Skip to Content

Security Risk Management & Defence-in-Depth: Dynamic Foundations and Iterative Principles

Static layers create a false sense of security. Defence-in-depth has to keep moving
22 July 2026 by
Quick answer: Static security layers create a false sense of security. Defence-in-depth has to keep moving, built once and left alone, it fails quietly, and Manunta's security theory explains why dynamic, iterative principles matter.

Originally published on LinkedIn: 28 May 2026.

Defence-in-depth is frequently built once, signed off, and left alone. That is precisely how it fails. Effective layered security has to be treated as a dynamic, iterative system, not a static checklist.

Manunta's security theory as the foundation

Manunta's security theory frames security as a function of asset, protector and threat interacting over time, not a fixed state. Defence-in-depth models that ignore this relational, time-based nature drift out of alignment with the actual threat environment.

A nested hierarchy, not a flat stack of layers

Effective layered defence works as a nested hierarchy, where each layer's assumptions depend on the layers around it, rather than a flat stack of independent controls that can be assessed in isolation.

The observer effect of static defences

Static, well-known defensive layers change adversary behaviour simply by existing, an observer effect that shifts the threat rather than removing it. A defence-in-depth model that does not account for this will look effective on paper while adversaries route around it in practice.

An iterative think, validate, rethink cycle

The organisations getting genuine value from defence-in-depth run a continuous think, validate, rethink cycle rather than a set-and-forget deployment. Assumptions get tested against real incidents and adjusted, on a cadence, not just after a breach.

If your defence-in-depth model has not been re-validated against current threat behaviour in the last twelve months, it is due. Happy to talk through what that review should look like for your environment.

Risk, Safety, Security, Resilience, Management: One Field, Five Lenses
Opening a new writing programme built on a shared framework library