Quick answer: Static security layers create a false sense of security. Defence-in-depth has to keep moving, built once and left alone, it fails quietly, and Manunta's security theory explains why dynamic, iterative principles matter.
Originally published on LinkedIn: 28 May 2026.
Defence-in-depth is frequently built once, signed off, and left alone. That is precisely how it fails. Effective layered security has to be treated as a dynamic, iterative system, not a static checklist.
Manunta's security theory as the foundation
Manunta's security theory frames security as a function of asset, protector and threat interacting over time, not a fixed state. Defence-in-depth models that ignore this relational, time-based nature drift out of alignment with the actual threat environment.
A nested hierarchy, not a flat stack of layers
Effective layered defence works as a nested hierarchy, where each layer's assumptions depend on the layers around it, rather than a flat stack of independent controls that can be assessed in isolation.
The observer effect of static defences
Static, well-known defensive layers change adversary behaviour simply by existing, an observer effect that shifts the threat rather than removing it. A defence-in-depth model that does not account for this will look effective on paper while adversaries route around it in practice.
An iterative think, validate, rethink cycle
The organisations getting genuine value from defence-in-depth run a continuous think, validate, rethink cycle rather than a set-and-forget deployment. Assumptions get tested against real incidents and adjusted, on a cadence, not just after a breach.
If your defence-in-depth model has not been re-validated against current threat behaviour in the last twelve months, it is due. Happy to talk through what that review should look like for your environment.