Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Why do defence in depth and best practices…
Cyber Security

Why do defence in depth and best practices still leave organizations exposed to attack paths?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Cyber Security

Defence in depth reduces risk, but it does not eliminate misconfigurations, shadow IT, weak awareness, or gaps between tools and processes. Attackers often exploit legitimate behavior and trusted tooling rather than obvious malware alone. That is why teams need testing that models real attack chains and shows whether security layers work together as intended instead of assuming each control is sufficient on its own.

Why Defence in Depth Still Leaves Attack Paths

Defence in depth lowers the odds of a successful compromise, but it rarely removes every path an attacker can use. The gap appears when one layer is bypassed, when a control is deployed unevenly, or when trusted behaviour, integrations, and exceptions are not covered by the same scrutiny as the “main” security stack. That is why a layered design can be sound and still leave exploitable routes.

In practice, the residual risk is often not a missing product, but a mismatch between how systems are protected and how they are actually used. Attack paths emerge across people, process, configuration, and dependency boundaries, especially where legitimate access, automation, or third-party connectivity is treated as safe by default.

Where the Gaps Usually Form

Most organisations do not get caught by a single weak control. They get caught by combinations: a permissive setting, a stale exception, an overlooked asset, a shadow workflow, or a trusted tool that can be abused without tripping obvious malware alarms. That is why the weakest point is often not the deepest technical layer, but the handoff between layers.

  • Misconfigurations can expose data or control planes even when preventive controls exist.
  • Shadow IT and unsanctioned integrations create unreviewed trust paths.
  • Weak user awareness and overbroad trust let attackers operate through valid actions.
  • Tool-to-tool gaps appear when logging, identity checks, or approval workflows do not line up.

That pattern is visible in exposed secrets and compromised machine identities, where legitimate tokens, API keys, or service accounts are used as access paths rather than “malware” in the traditional sense. NHIMG’s Ultimate Guide to Non-Human Identities is a useful reference point here, especially where secrets sprawl, overprivilege, and lifecycle gaps create reachable attack surfaces.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS Control 4 — Secure Configuration of Enterprise Assets and SoftwareMisconfigurations are a common seam in defence in depth.
CIS Control 6 — Access Control ManagementAttackers often abuse trusted access paths and overbroad permissions.
CIS Control 8 — Audit Log ManagementLayered defence fails when abuse of legitimate behaviour is not visible.
Recommendation — Harden and continuously validate configurations to close easy attack paths. Restrict and review access paths so legitimate use does not become an attack route. Centralise and retain logs so multi-step attack chains can be detected.
NIST CSF 2.0PR.AC — Access ControlResidual paths persist when access is broader than intended across systems.
DE.CM — Continuous MonitoringTesting must show whether layers work together, not in isolation.
ID.IM — ImprovementsGaps between tools and processes require iterative control improvement.
Recommendation — Enforce access boundaries that match real operational use, not just policy. Monitor control interactions continuously to surface chained abuse early. Use findings from attack-path testing to drive prioritized control improvements.
OWASP Non-Human Identity Top 10NHI-01 — Secrets ExposureExposed secrets create real attack paths through trusted credentials.
NHI-04 — Overprivileged AccessLayered security still fails when machine identities have excessive privilege.
NHI-08 — Third-Party and Supply-Chain ExposureTrusted integrations and external tooling often form the hidden path.
Recommendation — Find and eliminate exposed secrets before attackers can reuse them. Reduce non-human privileges so one compromise cannot traverse multiple layers. Review third-party access and dependencies as part of attack-path testing.
MITRE ATT&CKT1078 — Valid AccountsAttackers commonly exploit legitimate behaviour rather than obvious malware.
Recommendation — Hunt for abnormal use of valid accounts and sessions across the kill chain.

Practitioner Guidance

What to verify: Treat each control as a hypothesis, not a guarantee. Verify whether your preventive, detective, and response layers actually work together on the same asset, the same identity, and the same path from initial access to impact.

Decision rule: If a workflow, token, admin path, or trust relationship can be used by a real operator, a script, or a third party, assume an attacker will try to blend into it. Prioritise chain testing over single-control validation, because isolated checks often miss the exact sequence that makes compromise possible.

What practitioners underestimate: Best practices usually describe what should exist; they do not prove that exceptions, legacy access, and operational shortcuts are still bounded. The practical question is whether the organisation can detect and interrupt abuse of legitimate behaviour before that behaviour becomes a full attack chain.

Practitioner takeaway: Defence in depth is strongest when it is tested as a connected system, because attackers look for the seams between controls, not the controls in isolation.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org