{"id":106,"date":"2025-12-09T18:22:27","date_gmt":"2025-12-09T18:22:27","guid":{"rendered":"https:\/\/racter.com\/blog\/?p=106"},"modified":"2026-08-03T16:19:27","modified_gmt":"2026-08-03T16:19:27","slug":"stop-running-a-toll-booth-and-call-it-security","status":"publish","type":"post","link":"https:\/\/racter.com\/en\/blog\/stop-running-a-toll-booth-and-call-it-security\/","title":{"rendered":"Stop Running a Toll Booth and Call It Security"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">What the DoD Can Teach Us About Supply Chain Risk<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We need to stop pretending that securing the perimeter is enough. If your cybersecurity program in 2025 doesn\u2019t have a dedicated, rigorous Supply Chain Risk Management (SCRM) component, you aren&#8217;t just missing a feature\u2014you are failing at the fundamentals of defense.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To understand why, look at how the military builds a front gate.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The &#8220;UFC&#8221; Standard<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Department of Defense uses a standard called <strong>UFC 4-022-01<\/strong> (Entry Control Facilities) to design base perimeters. They don&#8217;t just put up a gate and check IDs. They divide the entry point into two distinct zones:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>The Access Control Zone:<\/strong> This verifies the <em>identity<\/em> of the driver.<\/li>\n\n\n\n<li><strong>The Inspection Area:<\/strong> This verifies the <em>safety<\/em> of the payload.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Most modern cybersecurity programs are obsessed with the driver and blind to the truck.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We spend millions on Identity and Access Management (IAM) to ensure the vendor is who they say they are. But once that vendor authenticates? We wave the truck right into our data center without opening the back doors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A military sentry wouldn&#8217;t let a truck through just because the driver is a &#8220;nice guy&#8221; with a valid badge. They inspect the vehicle because <strong>trusting the identity doesn&#8217;t mitigate the risk of the explosives in the cargo.<\/strong><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Search as a &#8220;Condition of Entry&#8221;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In physical security (codified in regulations like AR 190-13), consenting to a vehicle search is a <strong>&#8220;Condition of Entry.&#8221;<\/strong> If you don&#8217;t consent to the search, you turn around. Period.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In cybersecurity, we have lost this spine.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The Failure:<\/strong> We accept &#8220;proprietary information&#8221; excuses when we ask for a Software Bill of Materials (SBOM). We accept a vague SOC2 report instead of demanding a code audit.<\/li>\n\n\n\n<li><strong>The Fix:<\/strong> If a vendor wants their code to run in your environment, transparency is the Condition of Entry. No SBOM? No entry. No right to audit? Turn the truck around.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Where is Your &#8220;Overwatch&#8221;?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, physical gates rely on <strong>&#8220;Overwatch&#8221;<\/strong> positions\u2014armed personnel with a high vantage point observing the entire transaction, ready to engage if the situation changes <em>after<\/em> the initial check.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most security programs lack digital Overwatch for their supply chain. We vet a vendor once during procurement and then ignore them for three years. That isn&#8217;t security; that&#8217;s negligence. Real Overwatch means continuous runtime monitoring. Just because the vendor was safe when they entered doesn&#8217;t mean they haven&#8217;t been compromised since.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The Bottom Line<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">If you are running a program that checks IDs but ignores the cargo, you aren&#8217;t running a fortress; you&#8217;re running a toll booth. It is time to adopt a true Condition of Entry and establish Overwatch on your supply chain.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What the DoD Can Teach Us About Supply Chain Risk We need to stop pretending that securing the perimeter is enough. If your cybersecurity program in 2025 doesn\u2019t have a dedicated, rigorous Supply Chain Risk Management (SCRM) component, you aren&#8217;t just missing a feature\u2014you are failing at the fundamentals of defense. To understand why, look [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":115,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-106","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts\/106","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/comments?post=106"}],"version-history":[{"count":1,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts\/106\/revisions"}],"predecessor-version":[{"id":107,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/posts\/106\/revisions\/107"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/media\/115"}],"wp:attachment":[{"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/media?parent=106"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/categories?post=106"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/racter.com\/en\/blog\/wp-json\/wp\/v2\/tags?post=106"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}