MODELS
← Browse the encyclopedia

Encyclopedia · Free preview

Risk Layering (Multiple Defenses)

The defense-in-depth principle that no single risk mitigation is reliable enough on its own—effective risk management uses multiple independent layers, each catching what the others miss. Swiss cheese model (James Reason): each defense layer has holes, but if the layers are independent, the probability of holes aligning (allowing failure through all layers simultaneously) is extremely low. Aviation safety, cybersecurity, and nuclear plant design all use risk layering—no single control is perfect, but the combined system is robust.

When to use it

When failure would have severe or irreversible consequences; when designing safety-critical systems; when a single point of failure could cascade; when evaluating whether current risk management has genuine redundancy or just the appearance of it.

How it can help

For any critical risk, never rely on a single control. Layer multiple independent defenses: a prevention layer (stop it from happening), a detection layer (catch it quickly if prevention fails), a mitigation layer (limit damage if detection fails), and a recovery layer (restore function after damage). In business: don't rely solely on insurance, solely on prevention, or solely on backup plans—layer all of them. The independence criterion is crucial: if layers share a common failure mode, they're not truly independent and will fail simultaneously.

Keep exploring

Read the full page.

Create your free access to continue reading and explore the complete library.

Register free with ChatGPT →

Already registered? Use the same button to sign in.

Sign-in shares your email with Michael Simmons to create your site access. No payment required. Newsletter signup is separate. How your data is used