Defence in Depth
Defence in depth is a security strategy that protects industrial and IT systems with multiple independent layers of controls, so that the failure or bypass of one layer does not leave critical assets exposed.
Defence in depth is a security strategy that uses multiple, independent layers of protection so that if one control fails or is bypassed, others still prevent or limit harm. In industrial environments the layers typically include security policies and training, physical security, network segmentation and firewalls, secure remote access, hardened hosts and controllers, application allowlisting, account and access management, monitoring and incident response, and backup and recovery.
No single control can protect an industrial control system, because OT environments contain legacy devices, insecure protocols and many trusted users and suppliers. Defence in depth is a foundational principle of IEC 62443 and NIST SP 800-82, and it mirrors the layered approach long used in process safety, where independent protection layers prevent a single failure from causing a hazardous event.
Layers should be genuinely independent, so that one compromised credential or vulnerability does not defeat several at once. Detection and recovery matter as much as prevention, because some attacks will succeed. Effectiveness is assessed through risk assessments, penetration tests and exercises, and the strategy should be reviewed as connectivity changes, for example when cloud services or remote access are introduced.
Key points
- Combines physical, network, host, application, procedural and recovery controls
- A foundational principle of IEC 62443 and NIST SP 800-82
- Mirrors the independent protection layers used in process safety
- Layers must be independent so one failure does not defeat several
Where AiVibe comes in
In AiVibe's AiAmbA AI Factory, the AiAmbA IoT edge layer keeps writes to machines deny-by-default and AI agents only propose changes that a trained operator confirms. AiVibe's security services include vulnerability assessment and penetration testing, and AiVibe is ISO/IEC 27001:2022 certified.
Related terms
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- OT Network SegmentationOT & Industrial Cybersecurity
- Application AllowlistingOT & Industrial Cybersecurity
- NIST SP 800-82OT & Industrial Cybersecurity
- Zero Trust Architecture (ZTA)Cybersecurity & Compliance
- Safety and Security InterplayOT & Industrial Cybersecurity