Assume Change: Why IT security needs adaptability
For a long time, IT security was largely built around clear security boundaries, known as “perimeter security.” Systems were isolated, access was controlled, and firewalls were put in place. The focus was on protecting the organization from external threats. With Zero Trust and “Assume Breach,” a broader perspective emerged: a compromised account or security incident is treated as a real possibility that must also be addressed.
Today, another dimension has been added: technologies, regulatory requirements, and even the foundations of digital security continue to evolve, making another principle increasingly important: Assume Change.
From “Protect the Perimeter” to “Assume Change”
This evolution can be simplified into three phases.
First, protecting the perimeter was the main focus: Anyone working within the corporate network was largely considered trustworthy. With cloud services, mobile work, and distributed teams, this boundary became less relevant.
Zero Trust and “Assume Breach” respond to this: access is regularly verified, permissions are minimized, and security incidents are treated as a possible part of day-to-day operations.
“Assume Change” goes one step further: the principle takes greater account of the fact that the security mechanisms, regulatory requirements, and technical conditions in use today are not static. A future-ready architecture must be adaptable and able to respond quickly to changing threats.
Encryption as an example: Data security has a time dimension
The time dimension of data security is particularly evident in cryptography, or encryption technology. Data encrypted today may need protection for many years. At the same time, authorities and companies are preparing for post-quantum cryptography because powerful quantum computers could eventually threaten widely used methods. The U.S. National Institute of Standards and Technology (NIST), which develops internationally influential cryptographic standards, now explicitly calls on organizations to begin migrating to so-called “quantum-resistant” methods.
The question, then, is how long data must remain confidential and whether the security architecture in use can adapt to new requirements in time.
The EU has presented a coordinated roadmap for this: all member states are expected to begin transitioning to post-quantum cryptography by the end of 2026; use cases requiring particularly high levels of protection and critical infrastructure are to migrate as soon as possible and no later than the end of 2030.
AI accelerates change
Artificial intelligence (AI) is already changing day-to-day work. AI provides support in many areas - for example, research, translation, analysis, and document processing. At the same time, it increases the speed at which existing cyberattacks can be scaled. Companies want to use AI productively while also processing sensitive information in a controlled manner. Permissions, data access, and secure interfaces are therefore more important than ever.
Regulatory requirements keep evolving, too
NIS2, DORA, the Cyber Resilience Act, and the AI Act show the same development from another perspective. Legislative changes also require companies to create structures that allow new requirements to be implemented and demonstrated on an ongoing basis. This includes risk management, suppliers, access control, documentation, and resilience.
What is concerning is that government regulation is becoming so important largely because many companies fail to take action on their own initiative. Yet continuously improving security measures is a fundamental requirement for business continuity and should receive appropriate management attention in every company.
Read our regulatory overview to find out which laws are particularly important right now →
Security through adaptability
Sustainable IT security has always depended on adaptability. What is changing now is the rapid development of new forms of attack and the breadth of the attack surface. A modern cyberattack can bring entire companies to a standstill in an instant, comparable to a major fire or natural disaster. In that sense, the principle of “Assume Change” is not new in itself, but today it is more important than ever as a foundation for robust IT security.
Established cornerstones such as certifications, encryption, MFA, hosting in Germany, and regular audits remain important anchors. In addition, it is becoming crucial how well and quickly a platform can adapt to changing conditions: new cryptographic standards, new regulatory requirements, new interfaces, or new forms of automation.
netfiles: Your data partner through change
For netfiles, this adaptability is part of our product strategy - and an important reason why we remain successful even after 25 years. We continuously modernize our technological foundation, creating the conditions to implement new features and security requirements more quickly.
Our commitment remains unchanged: customers should be able to exchange sensitive data securely and collaborate on it without having to deal with every technical change happening behind the scenes. This allows us to take a significant part of that complexity off their shoulders. Security, data protection, and compliance are fundamental to our offering.
For netfiles, “Assume Change” means planning for change. Companies need partners that identify developments early, continuously evolve the technical foundations, and translate new requirements into practical solutions.
Security that can evolve
New technologies and regulatory requirements are continuously changing how sensitive data is handled. Our netfiles experts can advise you on how a secure data room can support your requirements for access control, traceability, data protection, and digital sovereignty. Talk to us about your processes and security requirements - together, we will find the right solution.