About this interactive
What you're doing: a defense-in-depth diagram has been drawn with six layers and twelve empty positions on it, two per layer, and each position states what a control sitting there has to accomplish. Twelve named controls are on the board. You place each one where it belongs. Why it matters: defense-in-depth is not the claim that more controls are better — it is the assumption that every control eventually fails, turned into a structure that survives the failure. That assumption is what makes the layers the unit of analysis rather than the products. An organization can hold a next-generation firewall, a tuned IPS and a well-run endpoint program and still lose its customer database in an afternoon, if nothing at the data layer meant the copied file was unreadable and nothing at the human layer meant a phished password was insufficient on its own. The layers here run outside in — perimeter, network, endpoint, application, data, human — and the ordering is doing work: an attacker who defeats a layer meets the next one, and an insider who never crossed the perimeter starts at the network layer with everything outside it irrelevant. How to use it: read all twelve positions before placing anything, because the board is built out of pairs that overlap on purpose. A firewall and a web application firewall are both firewalls, and one rules on packets at the network boundary while the other parses HTTP in front of one application, so the word in the name never decides the layer. Full disk encryption and data encryption both encrypt, and one answers a stolen laptop while the other answers a copied file, which is why they sit at different layers and why having one does not give you the other. A VLAN and an ACL are one control split in two — the VLAN draws the boundary and the ACL is what actually enforces it, so segmentation without rules is a diagram rather than a fact about the running network. A WAF and input validation both stop injection, and one is a shield you can raise this afternoon in front of code you cannot change while the other is the repair that makes the vulnerability stop existing. Training and multi-factor authentication are the human layer's pair: one reduces how often somebody is fooled, the other reduces what it costs when they are, and no amount of the first removes the need for the second. Carry the finishing move out of the activity, because it is the one an architect actually performs. Look down a completed stack and remove one control at a time in your head. Where removing a control empties a layer, you have found a gap — and a gap is not compensated by strength elsewhere, because the layers are sequential rather than additive. Nothing at the endpoint layer means the first sign of a compromised workstation is whatever it does loudly enough for another layer to see. Nothing at the data layer means every incident above it is a disclosure rather than an intrusion. Nothing at the human layer means the entire technical stack is bypassed by one convincing email, which is how most real intrusions begin.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →