crunchy outside, chewy center

expression

security

The classic critique of perimeter-only security: a hard shell around a soft, defenseless inside.

Bill Cheswick's 1990 description of firewalled networks - a sort of crunchy shell around a soft, chewy center - is still the sharpest one-liner about why one perimeter is not a strategy. Everything from segmentation to zero trust is an answer to it.

A hard crunchy outside with a soft chewy center is the vivid description of perimeter-only security, and it is the same critique as castle and moat delivered with more contempt. The point of the phrasing is that the interior is not merely less defended, it is undefended, and everyone involved knows it.

What makes the interior soft is usually accumulation rather than decision. Flat networks because segmentation was deferred, service accounts with broad rights because scoping them was harder, credentials reused across systems because rotation was painful, management interfaces reachable from anywhere inside because that was convenient, and no monitoring of internal traffic because the volume was high and the value was assumed low.

The consequence is that the entire security posture rests on nobody getting through the shell, which is a bet against an attacker who only needs one phishing email to work. Fixing it is unglamorous and slow: segment, scope, monitor east-west, and remove the shared credentials, none of which produces a visible improvement until the day it contains something. That is why it is consistently underfunded relative to perimeter products, and why the phrase persists as a diagnosis.

Also known as: hard shell, soft center, M&M security

All glossary entries