Defense in depth is a security strategy that layers multiple, independent controls across an environment so that the failure or bypass of any single control does not lead to compromise. Adapted from military doctrine, it spans physical, network, host, application, and data layers, combining preventive, detective, and responsive measures to slow attackers, increase the cost of intrusion, and provide redundancy. It assumes no control is infallible and complements modern paradigms such as zero trust by ensuring that defences are distributed rather than concentrated at a single perimeter.
Overview
- The principle assumes every control can eventually fail, so overlapping defences provide resilience.
- Controls span physical, network, host, application, identity, and data layers.
- Each layer adds preventive, detective, and responsive capability, slowing and exposing attackers.
- It complements zero-trust thinking by ensuring defences are not concentrated at one point.
Mechanisms
- Network segmentation and Firewall rules limit lateral movement.
- Access Control and least privilege constrain what compromised credentials can reach.
- Encryption protects data at rest and in transit even if other layers fail.
- Intrusion Detection and monitoring surface activity that bypasses prevention.
Applications
- Enterprise network and data-centre protection.
- Cloud workload hardening across identity, network, and workload layers.
- Critical-infrastructure and industrial control system security.
- Endpoint and application protection programmes.