
Cybersecurity in focus: Why identity is the new perimeter
August 11, 2026
By: Channel Eye
As cyber threats evolve, organisations are having to rethink where their greatest vulnerabilities lie.
In discussion with Channel Eye, Jersey-based James Gillies, Head of Cyber Security at Logicalis UKI, and Terry Walters, Head of Digital Services at Highlands College, discuss why identity and access have become central to cybersecurity, and how modern infrastructure can improve visibility, control and resilience.
1. Cybersecurity discussions often focus on external threats, but why are identity and access now becoming the biggest concern for organisations?
James Gillies explained: “When we talk about external threats, we’re typically referring to traditional perimeter-based security, where everything inside the corporate firewall was considered trusted. That model no longer reflects how organisations operate.
“Today, the new perimeter is identity, whether human or machine, that enables access to data and systems. As organisations have embraced cloud services, hybrid working and SaaS applications, security has shifted towards Zero Trust principles: verify explicitly, grant least-privilege access and always assume breach.
“Attackers have adapted accordingly. Rather than trying to break through perimeter defences, they increasingly target identities through phishing, social engineering and stolen credentials. In many cases, they’re no longer hacking in; they’re simply logging in using legitimate credentials. That’s why protecting identity and access has become one of the most critical priorities for organisations today.
Terry added: “User accounts are now considered the primary route to accessing an organisation’s data. Attacks on a network increasingly appear in the guise of a legitimate user account, which is why we have strengthened account security through multi-factor authentication (MFA) and access policies to ensure valid credentials are being used by the correct individual.”
2. Highlands College was dealing with ageing infrastructure and recurring network disruptions. At what point did it become clear that modernisation was also a security issue, not just an operational one?
Terry explained: “As technology changes, the necessary actions change to reflect emerging concerns. This is simply part of operating in an environment that evolves so quickly. It requires a continual process of reviewing existing systems, ensuring they remain fit for purpose and continue to provide the appropriate level of service and security.”
James added: “Modernisation and cybersecurity are now intrinsically linked. Legacy infrastructure often lacks the visibility, identity controls and integration capabilities needed to defend against modern cyber threats. As organisations refresh their infrastructure to improve reliability and performance, they quickly discover those same investments also strengthen their security posture. Better visibility, centralised identity management and more intelligent monitoring enable faster detection, response and resilience.”

3. Education environments are particularly complex, with thousands of users, personal devices and changing access requirements. What unique cybersecurity challenges does that create?
Terry said: “Due to the differing skill levels across staff, students, guests, visitors, contractors and event attendees, applying appropriate security controls can be extremely challenging. Courses start and finish throughout the year, accounts must be automatically disabled when required, and digital examinations add another layer of complexity because of the unique requirements of awarding bodies and individual access arrangements.”
James added: “Education magnifies the balance between usability and security because staff, students, contractors and visitors all require different levels of access from different devices and locations. Zero Trust approaches help strike the right balance by validating who is connecting, assessing the security of their device and granting only the access required while continuously monitoring activity for signs of compromise.”
4. The phrase ‘identity is the new perimeter’ is increasingly common in cybersecurity. What does that actually mean in practice for organisations trying to protect users and systems?
James explained: “It means moving security away from the network boundary and making identity the primary control point. Identity and Access Management, Privileged Access Management, conditional access, passkeys and least-privilege principles ensure users receive only the access they need, from the right device, for the right amount of time. If an account is compromised, access can be revoked centrally across connected systems.”
Terry said: “Heightened precautions are taken to ensure access requests are verified based on who, what and where, while policies determine what happens if certain thresholds are not met. Managed devices and a cohesive ecosystem help ensure stringent security controls are applied at every level.”
5. Highlands College mentioned that limited visibility made troubleshooting and issue resolution difficult. How important is visibility when it comes to identifying both operational and security risks?
Terry explained: “Given the number of accounts, devices and entry points, it is imperative that irregularities are identified as quickly as possible. Behavioural analytics and improved visibility now allow us to identify issues in real time and respond much faster than we could previously.”
James said: “Visibility is everything. If you can’t see it, you can’t protect it. Whether investigating user activity, vulnerabilities or security incidents, visibility underpins effective detection, response and risk management. Threat actors understand this too, which is why reconnaissance is always one of the first stages of an attack.”
Tomorrow on Channel Eye, James Gillies and Terry Walters look at why more cybersecurity tools do not always mean better protection, and how organisations can build resilience as AI-driven threats grow.
Source:
https://channeleye.media/cybersecurity-in-focus-why-identity-is-the-new-perimeter/
