White Rock Advisory

· Cyber Resilience  · 5 min read

Defending a Castle: Why Small Businesses Need Layers of Cyber Defence

Cyber resilience is much like defending a medieval castle. No single control can stop every threat, but layers of protection working together can dramatically reduce risk and improve resilience.

Cyber resilience is much like defending a medieval castle. No single control can stop every threat, but layers of protection working together can dramatically reduce risk and improve resilience.

Introduction

Imagine approaching a medieval castle. Before reaching the main gate, you would likely encounter a moat, towering walls, watchtowers, guards, reinforced gates and heavily protected inner chambers. Each layer serves a purpose. No single defence guarantees protection, but together they make attack significantly more difficult.

Cyber resilience works in exactly the same way.

Many organisations mistakenly look for a single product or solution that will keep them safe. In reality, resilience is built through multiple layers of protection working together. The principle has remained unchanged for centuries:

Strong defence relies on layers, not luck.

The Moat: Your First Line of Defence

The moat was designed to keep most attackers away from the castle before they reached the walls. In the modern world, this role is often performed by:

  • Firewalls
  • Secure internet gateways
  • Network filtering
  • Web protection services

These controls help reduce exposure to unwanted traffic and block many threats before they reach organisational systems. They do not stop everything, but they make access more difficult.

The Guards at the Gate

When visitors approached a castle, they were challenged before entry was granted. They had to prove who they were. Cyber resilience follows the same principle through authentication. Usernames and passwords provide the first layer of identity verification. However, passwords alone are no longer enough. Modern organisations should strengthen authentication through:

  • Multi-factor authentication (MFA)
  • Two-step verification (2SV)
  • Strong passphrases
  • Secure identity management

The goal is simple: ensure only authorised individuals gain access.

The Royal Seal: Protecting Trust

Throughout history, royal seals and official markings helped confirm authenticity. Today, organisations face a similar challenge with email and online communications. Cyber criminals frequently impersonate trusted brands, suppliers and colleagues. Controls such as:

  • SPF
  • DKIM
  • DMARC

help verify that emails genuinely come from authorised sources. These protections strengthen trust and reduce opportunities for fraud and impersonation.

Guards Inside the Walls

Even after entering a castle, visitors could not simply wander wherever they wished. Access was controlled. The same principle applies to modern organisations. Not everyone needs access to everything. Good cyber resilience includes:

  • User access controls
  • Role-based permissions
  • Least-privilege access
  • Zero Trust principles

Limiting access reduces the potential impact of both mistakes and malicious activity.

The Watchtowers

Castles relied on lookouts to spot danger early. The sooner a threat was identified, the more time defenders had to respond. Modern organisations require similar visibility. Examples include:

  • Security monitoring
  • Threat detection tools
  • System alerts
  • Log monitoring
  • Suspicious activity notifications

Early detection often makes the difference between a minor issue and a major incident.

The Crown Jewels

Every castle protected something valuable. For organisations, these assets may include:

  • Customer information
  • Financial records
  • Intellectual property
  • Operational systems
  • Business-critical data

Protecting these assets should always be a priority. This includes:

  • Data backups
  • Encryption
  • Secure storage
  • Recovery planning

If an incident occurs, organisations must be able to recover quickly.

The Foundations of Cyber Resilience

Many of the controls above align closely with the principles of Cyber Essentials. Five key foundations include:

Firewalls and Internet Gateways

Protecting the perimeter from unwanted access.

Secure Configuration

Removing unnecessary services, accounts and settings that create risk.

User Access Control

Ensuring people only have access to what they genuinely need.

Malware Protection

Identifying and preventing malicious software from causing harm.

Patch Management

Keeping systems updated to address known vulnerabilities. Together, these measures significantly reduce exposure to common cyber threats.

Going Beyond the Basics

While foundational controls are essential, organisations should also consider additional layers of resilience.

Brand Protection

Your brand is one of your most valuable assets. Criminals may attempt to impersonate your organisation through:

  • Fake websites
  • Spoofed emails
  • Fraudulent social media accounts

Protecting your digital identity helps protect customer trust.

Strong Passwords and Authentication

A strong passphrase remains one of the simplest and most effective security measures. Consider using three random words and enabling multi-factor authentication wherever possible.

Staff Awareness

Even the strongest technical controls can be undermined by human error. Practical awareness training helps staff:

  • Recognise phishing attempts
  • Report suspicious activity
  • Understand their role in protecting the organisation

Well-informed staff become an additional layer of defence.

Exercising and Preparedness

The strongest castles regularly prepared for attack. Organisations should do the same. Incident response exercises and tabletop discussions help teams understand:

  • Roles and responsibilities
  • Communication procedures
  • Recovery priorities
  • Decision-making processes

Preparation improves confidence and reduces disruption during real incidents.

Practical Recommendations

  • Implement the Cyber Essentials controls as a minimum baseline.
  • Enable multi-factor authentication on critical accounts.
  • Use strong passphrases rather than simple passwords.
  • Keep systems, software and websites updated.
  • Back up important data and test recovery procedures.
  • Review user access permissions regularly.
  • Monitor for suspicious activity and unusual behaviour.
  • Protect your brand through email authentication controls.
  • Deliver regular cyber awareness training.
  • Practise your response to cyber incidents before they happen.

Final Thought

The strongest castles in history survived because they relied on multiple layers of defence. Cyber resilience is no different. No single control will stop every threat. However, when firewalls, authentication, monitoring, backups, awareness and good governance work together, organisations become far harder targets. The objective is not simply to keep attackers out. It is to ensure that if one layer fails, others remain in place to protect what matters most.

Resilience is built layer by layer, and just like a castle, the stronger the foundations, the stronger the defence.


About the Author

Chris White is a cyber resilience consultant, speaker and former senior police officer with more than 30 years of experience across technology, cyber crime, fraud prevention and organisational resilience.

Through White Rock Advisory, Chris helps organisations understand risk, strengthen resilience and take practical steps to reduce avoidable harm.


Need Support?

Whether you are starting your Cyber Essentials journey, reviewing your cyber resilience or looking to strengthen the layers protecting your organisation, White Rock Advisory provides practical guidance backed by real-world experience.

Contact Us

Back to Blog
Chat on WhatsApp