Well, maybe. But thinking of security in terms of perimeter has its downsides. It is more productive to first look at "what are the assets that you want to protect." Are these documents, email, metadata, connection graphs, etc. Then, using an architecture diagram, you can look at the various interfaces in the system, and check for each one how they can be abused. 

Yes, people are not always smart. But then, that's what they pay for help, don't they?

