← Core Concepts

Core Concepts

Defence in Depth

Using complementary layers of protection so one failure is not the whole story.

Threats & defence

The idea

Defence in depth combines safeguards across people, processes and technology. If one control fails, other controls can still prevent, detect, contain or support recovery from an incident.

A layered example

  • People: clear guidance and a straightforward way to report suspicious messages.
  • Processes: access reviews, patch management and a tested incident response plan.
  • Technology: MFA, least privilege, malware protection, firewalls and monitoring.

Backups and recovery testing matter too: preventing every incident is not realistic.

Quality over quantity

Adding more products is not automatically better protection. Layers should address relevant risks, work together and avoid sharing a single point of failure. Their effectiveness needs checking over time.

Further reading

NIST glossary: defence in depth.