The perimeter you spent a career defending quietly stopped being the thing that protects you.
For a long time security had a shape. Inside the network was trusted, outside was not, and the firewall was the wall between them. Get the wall right and you'd done the hard part.
Then the workloads moved to cloud, the staff moved home, and the applications started talking to each other across the public internet by design. The inside emptied out. The wall now runs around almost nothing.
What's left guarding the things that matter is identity. Who is this, what are they allowed to touch, and is it really them. An attacker today rarely batters through a perimeter. They log in, with credentials that work, and the network treats them as trusted because they are, technically, inside.
This is why the centre of gravity shifted to who and what, not where. Strong authentication, least privilege so a single stolen login can't reach everything, and the working assumption that any identity might already be compromised. Not because the network stopped mattering, but because it stopped being the line that holds.
The question moved from "is the attacker inside the network" to "whose login are they using." Most breach reports answer the second question, not the first.