The security stack for a distributed, cloud-first company

by
Dawid Winiarski
Last update:
July 17, 2026

Some companies are spending the next few years dismantling a perimeter they spent decades building. You never had one to lose. If your team is remote or hybrid, your systems are all in the cloud, your people work from devices you do not fully control, and your data lives in dozens of SaaS apps with AI woven through them, then the castle-and-moat model of security was never yours to begin with. There is no office network to hide behind, no on-premises server room, no edge to defend.

That sounds like a disadvantage, and in one way it is, because you cannot fall back on a network boundary when something goes wrong. But it also means you get to skip a painful migration and go straight to the model everyone else is moving toward, where identity is the perimeter and trust is decided per request rather than by which side of a wall someone sits on. What follows is the general stack reordered for a company whose whole estate is identity, SaaS, and the cloud.

  • A distributed, cloud-first company never had a perimeter to lose, so it can skip a painful migration and adopt the model everyone else is moving toward: identity is the perimeter and trust is decided per request.
  • Identity is the only control that is always present, because every access request from any device carries an identity and little else you can rely on. MFA goes on everything, with phishing-resistant factors for anything sensitive.
  • Device trust becomes the second half of every access decision, because you often do not own the devices reaching your systems. Manage what you can, and control the browser for the rest.
  • SaaS and AI are nearly the whole estate, so the sprawl that is manageable elsewhere is defining here: apps behind single sign-on, OAuth grants reviewed, and what AI can reach governed.
  • A distributed company is the natural case for zero trust, adopting it as a starting posture rather than dismantling years of implicit network trust to get there.
  • The ordinary baseline still applies: endpoint protection where you can deploy it, email filtering, tested backups of the data that matters, and a managed detection service focused on identity and SaaS, since there is no SOC and no network to watch.

the stack, reordered for no perimeter

  • Critical · Territory: Identity · First move: Your only real perimeter. MFA everywhere, phishing-resistant for admins, SSO, strong conditional access, fast offboarding.
  • Critical · Territory: Device trust · First move: You do not control the network, so device health gates access. Manage what you can, control the browser for the rest.
  • High · Territory: SaaS · First move: Your entire estate. Apps behind single sign-on, OAuth grants reviewed, sprawl mapped.
  • High · Territory: AI · First move: It is everywhere your people work. Know what is in use, keep sensitive data out of consumer tiers, govern agent access.
  • High · Territory: Secure access (ZTNA) · First move: Replace any VPN with per-app access based on identity and device.
  • Baseline · Territory: Data and backups · First move: Your data sits in SaaS. Know where it flows, and back up what the vendor will not.
  • Baseline · Territory: Endpoints and email · First move: EDR where you can deploy it, email filtering on, a word to the team about phishing.
  • Later · Territory: Detection and response · First move: Managed detection covering identity and SaaS, since you have no SOC and no network to watch.

identity is the whole game

For a company with a perimeter, identity is one important control among several. For you it is the only one that is always present, because every single access request, from any device, anywhere, carries an identity and little else you can rely on. So the controls that would be merely good practice elsewhere are existential here.

MFA goes on everything, with no exceptions, and the accounts that can reach anything sensitive want phishing-resistant factors rather than codes a fake login page can relay. Single sign-on is not a convenience, it is how you keep one place to grant and remove access across an estate that is entirely SaaS. And conditional access does the work your firewall used to do: instead of trusting a connection because it came from the office, you allow it because the identity is verified and the device is in a known good state. Offboarding has to be fast and complete, because a former contractor with lingering access has the same reach from their living room that an employee has from theirs.

trusting devices you don't own

The hard part of having no network is that you also, often, do not fully own the devices. Personal laptops, home machines, a phone that checks work email, all reaching your systems from networks you have never seen. You cannot assume a device is healthy just because it connected, so device trust becomes the second half of every access decision.

Where you can manage devices, do, and feed their security posture into your access rules so an out-of-date or non-compliant machine gets less access or none. Where you cannot, because it is someone's personal device or a contractor's, the browser becomes the place you exert control, since that is where the work actually happens and where you can apply policy without owning the hardware. The aim is that access decisions consider both who is asking and what they are asking from, every time.

saas and ai are your entire estate

For most companies SaaS and AI are a growing part of the picture. For you they are nearly the whole of it, which means the sprawl that is a manageable problem elsewhere is a defining one here. Your teams adopt apps without asking, OAuth grants accumulate into standing access you never see, and your data scatters across services you do not operate. The work is to get apps behind single sign-on, inventory the connected apps and the scopes they hold, and review them the way you would review human access.

AI rides along with all of it, because a distributed, tool-happy team adopts it fast and feeds it company data through the browser and through SaaS integrations. Knowing what AI is in use, keeping sensitive work on enterprise tiers that do not train on your data, and governing what AI assistants and agents can reach is a real part of your stack rather than a future concern.

you're the natural case for zero trust

Everything above adds up to a single idea, and it happens to be the one the whole industry is converging on. With no perimeter, no trusted network, and no assumption that a device is safe, you have to decide trust per request, based on a verified identity and a known device, granting only the access that request needs. That is zero trust, and where a traditional enterprise has to dismantle years of implicit network trust to get there, you can adopt it as your starting posture. Replacing any remaining VPN with per-app access is the concrete first step.

the baseline still applies

None of this removes the ordinary floor. You still want endpoint protection on the devices you can manage, email filtering switched on, tested backups of the data that matters, and a practical word to a scattered team about phishing, which hits remote workers as readily as anyone. These sit below identity and SaaS on your list, but a missing tested backup is still the gap that turns an incident into a crisis, distributed or not. And because you have no security operations team and no network to watch, a managed detection service focused on identity and SaaS is usually the sensible way to get eyes on the surface that matters to you.

where to start

See your access and your SaaS clearly first, because for a company like yours that surface is the entire attack surface, and it is the thing that sprawls fastest and hides the most. Map the whole board, then work down the priority order above, knowing that identity and SaaS visibility is the foundation everything else stands on.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.