The idea
Defence in depth combines safeguards across people, processes and technology. If one control fails, other controls can still prevent, detect, contain or support recovery from an incident.
A layered example
- People: clear guidance and a straightforward way to report suspicious messages.
- Processes: access reviews, patch management and a tested incident response plan.
- Technology: MFA, least privilege, malware protection, firewalls and monitoring.
Backups and recovery testing matter too: preventing every incident is not realistic.
Quality over quantity
Adding more products is not automatically better protection. Layers should address relevant risks, work together and avoid sharing a single point of failure. Their effectiveness needs checking over time.