Cybersecurity Glossary
Defence in Depth
Layering controls so that no single failure results in a breach.
What Defence in Depth means
Defence in depth assumes every control will eventually fail. Mail filtering misses a message, a person clicks, so the endpoint tool must catch the payload, the account must have limited rights, and the backup must survive. Each layer buys time and reduces the blast radius.
Why Defence in Depth matters for small businesses and nonprofits
Small organisations often invest heavily in one control and leave the surrounding layers empty. A balanced set of ordinary controls consistently outperforms one very good control standing alone.
What to do about Defence in Depth
- Map your controls against the stages of an attack and look for the empty stages
- Prefer breadth over depth until the basics are covered everywhere
- Assume any single control will fail and ask what happens next
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.