Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Defense in depth

Also known as: Layered security, Defence in depth

German: Tiefenverteidigung

In cybersecurity, defense in depth is the strategy of protecting a system with several independent layers of security measures, so that the failure or bypass of one layer does not leave the system unprotected. In OT it combines physical, network, host, application and organizational measures.

  • OT security
  • Standards

In one sentence

Defense in depth protects a system with several independent security layers so the failure of one layer does not leave it exposed.

Example

A robot cell is protected by a locked cabinet, a zone firewall, disabled unused services on the controller, individual user accounts and monitoring of network traffic.

How it applies

  • Engineering: IEC 62443 builds on defense in depth: the Zone and conduit model segments the network, components are hardened, access is controlled and events are monitored. No single product, such as a Firewall, is expected to provide security alone.
  • Operation: Layers need maintenance. A firewall rule opened temporarily for commissioning and never closed silently removes one layer.
  • Product development: IEC 62443-4-1 expects suppliers to describe the defense-in-depth strategy their product is designed for, including which threats the environment must mitigate.
  • Documentation: Security guidelines in the product documentation should describe the assumed layers around the product (for example "operate only inside a protected zone") so that integrators do not rely on the product alone.

Defense in depth vs. layers of protection in safety

The idea resembles layers of protection in process safety, where independent protection layers reduce risk. The layers of defense in depth address intentional attacks and are assessed differently; they do not replace safety functions or Safeguard measures.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on IEC 62443 and industrial cybersecurity practice

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!