flevyblog

Flevy Blog is an online business magazine covering Business Strategies, Business Theories, & Business Stories.
MANAGEMENT & LEADERSHIP STRATEGY, MARKETING, SALES OPERATIONS & SUPPLY CHAIN ORGANIZATION & CHANGE IT/MIS Other

What Is a Multi-Layered Cyber Security Approach?

Editor's Note: Take a look at our featured best practice, Digital Transformation Strategy (145-slide PowerPoint presentation). Digital Transformation is being embraced by organizations across most industries, as the role of technology shifts from being a business enabler to a business driver. This has only been accelerated by the COVID-19 global pandemic. Thus, to remain competitive and outcompete in today's fast paced, [read more]

Also, if you are interested in becoming an expert on Digital Transformation, take a look at Flevy's Digital Transformation Frameworks offering here. This is a curated collection of best practice frameworks based on the thought leadership of leading consulting firms, academics, and recognized subject matter experts. By learning and applying these concepts, you can you stay ahead of the curve. Full details here.

* * * *

In a conflict, the defender never relies on a single line of defense. The human body has three—the skin, the immune cells, and white blood cells—to fight off any infectious diseases trying to enter. In risk management, businesses also employ three lines to handle the risks they’re facing now and will face in the future.

This idea rings as true in cybersecurity as anywhere else. Sensitive data should be buried under several layers of protection to make it difficult for hackers and other cybercriminals to steal it. This multi-layered approach to cybersecurity can form a strong deterrent against even the most potent attacks. Here’s an in-depth look at this strategy.

The Open Systems Interconnection Model

This approach isn’t anything new. The industry had the idea as early as the 1970s when it made the Open Systems Interconnection (OSI) model. Defined under ISO/IEC 7498, the OSI model consists of seven layers, divided between the host and media layer categories.

  • 7th layer – Application: Application Process Interface (API) or the app itself
  • 6th layer – Presentation: Encryption/decryption protocols, data compression
  • 5th layer – Session: Managing data exchanges and communications
  • 4th layer – Transport: Transmission techniques like segmentation or multiplexing
  • 3rd layer – Network: Structuring and managing data network paths
  • 2nd layer – Data Link: Media access control (MAC) and logical link control (LLC)
  • 1st layer – Physical: Transmission of unstructured data

Being a model that remains a globally-recognized standard 50 years after its inception means it’s still doing its job well. However, as most experts in cybersecurity Boston that businesses trust say, it can no longer stand alone today. Cyberattacks have grown more sophisticated through the years, and the OSI model in its current form won’t be able to fend them all off.

The Human Factor

Cybercriminals sometimes don’t even have to launch state-of-the-art attacks; instead, they can fool an employee into granting them access. The “Nigerian prince,” arguably one of the oldest deception methods in the book, continues to rake in hundreds of thousands from unsuspecting people every year. All hackers need to pull this off is a formal-looking email.

Industry experts agree that the human factor is the weakest link in any cybersecurity structure. Getting scammed is just the tip of the iceberg; the problem extends to a lack of IT training and understaffed and overworked IT teams, among others. The latest data shows that human error accounts for average losses of upwards of USD$3.33 million.

Conversely, experts concur that the human factor can be vital in a multi-layered cybersecurity approach. The innate ability to understand context can mean a lot in discerning fake messages from the real ones, preventing anyone from triggering its compromising content.

Upon taking the human factor into account, the multi-layered cybersecurity approach consists of seven layers. From the forefront, the layers include:

  • Human Layer – understanding human behavior, habits, and communication patterns
  • Perimeter Layer – physical and electronic security measures for guarding the premises
  • Network Layer – regulating access to the infrastructure’s network and databases
  • Endpoint Layer – protection of the data link between the mainframe and the devices
  • Application Layer – managing access to in-house apps and their access to data
  • Data Layer – security of data transfer and storage systems
  • Mission Critical Layer – the actual data under this protective umbrella

Some industry professionals refer to multi-layered cybersecurity by another name: defense-in-depth. It forms one of three foundations of cybersecurity risk management alongside security by design and zero-trust architecture. Redundant protective systems can make hacking require more resources than what hackers have at their disposal.

Digging In

Building this cybersecurity fortress will take time and resources. The good news is not all kinds of data need this much security (though still welcome), so businesses can save money in that regard. As such, the first step involves a clear picture of the workplace and its needs in the current economy.

For this, a business will need a motherload of data on the workplace’s current cybersecurity infrastructure. Gather information on unusual traffic sources, firewall and software versions, office ground rules, and others. Being aware of existing laws on cybersecurity compliance can also be helpful.

Once a full audit is complete, the next step is implementing as many changes to the cybersecurity infrastructure as possible. Aside from installing up-to-date cybersecurity hardware and software, experts believe it pays to promote a ‘rugged culture of security.’ Rather than reacting to threats as they arrive, the workplace must be aware that it’s not entirely secure—no infrastructure is.

Conclusion

A multi-layered cybersecurity approach combines humans and technology to create a defense-in-depth against sophisticated threats. Neither factor can stand alone in the face of hackers growing more intelligent and having greater access to the tools of their trade.

87-slide PowerPoint presentation
Securing the Path to Digital Transformation In today's hyperconnected landscape, digital transformation stands as the linchpin of strategic success for organizations striving to maintain competitiveness and operational excellence. The advent of cutting-edge technologies like cloud computing, [read more]

Want to Achieve Excellence in Digital Transformation?

Gain the knowledge and develop the expertise to become an expert in Digital Transformation. Our frameworks are based on the thought leadership of leading consulting firms, academics, and recognized subject matter experts. Click here for full details.

Digital Transformation is being embraced by organizations of all sizes across most industries. In the Digital Age today, technology creates new opportunities and fundamentally transforms businesses in all aspects—operations, business models, strategies. It not only enables the business, but also drives its growth and can be a source of Competitive Advantage.

For many industries, COVID-19 has accelerated the timeline for Digital Transformation Programs by multiple years. Digital Transformation has become a necessity. Now, to survive in the Low Touch Economy—characterized by social distancing and a minimization of in-person activities—organizations must go digital. This includes offering digital solutions for both employees (e.g. Remote Work, Virtual Teams, Enterprise Cloud, etc.) and customers (e.g. E-commerce, Social Media, Mobile Apps, etc.).

Learn about our Digital Transformation Best Practice Frameworks here.

Readers of This Article Are Interested in These Resources


18-page Word document
This Word Document provides a template for an IT Security & Governance Policy and is easily customisable. Areas cover are: Security, Data Back-Up, Virus Protection, Internet & Email usage, Remote & 3rd Party Network Access, User-Account Management, Procurement, Asset Management and IS Service [read more]


 
Excel workbook
 
 
23-slide PowerPoint presentation

About Shane Avron

Shane Avron is a freelance writer, specializing in business, general management, enterprise software, and digital technologies. In addition to Flevy, Shane's articles have appeared in Huffington Post, Forbes Magazine, among other business journals.


Complimentary Business Training Guides


Many companies develop robust strategies, but struggle with operationalizing their strategies into implementable steps. This presentation from flevy introduces 12 powerful business frameworks spanning both Strategy Development and Strategy Execution. [Learn more]

  This 48-page whitepaper, authored by consultancy Envisioning, provides the frameworks, tools, and insights needed to manage serious Change—under the backdrop of the business lifecycle. These lifecycle stages are each marked by distinct attributes, challenges, and behaviors. [Learn more]

We've developed a very comprehensive collection of Strategy & Transformation PowerPoint templates for you to use in your own business presentations, spanning topics from Growth Strategy to Brand Development to Innovation to Customer Experience to Strategic Management. [Learn more]

  We have compiled a collection of 10 Lean Six Sigma templates (Excel) and Operational Excellence guides (PowerPoint) by a multitude of LSS experts. These tools cover topics including 8 Disciplines (8D), 5 Why's, 7 Wastes, Value Stream Mapping (VSM), and DMAIC. [Learn more]
Recent Articles by Corporate Function

  

  

  

  

  

The Flevy Business Blog (https://flevy.com/blog) is a leading source of information on business strategies, business theories, and business stories. Most of our articles are authored by management consultants and industry executives with over 20 years of experience.

Flevy (https://flevy.com) is the marketplace for business best practices, such as management frameworks, presentation templates, and financial models. Our best practice documents are of the same caliber as those produced by top-tier consulting firms (like McKinsey, Bain, Accenture, BCG, and Deloitte) and used by Fortune 100 organizations. Learn more about Flevy here.
  


OUR CORE OFFERINGS
Flevy Marketplace: Top 100
· Strategy & Transformation
· Digital Transformation
· Operational Excellence
· Organization & Change
· Financial Models
· Consulting Frameworks
· PowerPoint Templates
FlevyPro (Subscription Service)
KPI Library
Streams (Functional Bundles)
Flevy Executive Learning (FEL)
PowerPoint Services

FREE Resources

About Flevy
Management Topics
Marcus (AI-Powered Consultant)
Partner Program
LinkedIn Influencer Marketing
FAQ / Terms / Privacy / Blog
Contact Us: support@flevy.com



CONNECT WITH US!
       
TOP 100 TRENDING TOPICS
Acquisition Strategy
Agile
Analytics
Artificial Intelligence
Balanced Scorecard
Best Practices
Big Data
Breakout Strategy
Business Continuity Planning
Business Plan Financial Model
Business Transformation
CMMI
COBIT
Change Management
Cloud
Communications Strategy
Company Financial Model
Competitive Advantage
Competitive Analysis
Consulting Frameworks
Continuous Improvement
Core Competencies
Corporate Culture
Cost Reduction Assessment
Customer Experience

BROWSE BY FUNCTION
Strategy, Transformation, & Innovation
Digital Transformation
Operational Excellence and LSS
Organization, Change, & HR
Management Consulting

Customer Journey
Customer Service
Cyber Security
Data Privacy
Decision Making
Digital Marketing Strategy
Digital Transformation
Digital Transformation Strategy
Due Diligence
ESG
Employee Engagement
Employee Training
Enterprise Architecture
Growth Strategy
HR Strategy
Hiring
Hoshin Kanri
ISO 27001
ITIL
Information Technology
Innovation Management
Integrated Financial Model
Kaizen
Kanban
Key Performance Indicators

ADDITIONAL RESOURCES
Business Strategy Frameworks
Case Studies
Consulting Training Guides
COVID-19 Trend Data
Digital Transformation
Financial Advising Services (FAS)

Knowledge Management
Leadership
Lean
Lean Manufacturing
Logistics
M&A (Mergers & Acquisitions)
Manufacturing
Market Research
Marketing Plan Development
Maturity Model
McKinsey PowerPoint
McKinsey Templates
Operational Excellence
Organizational Change
Organizational Design
Performance Management
Post-merger Integration
Pricing Strategy
Process Improvement
Process Maps
Procurement Strategy
Product Launch Strategy
Product Strategy
Project Management
Quality Management


Free Resources
KPI Library
Lean Management
Lean Six Sigma Training Guides
Marcus Insights
Operational Excellence

Real Estate
Remote Work
Restructuring
Risk Management
Robotic Process Automation
SWOT
SaaS
Sales
Scrum
Service Design
Six Sigma Project
Social Media Strategy
Strategic Planning
Strategic Thinking
Strategy Development
Supply Chain Analysis
Sustainability
Target Operating Model
Team Management
Total Productive Maintenance
Value Chain Analysis
Value Creation
Value Stream Mapping
Visual Workplace
Workplace Safety


Product Strategy
Small Business Owner
Startup Resources
Strategic Planning
Strategic Planning Process
Value Innovation Strategy


© 2012-2024 Copyright. Flevy LLC. All Rights Reserved.