The Enemy Does Not Need to Break In
4148
wp-singular,research_publication-template-default,single,single-research_publication,postid-4148,wp-theme-bridge,wp-child-theme-bridge-child,bridge-core-3.3.3,qode-optimizer-1.2.2,qode-page-transition-enabled,ajax_fade,page_not_loaded,,qode_enable_button_white_space,qode-smooth-scroll-enabled,qode-child-theme-ver-1.0.0,qode-theme-ver-30.8.5,qode-theme-bridge,disabled_footer_bottom,qode_advanced_footer_responsive_1024,wpb-js-composer js-comp-ver-8.1,vc_responsive

The Enemy Does Not Need to Break In

The Enemy Does Not Need to Break In

How Digital Dependence Is Reshaping Modern Security

The traditional image of an attack often begins with an intruder forcing his way through a locked door. In the digital age, that assumption is increasingly outdated. The most consequential threats may not require an attacker to physically penetrate a facility, defeat a security perimeter, or even compromise a system directly.

The enemy may already be operating through the systems, services, suppliers, applications, and information environments on which modern institutions depend.

Governments, businesses, financial institutions, research organizations, and critical infrastructure providers have become deeply interconnected. This connectivity has created enormous efficiencies, but it has also expanded the number of pathways through which disruption, manipulation, and strategic influence can occur.

The central security challenge is therefore no longer simply protecting the perimeter. It is understanding where dependence exists, who controls it, and what happens when that dependence is disrupted or manipulated.

The Changing Meaning of the Perimeter

For decades, cybersecurity strategies were largely organized around the idea of a protected network. Organizations established firewalls, authentication systems, physical security controls, and other defensive measures to prevent unauthorized access.

Those protections remain important, but the environment surrounding them has changed.

Organizations increasingly rely on cloud platforms, third-party software, telecommunications providers, external data services, payment networks, logistics companies, contractors, and interconnected infrastructure. Employees also access organizational resources from multiple locations and devices.

As a result, the boundary of an organization is no longer clearly defined.

A system can remain technically uncompromised while the organization itself becomes vulnerable through another dependency.

For example, an institution may maintain strong internal security while depending on an external provider for communications, data storage, software updates, authentication, or essential operational services. A disruption involving that provider can affect the institution without an attacker ever needing to enter its internal network.

This creates a different kind of security problem: indirect exposure.

The Supply Chain as a Strategic Target

Modern supply chains illustrate this problem particularly clearly.

Software and hardware used by organizations frequently pass through multiple suppliers and service providers. A single technology product may incorporate components, libraries, infrastructure, or services developed by numerous organizations.

This interconnected structure creates efficiency, but it also creates concentration risk.

A weakness in one important supplier can affect hundreds or thousands of downstream organizations. In a strategically important sector, the consequences can extend beyond individual companies and affect national resilience.

The issue is not necessarily that every supplier represents a malicious threat. Rather, organizations often have limited visibility into the full network of dependencies supporting their operations.

Security therefore requires more than asking:

“Is our system secure?”

It also requires asking:

“What systems do we depend on, and how secure are they?”

Information Can Be a Weapon

Another important dimension is information.

Modern organizations depend on accurate information to make decisions. Financial markets require reliable data. Governments depend on intelligence and communications. Businesses rely on information about customers, suppliers, competitors, and markets.

Manipulating information can therefore be as consequential as stealing it.

An adversary does not always need to destroy a database. In some circumstances, introducing uncertainty, altering selected information, or creating conflicting signals may be enough to undermine confidence.

The objective can shift from access to influence.

This is particularly significant during periods of crisis. When decision-makers must act quickly, uncertainty can become a strategic vulnerability.

False information, manipulated communications, compromised accounts, or deliberately misleading digital activity can create confusion without producing an obvious technical breach.

Dependence Creates Vulnerability

Technology has also created forms of dependence that are difficult to see during normal operations.

Organizations may depend on:

  • Cloud computing infrastructure
  • Internet and telecommunications providers
  • Payment systems
  • Geographic information services
  • Software platforms
  • Data centers
  • Energy networks
  • Global logistics systems
  • External authentication services
  • Specialized technology suppliers

Under normal conditions, these dependencies provide efficiency and scale.

During a disruption, however, they can become points of vulnerability.

The question is not simply whether a system can be attacked. It is whether an organization can continue operating when one of its essential dependencies becomes unavailable.

That distinction is increasingly important for national and organizational resilience.

The Human Dimension

Technology does not eliminate the human element of security.

Employees, contractors, administrators, researchers, and executives remain central to organizational systems. Social engineering, credential theft, impersonation, and manipulation can exploit human trust rather than technical weaknesses.

An attacker may not need to defeat sophisticated encryption if legitimate credentials can be obtained through deception.

Likewise, an organization may possess advanced security technology but still face significant risk if employees are not prepared to recognize suspicious communications or unexpected requests.

Security therefore has to combine technology with institutional awareness.

The objective is not to assume that people will never make mistakes. It is to build systems that limit the consequences when mistakes occur.

From Protection to Resilience

The changing threat environment suggests a broader definition of cybersecurity.

Traditional security often emphasizes prevention: stop unauthorized access, block malicious traffic, and protect sensitive systems.

Resilience asks a different set of questions:

What happens if prevention fails?

How quickly can an organization identify a disruption?

Can critical operations continue?

Can affected systems be isolated?

Can trustworthy communications be maintained?

Can essential services be restored?

Can decision-makers distinguish reliable information from manipulated information?

These questions move cybersecurity from a purely technical function toward a broader strategic responsibility.

Strategic Competition in the Digital Environment

The implications extend beyond individual organizations.

Digital infrastructure has become part of national power. Countries that control advanced technologies, communications networks, computing infrastructure, data resources, and critical supply chains can possess significant strategic advantages.

At the same time, dependence on foreign technology or concentrated suppliers can create vulnerabilities.

This does not mean that technological interdependence should be eliminated. Modern economies depend on international cooperation, and complete technological isolation is neither practical nor necessarily desirable.

The strategic challenge is to understand where dependence creates unacceptable risk and where diversification, redundancy, or alternative capabilities may be necessary.

Building a More Resilient Environment

A resilient security strategy begins with visibility.

Organizations need to understand their critical dependencies and identify which services would cause serious disruption if they became unavailable.

They can then evaluate whether alternatives exist, whether important systems have sufficient redundancy, and whether recovery procedures have been tested.

Security should also extend beyond the organization’s immediate infrastructure.

Third-party relationships, software providers, contractors, communications systems, and other external dependencies should be considered part of the broader security environment.

At the national level, cooperation between government agencies, private companies, researchers, and infrastructure operators can improve awareness of emerging threats and strengthen collective resilience.

No single organization controls the entire digital ecosystem.

Conclusion

The enemy does not always need to break in.

In an interconnected environment, disruption can occur through a supplier, a compromised account, manipulated information, an unavailable service, or a dependency that an organization never considered a security vulnerability.

This changes the fundamental question of modern security.

The objective is no longer simply to build a stronger wall around an organization. It is to understand the entire environment in which that organization operates.

Security requires visibility into dependencies, resilience against disruption, protection of trustworthy information, and cooperation across organizational boundaries.

As technological interdependence continues to expand, the institutions that are best prepared will not necessarily be those with the strongest perimeter alone. They will be those capable of identifying their hidden dependencies, anticipating indirect threats, and continuing to operate when the systems around them are placed under pressure.

The most important security question may therefore not be who can get inside—but what can happen without anyone needing to get inside at all.

Publication Details

Publication Date:
September 2, 2026
Publication Type:
Journal Article
Journal / Publisher:
OVERWATCH: The Hughes Journal of Strategic Intelligence
Series:
Overwatch
Research Area:
International Relations

Abstract

This essay examines how Russia, China, and Iran exploit the openness of democratic societies to advance strategic objectives without relying primarily on direct coercion. Using Lioness as a narrative point of entry and drawing on official findings, court records, academic research, and recent cases from the United States, Canada, Latin America, and the Caribbean, it traces a common influence cycle: identify an authentic grievance, impose an emotionally compelling frame, enlist or cultivate trusted local messengers, conceal the foreign origin, and convert public attention into political, economic, or security advantage.

The analysis distinguishes among witting agents, proxies, access facilitators, unwitting amplifiers, and independent dissenters, emphasizing that controversial beliefs or foreign associations alone do not establish foreign control. It also situates money, ideology, compromise, and ego, including honeypot cultivation, within the gradual progression from access to dependency and deliberate tasking.

Although their methods overlap, their objectives differ: Russia seeks disruption and distrust; China favors normalization, elite accommodation, and geoeconomic leverage; and Iran combines ideological mobilization with cyber-enabled influence and Spanish-language media networks. The essay concludes that information dependency and economic dependency reinforce one another. Democratic resilience therefore requires transparent attribution, counterintelligence awareness, independent journalism, hemispheric coordination, and credible economic alternatives, not censorship or viewpoint policing.

Citation

Dr. Rafael Marrero. “The Enemy Does Not Need to Break In.” OVERWATCH: The Hughes Journal of Strategic Intelligence. September 2, 2026.

Available PDF Versions