Smart-cloud platforms increasingly reject the old idea that a request from inside the corporate network can be trusted by default. This simulator runs four request lanes — a verified employee on the office LAN, a verified employee connecting remotely, a compromised "inside" device carrying stolen credentials, and an outside attacker with no credentials at all — toward a policy engine that can run in one of two modes. In legacy perimeter mode, anything arriving from inside the network is waved through untouched, so a compromised insider walks straight past the gate. In zero-trust mode, every request is scored the same way regardless of where it originates: identity verification, device posture and behavioral anomaly are combined into a single trust score and checked against the resource's threshold before access is ever granted. Tune the threshold, the share of compromised inside devices, and the request rate, and watch the breach counter expose exactly what perimeter trust misses.