The firewall model assumes there is an inside and an outside. Machines inside the building are trusted, traffic from outside is not, and the job of security is to police the line between them.

That line stopped existing some years ago and most defences have not been rebuilt around its absence.

Consider what a laptop does. It sits on the corporate network on Friday, goes home, connects to a domestic router with a default password, visits whatever the owner’s family visits, spends Saturday on a hotel network shared with strangers, and returns on Monday to be plugged back into the trusted side. Whatever it collected over the weekend is now inside the perimeter, having been carried through the wall by an employee with a valid badge.

Then there is the browser, which is a hole deliberately punched through the firewall for every user, permanently, because the alternative is a company that cannot work. Attacks arrive through it as ordinary allowed traffic, and the firewall is functioning exactly as configured while they do.

What is going on with web servers this spring is a separate and more depressing story.

The automated campaigns compromising sites in enormous numbers are exploiting a flaw that has been documented for a decade. Text arrives from a visitor, gets pasted into a database query without being separated from the query itself, and the visitor’s text is executed as instructions. The fix is well understood, costs almost nothing, and is taught in every competent introduction to the subject.

It remains everywhere because a vulnerability produces no symptoms. A site with this flaw looks and behaves exactly like a site without it, right up until the morning it does not, and no manager approves a fortnight of remediation for a defect nobody can see.

I wrote last autumn about a botnet that had become disciplined enough to attack the researchers examining it, and the professionalisation I described there is what is driving this. Mass exploitation of a known flaw is not the work of somebody proving a point. It is inventory acquisition, done at scale, by people with a business plan.

Defending a perimeter made sense when the valuable machines stayed in the room. They do not, and the honest position now is that anything inside your network should be treated as potentially hostile, which is expensive, unpopular, and correct.