Defensible Security Architecture for the AI Era: Inside Our SANS SEC530 Training

Most small and mid-sized businesses already own capable security technology: a next-generation firewall, Microsoft 365 with Entra ID, endpoint protection, maybe a SIEM. What's often missing isn't another product. It's an architecture that makes those tools work together to prevent, detect and respond to attacks.

That's the focus of SANS SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise, which our team is completing now. The course has been updated for the AI era, covering both AI-enabled attackers and AI-assisted defense.

What "defensible" means

A defensible architecture assumes that some attacks will get through. Instead of relying on a single wall, it layers controls so that:

  • Prevention stops most attacks outright.
  • Detection quickly surfaces the ones that don't get stopped.
  • Response can contain an attacker before they reach what matters.

Each layer, from network and endpoint to identity, application, data and cloud, contributes to all three.

Zero Trust, without the buzzword

Zero Trust is often sold as a product. In practice it's a set of principles:

  • Never trust by location. Being "on the office network" shouldn't grant access to everything.
  • Verify every request. Access decisions consider who the user is, the health of their device, and the context of the request.
  • Grant least privilege. People and systems get only the access they need, only for as long as they need it.
  • Assume breach. Design so that one compromised account or device can't take down the whole business.

Key lessons we're applying

Get more from what you already own. Firewalls, switches, identity platforms and cloud controls often have strong security features that are switched off or poorly configured. Tuning existing investments is usually faster and cheaper than buying new tools.

Identity is the new perimeter. Attackers increasingly go after accounts rather than networks, through stolen credentials, MFA fatigue attacks (repeated push prompts until someone approves) and OAuth consent abuse. Phishing-resistant MFA and well-designed Conditional Access policies in Microsoft Entra ID are some of the highest-value controls available.

Segmentation limits the blast radius. Separating user devices, servers, medical equipment, point-of-sale systems, job-site networks and guest Wi-Fi means a compromise in one area doesn't spread to the rest.

Visibility has to be designed in. Encrypted traffic, cloud services and remote users create blind spots. A defensible architecture decides up front which signals are collected, where they go, and how they trigger action.

Protect the data itself. Knowing where sensitive data lives and controlling access to it directly holds up even when the network perimeter doesn't.

Prepare for AI on both sides. Attackers are using AI to scale phishing and reconnaissance, and businesses are connecting AI to their workflows. Both need to be part of the architecture, with AI integrations held to the same least-privilege rules as any other system.

How Dominant-IT applies this for clients

  • Architecture reviews. We assess your network, identity, endpoint and cloud setup against defensible architecture and Zero Trust principles, and identify the gaps.
  • A prioritized roadmap. Recommendations are ranked by business impact, attacker behavior and cost, so you fix what matters most first.
  • Identity hardening. Phishing-resistant MFA, Conditional Access, privileged account protection and cleanup of stale accounts and risky app permissions.
  • Practical segmentation. Network designs that isolate critical systems, including medical devices in healthcare and payment systems in PCI DSS environments.
  • Detection that leads to action. Security signals feed our 24/7 monitoring and managed SOC, so alerts turn into response.
  • Alignment with your frameworks. Architecture decisions mapped to the requirements you answer to, including HIPAA, PCI DSS, SOC 2 readiness and NIST 800-53.

Where to start

  1. List your internet-facing systems and remote access methods. Each one is a door.
  2. Review who has administrator rights, and remove any that aren't needed.
  3. Require MFA everywhere, and move to phishing-resistant methods for administrators.
  4. Separate guest Wi-Fi and specialized devices from the systems that run your business.
  5. Check whether your firewall and identity platform send logs anywhere someone actually reviews.

If you'd like an honest assessment of how defensible your environment is today, schedule a consultation. We'll show you where you stand and what we'd fix first.

All articles

Talk with us about your environment

Tell us what you're running and what worries you. We'll give you a straight assessment of where you stand and what we'd do first.