Abstract

For decades, cybersecurity has been organised around protecting networks, systems, and organisational perimeters. Firewalls, intrusion-detection systems, secure gateways, virtual private networks, endpoint controls and network segmentation were developed on the assumption that an organisation possessed a relatively identifiable and controllable digital boundary.
The expansion of cloud computing, remote work, software-as-a-service, application programming interfaces, third-party dependencies, and artificial-intelligence systems has weakened the assumption that organisations can protect information primarily through a stable network perimeter.
This paper examines the transition from perimeter-centric cybersecurity to data-centric security, defined here as protecting information according to its sensitivity, context, value, and intended use throughout the data lifecycle. Using qualitative comparative analysis of the Equifax, SolarWinds, Colonial Pipeline, and All India Institute of Medical Sciences Delhi incidents, the paper examines how different initial compromise vectors produced data exposure, operational disruption, or loss of trust when post-compromise controls were insufficient.
The paper examines the limitations of traditional perimeter-based security; the relationship between data-centric security and Zero Trust; the protection of data at rest, in motion, and in use; data governance and accountability; and the emerging implications of artificial intelligence and agentic AI. The paper further examines the implications of agentic artificial intelligence, whose non-human identities, delegated authority, and tool access create new challenges for least privilege and continuous verification.
As digital boundaries dissolve, security must shift from defending networks to protecting data itself. This paper argues for a doctrinal transition to data-centric security, integrating Zero Trust principles and resilience across the data lifecycle.