AI Briefing
KO

From Perimeter Security to Zero Trust: A Security Advancement Journey

·2026.02.10 11:05

Key point

Toss Payments introduces the phased security advancement process it built in a hybrid IDC and AWS environment.

1 / 2

Details

To improve a poor security environment—where encrypted traffic analysis was difficult and reliance on a single line of defense was the norm—the company established a Defense in Depth strategy.

First, to advance perimeter security, it built a hybrid security architecture spanning IDC and AWS. It introduced SSL/TLS traffic decryption to gain visibility into encrypted attacks, and established a security process in collaboration with merchants.

To prepare for attacks that bypass the perimeter, it also strengthened server-level internal network security. In the IDC environment, log collection and threat detection are managed in an integrated manner via Wazuh, while in the AWS environment, an intelligent detection system was built using GuardDuty.

To protect the dynamic container environment, container runtime security was established as the last line of defense. Falco was introduced into the IDC's Kubernetes environment to monitor real-time system calls (Syscalls), and security events are delivered via Falco Sidekick.

Finally, the company proactively adopted Zero Trust security, which performs continuous verification of users and devices along with dynamic access control.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.