The contributor of this article, Bayani Elogada, gives his insights on the current cyber landscape. He is a cybersecurity officer and does consultancies for multiple orgs. In this blog, he shares systemic issues plagueing orgs and their lack of Defense in Depth in cybersecurity. He shares a list of pointers and solutions when observing Defense in Depth at every layer.
What is Defense in Depth in Cybersecurity
Defense in depth in cybersecurity is a strategy that uses multiple layers of security controls to protect systems from attacks. Instead of relying on a single defense like a firewall, organizations use logging, monitoring, access control, and updates together.
Each org varies dramatically in its approach, some great, some just suck. It's frustrating for me because while some do know the severity of unprotected cyber posture, they simply don't put effort into it, leading to a gaping hole in their assets that no one particularly wants to fix. Digging any deeper justs ends up being frustrating for me.
Why Defense in Depth Matters
Former FBI Director Robert Mueller once said that cyber threats would eventually overtake and overshadow terrorism. When I look at logs in my consultancies, I get a first person POV of how it is: intrusion attempts, feeding lists of hacked credentials into logins, or attempts to check dangling backups in websites and apps. You don't need guns and bombs to cause damage to property anymore.
That leads me to realize an action point that people seem to know but don't say out loud: The same effort you spend with protecting against physical threats, should be more or less at par with the effort you put with protecting against cyber threats.
Key Layers of Defense in Depth
Defense in Depth in the digital world is not the same as Defense in Depth in the military. The military kind assumes a delaying tactic. Also known as elastic defense, it means you protect more by delaying the advance rather than preventing the advance of the attacker.
Defense in Depth in cyber and infosec is nearly an opposite idea: Prevent the attack at every level. Think of it like an onion: except the onion can log events, protect intrusions, and fight back at every layer
In my time in cyber consulting a lot of companies think everything cybersecurity-related is just proper use of firewalls. It's a whole lot more than that. Firewalls are important but so is logging, detection of anomalies using intrusion detection systems, incorporating red team or proactive security testing like vulnerability scans and penetration tests, making sure everything is updated, and observing good privilege control. This isn't exhaustive, but it should give you a good baseline.
Let's talk about them one by one.
Logging (Why It Matters)
Logging doesn't seem like a big deal at first. So what if I can see if a file was touched? Not a big deal, right? Now let's put this into this perspective. Imagine you have security cams at your office, but you had no way of checking camera feeds from the past days. That's what it's like without proper logging systems.
I've seen a lot of companies fail at this. Some do have logging for compliance reasons, but keep their logs for like 3 days retenion. So if they had a long weekend and something happens, poof. No evidence. The best practice, in my experience, is 60 days, but some orgs I've seen do fine with 30 days. It depends on your local legislation too.
Alerts and Intrusion Detection
Logging is fine, but only if you actually have someone assigned to read logs 24/7. Otherwise, what happens if that one action in a sea of hundreds of thousands of actions turns out to be malicious? This is where IDS and alerting comes in.
With alerting systems, you can leverage AI and automated tools to check for attacks every minute, every hour, everyday. No need for humans to check all the time. If the alert goes to the email, the company's cyber person can pull overtime and adjust firewalls accordingly, then go back to living their dailies. Less toil for more effectiveness.
Why are Firewalls Important
Not all firewalls are equal. Some cover IP address and region-based access. Some protect on a per-request basis. And some simply work on specific assets only, like websites, but not in remote desktop apps.
This leads you to a solution where you can't have only one firewall solution. I've seen a lot of companies dependent on only one layer. Not a good idea. A different tool for a different situation is the right answer.
Additionally, there should be firewalls at every level. Robert Mueller famously mentioned "There are only two types of companies: those that have been hacked and those that will be". Firewalls should be in places that assume that an attacker is already inside. Firewalls that segment the network, firewalls that protect the websites, firewalls that protect workstations between workstations (if a worm virus happens to infect one PC in the office for example).
Why is it so important to update
It's 2026 and surprisingly a lot of people still demonize software updates. As a person who has worked in red team cyber before, believe me when I say this: Software updates can and will save your ass. Sometimes the difference between hacking immunity vs hacking vulnerability is yesterday's update.
What is POLP - Principle of Least Privilege
Surprisingly a lot of orgs I've been to fail at this. Half the orgs I go to have accounts that have "owner" access levels even for junior accounts. Frustrates me always. Their argument is always that it's far more convenient that way.
Imagine how that might end up if management ends up with an employee-facing faux pas one day. Miscommunication. Bad handling of an incident. Or not even a faux pas, just a disciplinary memo. Or how about when the employee just had a bad day? Would you still trust a junior with "owner" level privileges to keep their hands to themselves?
All in all I think orgs still have a lot to learn. So much still needs to be done to improve security in the current cyber landscape. Defense in Depth is the key to protecting our online assets, wherever they may be in the world.
FAQ
Why is defense in depth important?
Defense in Depth provides redundancy in the event of the failure of one layer of protection, and allows an org to cover all levels of security in their attack surface.
What are examples of defense in depth?
Logging, alerts, POLP, IDS (Intrusion Detection Systems), IP-based (threat-centric) firewalls, Behavior-based firewalls, software updates, and proactive security scanning.
Bayani Elogada can be contacted via his LinkedIn account at https://www.linkedin.com/in/belogada/ .
