The post-mortem pattern

Read enough breach post-mortems and a pattern appears. The organisation had the control. It had bought it, deployed it, sometimes even audited it. The attacker simply went through a different layer, one where the equivalent decision had never been made, or had been made once and never revisited.

Security is not a firewall. It is seven stacked decisions, one per layer of the network model, each with its own attack surface, its own control set and its own audit fingerprint. Miss one and the others do not compensate; they just make the miss harder to see.

Exhibit 1

The seven layers, and what each one owes you

Attack surface, control set and audit fingerprint at every layer of the OSI model. The framework references use ISO 27001:2013 Annex A numbering.

Attacks, controls and framework mapping by layer
LayerTypical attacksControlsMaps to
L7 ApplicationSQL injection, XSS, CSRF, API abuseWAF, secure coding, input validationISO A.14 · PCI Req 6 · NIST SI-10, SA-11
L6 PresentationSSL stripping, encryption downgradeTLS 1.2 or later, certificate lifecycle managementISO A.10 · PCI Req 4 · NIST SC-12, SC-13
L5 SessionSession hijacking, replaySession timeouts, token management, MFAISO A.9 · PCI Req 8 · NIST IA-2
L4 TransportSYN flood, port scanningFirewall rules, IDS and IPSISO A.13 · NIST SC-7
L3 NetworkIP spoofing, routing attacksSegmentation, access control listsISO A.13 · NIST SC-7
L2 Data linkARP spoofing, MAC floodingPort security, DHCP snoopingISO A.13 · NIST AC-4
L1 PhysicalCable tapping, hardware tamperingPhysical access control, tamper-evident hardwareISO A.11 · NIST PE family
The uncomfortable truth
  • Your WAF does not help if someone walks into the data centre with a USB stick
  • Your MFA does not help if session tokens never expire
  • Your TLS does not help if the certificate chain is not managed
The gut-check: pick one layer
  • Who owns the controls at that layer?
  • When were they last tested end to end, not just scanned?
  • If that layer failed tomorrow, which business process stops?
Defence in depth is not a slogan. It is seven audits.Rhinexa Perspective · Krishna Mohan Parsha
Exhibit 1. Defence in depth as seven audits. Download it as an image for your own board pack.

Layer by layer

L7

ApplicationSQL injection, cross-site scripting, CSRF and API abuse, met by a web application firewall, secure coding and input validation. ISO A.14, PCI DSS requirement 6, NIST SI-10 and SA-11.

L6

PresentationSSL stripping and encryption downgrade, met by TLS 1.2 or later and certificate lifecycle management. ISO A.10, PCI requirement 4, NIST SC-12 and SC-13.

L5

SessionSession hijacking and replay, met by session timeouts, token management and MFA. ISO A.9, PCI requirement 8, NIST IA-2.

L4

TransportSYN floods and port scanning, met by firewall rules and intrusion detection and prevention. ISO A.13, NIST SC-7.

L3

NetworkIP spoofing and routing attacks, met by segmentation and access control lists. ISO A.13, NIST SC-7.

L2

Data linkARP spoofing and MAC flooding, met by port security and DHCP snooping. ISO A.13, NIST AC-4.

L1

PhysicalCable tapping and hardware tampering, met by physical access control and tamper-evident hardware. ISO A.11, the NIST PE family.

The ISO references use the 2013 Annex A numbering that most Indian certifications still cite in their statements of applicability. The 2022 edition regroups the same controls into four themes; the intent at each layer is unchanged.

The uncomfortable truth

  • Your WAF does not help if someone walks into the data centre with a USB stick.
  • Your MFA does not help if session tokens never expire.
  • Your TLS does not help if the certificate chain is not managed.

Defence in depth is not a slogan. It is seven audits.

A gut-check

Pick one layer. Just one. Now answer three questions. Who owns the controls at that layer? When were they last tested end to end, not just scanned? If that layer failed tomorrow, which business process stops?

If you paused on any of the three, that is your weakest layer. Not the one with the fewest tools. The one with the least clarity.

Where to begin

Run the gut-check for all seven layers with the people who actually operate them, in one room, in one afternoon. Write down the owner, the last end-to-end test and the dependent business process for each. The blanks on that page are the programme. Then fund the layer with the least clarity first, not the layer with the most vendors.

So, which layer is your programme under-investing in?

Krishna Mohan Parsha

CTO and Co-Founder, Rhinexa

Krishna works at the intersection of cyber security, infrastructure, AI and enterprise risk, with a focus on engineering trustworthy and resilient technology foundations.

Follow on LinkedIn

This perspective expands a post first published by the author on LinkedIn.