Skip to content

Mighty Walls. No Alarm.

The Great Wall didn’t save the Ming Empire from the threat already inside. Why perimeter defense isn’t enough, and what defending from within means.

7 min read
Also inenit

The Great Wall, Wei Zhongxian and the problem no firewall can solve

The man who never crossed the walls

It’s the early decades of the seventeenth century in China, under the Ming dynasty. The Great Wall is the symbol of an empire that made perimeter defense its philosophy of survival: thousands of kilometers of stone and brick, signal towers ready to light fires visible from miles away, garrisons along every strategic stretch. A system designed to spot the enemy from afar and stop him before he touches the border.

And yet the Wall did not save the Ming Empire.

Its deepest crisis began from the inside, with a man who deserves to be remembered not for his moral qualities, which were few, but for the precision with which he grasped what the empire’s generals had not: walls protect you from the outside, not from whoever is already in.

Wei Zhongxian was born in 1568, poor and nameless. To enter the court, he made himself a eunuch: not out of vocation, but out of calculation. It was one of the few ways in for someone without noble blood, and he went through it without looking back.

Inside, he was nobody. A servant among servants, minimal permissions, invisible by design. And that’s where he began to watch, with the cold patience of someone who has understood that time, inside a vast and distracted system, is the most underrated weapon there is. He cultivated the right friendship at the right moment, Madame Ke, the nurse of the future emperor, and through her he slipped into the room closest to power. He made no noise. Not for a single day.

When the young prince became emperor in 1620, Wei was already there. The new emperor, Tianqi, trusted him blindly and preferred to devote himself to his real passion, carpentry, leaving the empire to whoever seemed to know what they were doing. Power came one rank at a time, one appointment at a time, without a single step that looked excessive on its own. Then Wei stopped waiting: he purged his rivals, some of whom were tortured and killed in prison, took over the secret police and every lever that mattered.

The towers of the Great Wall kept scanning the horizon. None of them looked inward, toward the room where a former nameless servant decided who lived and who died.

Then it all ended. Not because of an alarm, not because of a fire lit on a tower. It ended because the emperor died, and the young man who took the throne had no intention of inheriting his eunuch as well. In 1627, Wei took his own life before he could be tried.

But the system he had hollowed out from within did not recover with his death. Seventeen years later, when Li Zicheng’s rebels took Beijing and a Ming general, Wu Sangui, let the Manchus through the Shanhai Pass, the dynasty fell. Not at the hands of Wei Zhongxian, but on ground he had left unable to withstand any blow.

The walls, that day, were still perfectly intact.

The problem walls cannot solve

The Great Wall was an extraordinary achievement. Building it was not a mistake. The mistake was believing it was enough.
The problem with perimeter defense isn’t technical. It’s conceptual. Whoever builds walls is answering a precise question: how do I stop whoever is trying to get in? It’s a legitimate question. But it leaves another one open, a harder one: what do I do about whoever is already inside?

In computer systems, this distinction has a name. It’s called a threat model. And many Italian SMBs have an implicit threat model that looks a lot like the Ming Empire: robust firewalls, updated antivirus, a few rules on outbound traffic. All oriented outward. All designed to stop someone knocking at the door.

The problem is that perimeters always have cracks. Not because they’re badly built, but because a functioning organization can’t be hermetically sealed. There are emails to receive, VPNs to maintain, suppliers to connect, updates to download. Every point of contact with the outside is a surface. And surfaces erode.

A patient threat actor doesn’t need to scale the walls. They need to find a door left ajar, a moment of distraction, a reused credential. Something that happens every day, in every organization, with a frequency nobody likes to admit.

Inside the walls: how a threat actor moves

Once inside the perimeter, the logic changes completely. The threat actor is no longer in offensive mode: they’re in reconnaissance mode. Their primary goal isn’t to destroy or encrypt, but to understand where they are and what’s around them.

Anyone who knows the technical sequence (beachhead, lateral movement, privilege escalation, all the way to total control) recognizes the pattern immediately. Wei Zhongxian followed exactly the same logic, four centuries before anyone gave it a name in English: silent entry with minimal privileges, patient observation, slow accumulation of relationships and access, one jump at a time, without ever generating anything worth noticing.

The difference between him and a cyber threat actor isn’t the strategy. It’s the time available. For a cyber threat actor, the median is fourteen days before being discovered (Mandiant M-Trends 2026). Wei Zhongxian had years.

Why we keep watching the horizon

If the problem is known (and it is, at least within the cybersecurity community), why do most organizations keep investing almost exclusively in the perimeter?
The answer is psychological before it’s technical. The perimeter is visible. It’s measurable. A firewall has a price, a configuration, a dashboard showing how many connections it blocked today. It’s something you can show management, put in a report, use to justify a budget.
Lateral movement, privilege escalation, the anomalous behavior of a compromised account are subtle, contextual phenomena, hard to detect without specific tools and dedicated skills. They don’t show up on a dashboard. They can’t be counted. They don’t produce the instant gratification that a list of blocked threats can give.

There’s also a problem of mental model. When we think of a cyberattack, we think of something coming from outside. A hacker knocking at the door. A virus arriving by email. A port scan from a foreign IP. It’s the model Hollywood taught us, and it has the advantage of being simple, narratively clear, emotionally intuitive.

But Wei Zhongxian knocked on no door. He moved through the system patiently, using the channels the system itself provided, becoming over time something the system didn’t know how to recognize: an insider who had acquired too much power.

Defending from within: a change of perspective

Defending from within doesn’t mean abandoning the perimeter. It means ceasing to believe it’s enough.
Concretely, it means shifting some of your attention (and budget) toward what happens inside the network. Asking not only who is trying to get in, but what happens once someone is in. Who accesses what. When. From where. With which credentials.

It means accepting that initial compromise is, to some extent, inevitable. Not because perimeter defenses are useless, but because the attack surface of a modern organization is too wide and too dynamic to be protected absolutely. The phishing email that gets past the filter. The reused credential. The compromised supplier. These events happen, and will happen more and more often as threat actors refine their techniques.
The question isn’t whether someone will get in. The question is: how quickly do you notice?
A threat actor who stays in the network for fourteen days has fourteen days to explore, escalate, exfiltrate. Detecting them on day one, when they’re still at the beachhead stage, with minimal privileges and no real visibility, completely changes the profile of the damage. It doesn’t eliminate the incident, but it contains it. The difference between a manageable event and an operational disaster is often measured in hours, not days.

Send threat actorsfrom your network into ours.

From €145 per decoy per month. Free trial available, no hardware, no setup fees.

Join The Hive

Threat intel from our own decoys, first-hand. Not another newsletter.

  • Intel from our network. What our decoys catch: the credentials threats try, the tools they bring, the techniques that are new. First-hand, not recycled.
  • Alerts, when it matters. When something we see is worth acting on, you hear it from us, with what to do.
  • Attack stories. The story behind the intel: a real attack, narrated step by step from the offensive side.

Low volume, high quality.

Plus occasional Hoxey news, and we remember your visits. Unsubscribe anytime.

Get in touch

Write to us here and we'll email you back.

We'll reply by email. Privacy policy Prefer a call? Book one