Defense in depth is a layered security strategy that places multiple safeguards throughout a network rather than relying solely on perimeter protection. If one layer fails, additional barriers continue to protect critical systems and data.
Defense in Depth
Nowadays, it's not enough just to protect our perimeter and figure everything on the inside is okay. That's where defense in depth comes into play. We want to have multiple barriers, so that especially if one fails us, another will stop an enemy from getting into our systems.
At one point in time, as IT professionals, we spent all of our time protecting our perimeter, putting things like good firewalls on there so people couldn't enter into our network. We considered that inside of our network everything was secure, so we didn't have people that could be compromised, computers that could be compromised, no one could plug into our switches. So we weren't as concerned about the inside. That's no longer safe. We have to practice defense in depth.
Defense in depth is using multiple layers of safeguards, not just at the perimeter but all along the way, to protect our assets, our data, our systems and resources. Think of it like an onion. We have the perimeter of the onion, which is the outside, and we want to make sure it's protected. But if for some reason there was a penetration to that outside layer, we would want another layer, and another layer after that. We want these multiple layers to really safeguard our resources, especially our more secure resources.
Let's look at an example. We've got some data that we need to protect. If it were to get out, it would cause a problem for us. For instance, maybe it's a lot of customer data, and if it were to get out, we'd have to notify all those customers that we lost their data. So the first thing we do is put a wall around it and a gate, so that we can have limited access to this data. We also put a security guard up, so we can identify anybody that's walking up or any issues with them. Maybe we even put some surveillance monitoring up as well. But just in case it still gets stolen, we are going to encrypt that. So even if one of these layers fails, we still have protected data.
Same thing with our networks. We have a firewall on the outside, but we probably want to have firewalls turned on on the inside as well, so these machines would have firewalls also. Maybe we have an intrusion detection system or intrusion prevention system on our firewall; maybe we want it on the host level as well. Maybe we want to secure our network so that if you plug into the switch, you don't automatically get a connection: you have to go through something like 802.1X. And maybe we train our people.
So really what we want to do is all of this. We want to secure our network so that nothing gets leveraged within it, because our networks now are really not like that onion. It's more like an artichoke, where there are layers and you can bury down in between these layers, and an attacker, an adversary, can figure out ways to get into our network. But if we have enough layers, it's really going to stop them from being able to get to the heart of what we're trying to protect.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →