Segmented moat
Separate users, workloads, crown-jewel systems, vendors, build pipelines, and recovery paths so one breach does not become full-domain movement.
Security architecture
Security architecture is easier to fund, operate, and test when teams can explain it clearly. Use the castle model for layered defense and the ship model for resilience under active attack.

Castle model

Separate users, workloads, crown-jewel systems, vendors, build pipelines, and recovery paths so one breach does not become full-domain movement.
Force every user, service account, workload, and AI agent through identity, device posture, least privilege, and just-in-time access.
Default-deny sensitive actions, require context, monitor policy decisions, and make exceptions visible.
Watch identity, endpoint, cloud, SaaS, code, network, model gateways, and agent tool calls from one evidence-driven view.
Protect critical data and production control planes with stronger authentication, encryption, logging, recovery tests, and executive ownership.
Ship model

Run detection, triage, escalation, containment, and communication from a command center that can act quickly without improvising.
Continuously discover assets, exposures, suspicious behavior, third-party drift, agent activity, and exploit signals.
Harden the outer operating surface with identity-aware access, encrypted channels, secure configuration, and policy enforcement.
Use containment boundaries so compromised credentials, hosts, tokens, or SaaS integrations cannot sink the whole organization.
Maintain tested backups, break-glass access, clean-room rebuild procedures, communication plans, and customer-safe restoration paths.
Checklist
Name the crown jewels: identity, source code, customer data, production cloud, signing keys, build systems, and financial operations.
Map trust paths between people, devices, SaaS apps, cloud accounts, CI/CD, vendors, AI agents, and model gateways.
Create segmentation boundaries that match business blast radius, not only network diagrams.
Treat AI agents as non-human identities with scoped tools, logs, approvals, and revocation.
Centralize telemetry across identity, endpoint, cloud, code, data, network, and AI tool activity.
Test recovery before the breach: backups, clean admin paths, alternate communications, and customer-facing service restoration.
Use tabletop exercises that include AI-assisted phishing, supply-chain compromise, token theft, rogue automation, and cloud control-plane abuse.