{"id":11279,"date":"2022-06-29T01:01:54","date_gmt":"2022-06-29T06:01:54","guid":{"rendered":"https:\/\/flevy.com\/blog\/?p=11279"},"modified":"2022-06-28T08:42:00","modified_gmt":"2022-06-28T13:42:00","slug":"what-is-a-multi-layered-cyber-security-approach","status":"publish","type":"post","link":"https:\/\/flevy.com\/blog\/what-is-a-multi-layered-cyber-security-approach\/","title":{"rendered":"What Is a Multi-Layered Cyber Security Approach?"},"content":{"rendered":"<p><img decoding=\"async\" class=\"alignright size-medium wp-image-11280\" src=\"http:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_284764382-300x200.jpeg\" alt=\"\" width=\"300\" height=\"200\" srcset=\"https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_284764382-300x200.jpeg 300w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_284764382-1024x683.jpeg 1024w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_284764382-768x512.jpeg 768w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_284764382-1536x1025.jpeg 1536w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_284764382-2048x1366.jpeg 2048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>In a conflict, the defender never relies on a single line of defense. The human body has three\u2014the skin, the immune cells, and white blood cells\u2014to fight off any infectious diseases trying to enter. In risk management, businesses also employ three lines to handle the risks they\u2019re facing now and will face in the future.<\/p>\n<p>This idea rings as true in cybersecurity as anywhere else. Sensitive data should be buried under several layers of protection to make it difficult for hackers and other cybercriminals to steal it. This multi-layered approach to cybersecurity can form a strong deterrent against even the most potent attacks. Here\u2019s an in-depth look at this strategy.<\/p>\n<h2><strong>The Open Systems Interconnection Model<\/strong><\/h2>\n<p>This approach isn\u2019t anything new. The industry had the idea as early as the 1970s when it made the Open Systems Interconnection (OSI) model. Defined under ISO\/IEC 7498, the OSI model consists of seven layers, divided between the host and media layer categories.<\/p>\n<ul>\n<li><strong>7th layer \u2013 Application:<\/strong> Application Process Interface (API) or the app itself<\/li>\n<li><strong>6th layer \u2013 Presentation:<\/strong> Encryption\/decryption protocols, data compression<\/li>\n<li><strong>5th layer \u2013 Session:<\/strong> Managing data exchanges and communications<\/li>\n<li><strong>4th layer \u2013 Transport: <\/strong>Transmission techniques like segmentation or multiplexing<\/li>\n<li><strong>3rd layer \u2013 Network: <\/strong>Structuring and managing data network paths<\/li>\n<li><strong>2nd layer \u2013 Data Link: <\/strong>Media access control (MAC) and logical link control (LLC)<\/li>\n<li><strong>1st layer \u2013 Physical: <\/strong>Transmission of unstructured data<\/li>\n<\/ul>\n<p>Being a model that remains a globally-recognized standard 50 years after its inception means it\u2019s still doing its job well. However, as most experts in <a href=\"https:\/\/www.nens.com\/cybersecurity-services\/\">cybersecurity Boston<\/a> that businesses trust say, it can no longer stand alone today. Cyberattacks have grown more sophisticated through the years, and the OSI model in its current form won\u2019t be able to fend them all off.<\/p>\n<h2><strong>The Human Factor<\/strong><\/h2>\n<p>Cybercriminals sometimes don\u2019t even have to launch state-of-the-art attacks; instead, they can fool an employee into granting them access. The \u201cNigerian prince,\u201d arguably one of the oldest deception methods in the book, continues to rake in hundreds of thousands from unsuspecting people every year. All hackers need to pull this off is a formal-looking email.<\/p>\n<p>Industry experts agree that the human factor is the weakest link in any cybersecurity structure. Getting scammed is just the tip of the iceberg; the problem extends to a lack of IT training and understaffed and overworked IT teams, among others. The latest <a href=\"https:\/\/www.ibm.com\/security\/digital-assets\/cost-data-breach-report\/?utm_medium=OSocial&amp;utm_source=Blog&amp;utm_content=000039JJ&amp;utm_term=10013747&amp;utm_id=SI-blog-1&amp;cm_mmc=OSocial_Blog-_-Portfolio%20Security_Security%20Conversation-_-WW_WW-_-SI-blog-1_ov76748&amp;cm_mmca1=000039JJ&amp;cm_mmca2=10013747#\/\">data<\/a> shows that human error accounts for average losses of upwards of USD$3.33 million.<\/p>\n<p>Conversely, experts concur that the human factor can be vital in a multi-layered cybersecurity approach. The innate ability to understand context can mean a lot in discerning fake messages from the real ones, preventing anyone from triggering its compromising content.<\/p>\n<p>Upon taking the <a href=\"https:\/\/www.forbes.com\/sites\/phillipkeys\/2017\/11\/09\/wetware-the-often-overlooked-crucial-factor-in-cybersecurity\/?sh=56b770706a2c\">human factor<\/a> into account, the multi-layered cybersecurity approach consists of seven layers. From the forefront, the layers include:<\/p>\n<ul>\n<li><strong>Human Layer \u2013 <\/strong>understanding human behavior, habits, and communication patterns<\/li>\n<li><strong>Perimeter Layer \u2013<\/strong> physical and electronic security measures for guarding the premises<\/li>\n<li><strong>Network Layer \u2013<\/strong> regulating access to the infrastructure\u2019s network and databases<\/li>\n<li><strong>Endpoint Layer \u2013<\/strong> protection of the data link between the mainframe and the devices<\/li>\n<li><strong>Application Layer \u2013<\/strong> managing access to in-house apps and their access to data<\/li>\n<li><strong>Data Layer \u2013<\/strong> security of data transfer and storage systems<\/li>\n<li><strong>Mission Critical Layer \u2013 <\/strong>the actual data under this protective umbrella<\/li>\n<\/ul>\n<p>Some industry professionals refer to multi-layered cybersecurity by another name: defense-in-depth. It forms one of three foundations of cybersecurity risk management alongside security by design and zero-trust architecture. Redundant protective systems can make hacking require more resources than what hackers have at their disposal.<\/p>\n<h2><strong><img decoding=\"async\" class=\"alignright size-medium wp-image-11281\" src=\"http:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_393093122-300x154.jpeg\" alt=\"\" width=\"300\" height=\"154\" srcset=\"https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_393093122-300x154.jpeg 300w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_393093122-1024x526.jpeg 1024w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_393093122-768x394.jpeg 768w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_393093122-1536x788.jpeg 1536w, https:\/\/flevy.com\/blog\/wp-content\/uploads\/2022\/06\/AdobeStock_393093122-2048x1051.jpeg 2048w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/>Digging In<\/strong><\/h2>\n<p>Building this cybersecurity fortress will take time and resources. The good news is not all kinds of data need this much security (though still welcome), so businesses can save money in that regard. As such, the first step involves a clear picture of the workplace and its needs in the current economy.<\/p>\n<p>For this, a business will need a motherload of data on the workplace\u2019s current cybersecurity infrastructure. Gather information on unusual traffic sources, firewall and software versions, office ground rules, and others. Being aware of existing laws on cybersecurity compliance can also be helpful.<\/p>\n<p>Once a full audit is complete, the next step is implementing as many changes to the cybersecurity infrastructure as possible. Aside from installing up-to-date cybersecurity hardware and software, experts believe it pays to promote a \u2018<a href=\"https:\/\/flevy.com\/blog\/the-key-to-continuous-security-improvement-a-rugged-culture-of-information-security\/\">rugged culture of security<\/a>.\u2019 Rather than reacting to threats as they arrive, the workplace must be aware that it\u2019s not entirely secure\u2014no infrastructure is.<\/p>\n<h2><strong>Conclusion<\/strong><\/h2>\n<p>A multi-layered cybersecurity approach combines humans and technology to create a defense-in-depth against sophisticated threats. Neither factor can stand alone in the face of hackers growing more intelligent and having greater access to the tools of their trade.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a conflict, the defender never relies on a single line of defense. The human body has three\u2014the skin, the immune cells, and white blood cells\u2014to fight off any infectious diseases trying to enter. In risk management, businesses also employ three lines to handle the risks they\u2019re facing now and will face in the future.&hellip;&nbsp;<a href=\"https:\/\/flevy.com\/blog\/what-is-a-multi-layered-cyber-security-approach\/\" rel=\"bookmark\"><span class=\"screen-reader-text\">What Is a Multi-Layered Cyber Security Approach?<\/span><\/a><\/p>\n","protected":false},"author":17,"featured_media":11280,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-11279","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general"],"_links":{"self":[{"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/posts\/11279","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/users\/17"}],"replies":[{"embeddable":true,"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/comments?post=11279"}],"version-history":[{"count":1,"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/posts\/11279\/revisions"}],"predecessor-version":[{"id":11282,"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/posts\/11279\/revisions\/11282"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/media\/11280"}],"wp:attachment":[{"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/media?parent=11279"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/categories?post=11279"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/flevy.com\/blog\/wp-json\/wp\/v2\/tags?post=11279"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}