Glossary

Defense in Depth

Don't rely on one lock. Use multiple layers - firewall, antivirus, EDR, training, monitoring. If attackers get past one defense, they hit another. No single point of failure.

What is Defense in Depth?

A layered security strategy that uses multiple security controls so if one fails, others still protect assets.

Why Should You Care?

A single security control—whether a firewall, password policy, or endpoint detection tool—will eventually fail against determined attackers or zero-day exploits. Defense in Depth ensures that when one layer is breached, subsequent controls still block or slow lateral movement, giving security teams time to detect and respond. Without it, a compromised credential or unpatched vulnerability can become an immediate full-system compromise.

Is your business exposed?

Real-World Example

After the 2013 Target breach exposed millions of payment cards, investigators found attackers entered via a third-party HVAC vendor's credentials and then moved through the network before reaching point-of-sale systems. A layered approach—network segmentation isolating payment systems, multi-factor authentication on privileged accounts, and behavioral monitoring—would have slowed or trapped the intruders, preventing the progression from initial vendor access to the checkout systems that processed card data.

How to Protect Against Defense in Depth

  1. 1.

    Audit security controls at each layer

  2. 2.

    Ensure no single point of failure

Is your business exposed?

Check if your company data is circulating on the dark web

Free scan • No credit card required