Defence in depth reduces risk, but it does not eliminate misconfigurations, shadow IT, weak awareness, or gaps between tools and processes. Attackers often exploit legitimate behavior and trusted tooling rather than obvious malware alone. That is why teams need testing that models real attack chains and shows whether security layers work together as intended instead of assuming each control is sufficient on its own.
Why Defence in Depth Still Leaves Attack Paths
Defence in depth lowers the odds of a successful compromise, but it rarely removes every path an attacker can use. The gap appears when one layer is bypassed, when a control is deployed unevenly, or when trusted behaviour, integrations, and exceptions are not covered by the same scrutiny as the “main” security stack. That is why a layered design can be sound and still leave exploitable routes.
In practice, the residual risk is often not a missing product, but a mismatch between how systems are protected and how they are actually used. Attack paths emerge across people, process, configuration, and dependency boundaries, especially where legitimate access, automation, or third-party connectivity is treated as safe by default.
Where the Gaps Usually Form
Most organisations do not get caught by a single weak control. They get caught by combinations: a permissive setting, a stale exception, an overlooked asset, a shadow workflow, or a trusted tool that can be abused without tripping obvious malware alarms. That is why the weakest point is often not the deepest technical layer, but the handoff between layers.
- Misconfigurations can expose data or control planes even when preventive controls exist.
- Shadow IT and unsanctioned integrations create unreviewed trust paths.
- Weak user awareness and overbroad trust let attackers operate through valid actions.
- Tool-to-tool gaps appear when logging, identity checks, or approval workflows do not line up.
That pattern is visible in exposed secrets and compromised machine identities, where legitimate tokens, API keys, or service accounts are used as access paths rather than “malware” in the traditional sense. NHIMG’s Ultimate Guide to Non-Human Identities is a useful reference point here, especially where secrets sprawl, overprivilege, and lifecycle gaps create reachable attack surfaces.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS Control 4 — Secure Configuration of Enterprise Assets and Software | Misconfigurations are a common seam in defence in depth. |
| CIS Control 6 — Access Control Management | Attackers often abuse trusted access paths and overbroad permissions. | |
| CIS Control 8 — Audit Log Management | Layered defence fails when abuse of legitimate behaviour is not visible. | |
| Recommendation — Harden and continuously validate configurations to close easy attack paths. Restrict and review access paths so legitimate use does not become an attack route. Centralise and retain logs so multi-step attack chains can be detected. | ||
| NIST CSF 2.0 | PR.AC — Access Control | Residual paths persist when access is broader than intended across systems. |
| DE.CM — Continuous Monitoring | Testing must show whether layers work together, not in isolation. | |
| ID.IM — Improvements | Gaps between tools and processes require iterative control improvement. | |
| Recommendation — Enforce access boundaries that match real operational use, not just policy. Monitor control interactions continuously to surface chained abuse early. Use findings from attack-path testing to drive prioritized control improvements. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets Exposure | Exposed secrets create real attack paths through trusted credentials. |
| NHI-04 — Overprivileged Access | Layered security still fails when machine identities have excessive privilege. | |
| NHI-08 — Third-Party and Supply-Chain Exposure | Trusted integrations and external tooling often form the hidden path. | |
| Recommendation — Find and eliminate exposed secrets before attackers can reuse them. Reduce non-human privileges so one compromise cannot traverse multiple layers. Review third-party access and dependencies as part of attack-path testing. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Attackers commonly exploit legitimate behaviour rather than obvious malware. |
| Recommendation — Hunt for abnormal use of valid accounts and sessions across the kill chain. | ||
Practitioner Guidance
What to verify: Treat each control as a hypothesis, not a guarantee. Verify whether your preventive, detective, and response layers actually work together on the same asset, the same identity, and the same path from initial access to impact.
Decision rule: If a workflow, token, admin path, or trust relationship can be used by a real operator, a script, or a third party, assume an attacker will try to blend into it. Prioritise chain testing over single-control validation, because isolated checks often miss the exact sequence that makes compromise possible.
What practitioners underestimate: Best practices usually describe what should exist; they do not prove that exceptions, legacy access, and operational shortcuts are still bounded. The practical question is whether the organisation can detect and interrupt abuse of legitimate behaviour before that behaviour becomes a full attack chain.
Practitioner takeaway: Defence in depth is strongest when it is tested as a connected system, because attackers look for the seams between controls, not the controls in isolation.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org