In-depth defense, also known as defense in depth, is a multi-layered strategy that protects organizations against increasingly sophisticated cyberattacks. It builds on the principle of the “onion” model: if one layer fails, another will catch, slow, or stop the attack. In practice, it allows security to be built up gradually according to priorities and budget.
From military strategy to digital security
The roots of in-depth defense reach back to antiquity and were later applied during World War II, when layering protection became an effective tactic. In the 1990s this approach shifted into IT, as with the advent of the internet it was no longer sufficient to protect only the network perimeter. International recommendations, such as those from the U.S. NIST, identified it as an appropriate way to respond to growing cyber threats. Today the concept is also promoted by ENISA and in Slovakia it is recommended by SK-CERT, especially for industrial and operational (OT) environments.
The essence remains the same: build multiple independent protective layers that complement each other. Each layer protects a different type of asset and reduces the chance that a single mistake will open the door to an attacker. This approach is more resilient to multi-stage and multi-vector attacks, which today are part of everyday reality.
Critical assets: more than just data
Laypeople often think of critical assets as only data, information systems, or digital services. In reality, this group also includes people and holders of key know-how, identities and access rights, suppliers, production and operational technologies, and hardware infrastructure. Precise identification and classification of assets is therefore crucial; without it, it is not possible to deploy appropriate measures. Official recommendations call for this and require an overview of what the organization has, where it is located, and the significance of these items.
Statistics indicate significant gaps: 82% of security professionals admit shortcomings in identifying and classifying assets. Only 29% of organizations have a complete overview of devices and systems connected to their own network, according to a survey conducted in Germany. Experience from practice confirms that in ransomware incidents up to 80% of affected companies did not have all key assets properly mapped before the attack. Every step toward a better inventory therefore directly increases resilience to attacks.
Multilayer and multivendor defense in practice
A typical composition of layers includes perimeter protection between the internet and the internal network, network protection, endpoint protection, the application layer, and data protection. Antivirus is a given today, but EDR/XDR solutions capable of capturing more steps of an attack are more effective. If one technology fails, other layers increase the chance of stopping the attack or at least slowing its progress. This allows companies to build security gradually, according to current priorities and budget.
An important principle is to avoid dependence on a single vendor: a multivendor strategy brings redundancy and a lower risk of a single solution failing. This approach is also supported by regulatory trends, for example the European DORA, which demands greater resilience from financial institutions and limits vendor lock-in. A practical example is Slovanet’s Savelink portfolio, assembled into five logical layers according to international standards. According to Slovanet, the company positions itself as the first Slovak integrator to have implemented this concept comprehensively in its cybersecurity solutions offering.