Technology Changes, Principles Do Not

While technologies evolve rapidly, the principles that determine whether systems are resilient remain remarkably stable. Least privilege, defence in depth, simplicity, and visibility continue to shape outcomes regardless of platform or era. This article explains why these principles endure, how ignoring them leads to recurring failures, and why historical security lessons remain relevant long after specific technologies become obsolete. A focus on principles produces systems that are easier to manage and harder to compromise.

Technology changes constantly. Platforms rise and fall, interfaces evolve and new threats emerge. It is tempting to assume that security must be reinvented each time. Experience suggests otherwise.

The same underlying principles recur because they address fundamental properties of complex systems. You might need to tweak the odd approach, but we don’t call them “principles” for nothing.

Least privilege limits the damage caused by compromise. Defence in depth acknowledges that no single control is sufficient. Simplicity reduces the likelihood of hidden interactions and unexpected behaviour. Visibility ensures that failures are noticed before they escalate.

Back to ‘basics’

Cyber hygiene is important, but considered to be boring. In fact it’s not boring, if you are protecting a valuable organisation. And it’s not even as basic as many assume. Getting the ‘basics’ right can be hard work in a complex environment, running multiple operating systems in different locations, possibly with varied levels of internet access.

Achieving best practices is also non-trivial when you lack the resources. This could be expertise, money or even access. Smaller organisations are unable to buy many security products because of the cost, and also because many security vendors only want to sell to very large customers. As such, cyber security ‘poverty’ reduces security for small and medium enterprises and, through the supply chain, reduces the security of their larger clients.

Consequences

When these principles are ignored, the resulting failures are familiar. Excessive access enables lateral movement. Single points of failure lead to cascading outages. Overly complex systems become opaque to those responsible for them.

Historical incidents remain instructive because they illustrate these dynamics, even when the specific technologies involved are outdated. The details change, but the patterns persist.

Focusing on principles also reduces dependence on novelty. New tools can be evaluated based on how well they support established ideas rather than how innovative they appear.

A security posture grounded in principles tends to age better. It adapts to change because it is not tied to specific implementations.

Technology changes, fundamentals remain

In the long term, resilience is built less through constant reinvention and more through consistent application of ideas that are already well understood. Technology changes but the fundamentals do not.