Definition · External Attack Surface Management

What is Defence in Depth?

Defence in depth means not relying on one control to hold. Layers are arranged so that an attacker who defeats one still faces another, and so that a control failing quietly — a misconfiguration, an unpatched flaw, a credential that leaked — does not translate directly into compromise. The idea is old and borrowed from military thinking, but its security value is specific: it buys detection time and limits blast radius when something inevitably fails.

Layering at the perimeter

A single internet-facing web application illustrates the pattern. The boundary limits which TCP ports are reachable. TLS with a valid certificate protects the transport. Authentication with multi-factor sits in front of privileged functions. Browser-side controls such as CSP, HSTS and X-Frame-Options contain the effect of an injection or framing attack. Patch management removes known flaws in the stack. Logging and monitoring make an attempt visible.

None of these is sufficient alone. CSP does not stop an unpatched server being exploited; patching does not stop stolen credentials being used.

Where the idea gets misapplied

Layers only count if they fail independently. Three controls administered through the same interface, protected by the same credential, or hosted on the same unpatched appliance are closer to one control with extra configuration. Depth is also not a substitute for removing exposure: layering protections around a service that never needed to be internet-facing is more expensive and less reliable than attack surface reduction.

The other common failure is uneven application. Layers are applied to the assets a team knows about, so shadow IT and forgotten hosts end up as the thin part of the wall.

See least privilege and network segmentation for containing movement after a breach, and MITRE ATT&CK for mapping which layers cover which attacker techniques. Frameworks including ISO 27001 and CIS Benchmarks encode the principle in their control sets.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.