it.
  7. Restore known-good service and prove old authority fails.

Use measured blast radius and revocation latency. A diagram alone does not show whether a stolen session remains valid or a direct endpoint still accepts requests.

Failure and residual risk

Assumed breach can become an excuse to accept weak preventive controls. It can also become an impossible demand that every component distrust every other component. Define specific failure assumptions and impact bounds.

Shared identity providers, signing keys, policy engines, administrators, networks, or recovery paths can join several boundaries into one failure domain. Residual risk includes simultaneous compromise, hidden dependencies, valid low-volume abuse, and destructive actions that cannot be reversed.

Pomerium boundary

Pomerium can place identity-aware policy on named routes and reduce broad network access. Operators must still isolate upstream services, limit application permissions, protect identity and control planes, manage credentials, and provide independent detection and recovery. Pomerium cannot bound effects on paths or application actions that it does not mediate.

Evaluation checklist

  • Which single identity, credential, workload, route, or control failure does the design assume?
  • Which resources and actions become reachable after that failure?
  • Which independent boundaries limit movement, duration, and impact?
  • Can detection, containment, and recovery operate without trusting the compromised component?
  • Do tests prove old authority and direct paths fail after containment?

Sources and further reading

Keep learning

Security Engineering FoundationsSecurity Operations and Risk

Defense in Depth

Place complementary controls across distinct failure domains so one failure does not expose the protected asset.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo