Cyber resilience of critical infrastructure requires rethinking traditional approaches. Updated CISA CPG 2025 recommendations shift the focus from network perimeter protection to data protection at the business logic level. According to the ENISA Threat Landscape 2025, 53.7% of critical infrastructure organizations (essential entities) were affected by cyberattacks between July 2024 and June 2025. These figures confirm that isolated network protection is no longer sufficient.
Why network segmentation fails to stop lateral movement
Technical teams often invest in formal network segmentation, yet attacker methods continue to evolve. As CERT-UA specialists note, the use of modified VPN clients allows bypassing standard security measures. Once inside the internal network (lateral movement), attackers often encounter a lack of additional application-level barriers. If access to HR or financial databases is based solely on network connectivity, compromising a user account grants access to all business objects.
CISA CPG 2025: from perimeter protection to business logic security
According to the Cisco Cybersecurity Readiness Index 2025, which surveyed 8,000 executives, cyber resilience requires integrating identity and access control directly into business processes. Modern standards, such as CISA CPG, emphasize the need to implement a "least privilege" model. This means that security must be embedded into the application's data model, turning the system into an environment where access to records is controlled by business authorization rather than network paths.
Isolating business processes: row-level security
Architectural segmentation is implemented through mechanisms like Row-Level Security (RLS). This allows restricting access to individual database table rows based on the user's context. Unlike standard RBAC, which manages access to entire modules, RLS reduces the "blast radius" to the level of a specific business object. If a user's request to the system exceeds their permissions, RLS automatically blocks access to the data, regardless of the request's origin.
Model-driven architecture as a security tool
Architectural segmentation is achieved through a model-driven architecture, where domain metadata describes not only the data structure but also access policies. The UnityBase platform, developed by the Intecracy Group alliance, allows implementing RBAC and RLS directly at the metadata level. This ensures automatic data isolation, preventing leaks if one of the application modules is compromised. To meet high security requirements in critical infrastructure, the platform's official documentation recommends using specialized Enterprise or Defence editions.
Levels of architectural resilience
| Level | Description | Security effect |
|---|---|---|
| 1 | Network segmentation (VLANs, Firewalls) | Basic perimeter, does not stop lateral movement. |
| 2 | Application RBAC | Access to functions, but module data is exposed. |
| 3 | Data-centric isolation (RLS) | Row-level control, risk minimization. |
| 4 | Model-driven security | Policy integration into the data model, automatic audit. |
Transitioning to the 3rd and 4th levels of resilience allows businesses to meet regulatory requirements, not just by declaring security, but by ensuring data protection at the level of every business object.
FAQ
How to implement Row-Level Security without rewriting code?
Use model-driven platforms (such as UnityBase), where access policies are described in domain metadata. This allows the system to automatically apply data access filters regardless of the module's business logic.
What is the difference between network segmentation and architectural segmentation?
Network segmentation isolates the network space at the packet level, while architectural segmentation controls access to specific business data (records) within the application, protecting them even if the network is compromised.
How to meet CISA CPG requirements without being limited to the network?
Implement data protection at the business logic level, use identity as the center of access control, and utilize an architecture where access to objects is determined by the data model rather than just network connection parameters.