HACKS VITAE

TOOLS & TECH · SOURCES SHOWN

How Cybersecurity Is Built
The Layers, the Tools and Who Does What, in Plain Words

PRICES, VERSIONS AND FACTS AS OF SEPTEMBER 2026

How organisations are defended: defence in depth, the frameworks (NIST CSF 2.0, CIS Controls, ISO 27001, MITRE ATT&CK), the network, device, identity and data layers, detection and response, the people and roles, what a small organisation needs, and five myths checked.

11 SECTIONS · HOVER A POINT TO JUMP
Published
September 23, 2026
Updated
September 28, 2026
Facts as of
September 2026
Read
15 min
Sections
11

BACKGROUND · JACQUES LOUIS DAVID, ANTOINE LAURENT LAVOISIER AND MARIE ANNE LAVOISIER, 1788 · THE MET, OPEN ACCESS

THE SHORT VERSION

  1. Security is built in layers, so one failure is not the end. NIST's glossary describes layering different technologies so that attacks missed by one are caught by another.
  2. The frameworks are checklists of outcomes, not products. NIST's CSF 2.0 has six functions: Govern, Identify, Protect, Detect, Respond and Recover. Other frameworks list controls, certify management systems or map what attackers do.
  3. Several well-known facts changed in 2025 and 2026. MITRE ATT&CK now lists 15 attacker tactics, DMARC has a new standard, NIST's incident-response guide follows the CSF functions, and CISA's patch deadlines for US federal agencies are set by risk.
  4. A small organisation does not need its own security operations centre. Updates, two-step logins, offline backups and a plan for who to call come first; watching and responding can be rented. Facts here are as of September 2026.

THE ARTICLE · 15 MIN

Our cybersecurity crash course covers what one person or a small business should do. Our website security crash course covers what a site owner should do. This page explains the bigger picture: how organisations are defended, what the tools are called, and who does what. Each claim is traced to its source, mostly the US National Institute of Standards and Technology (NIST), the US Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC), MITRE and the Internet Engineering Task Force (IETF). It names no products and gives no legal advice. Versions and figures are as of September 2026.

The idea behind it all: layers

No single barrier is trusted to stop everything. Security people call this defence in depth: “layering heterogeneous security technologies in the common attack vectors to ensure that attacks missed by one technology are caught by another.” NIST’s other definition makes the point that it is not only technology but a strategy “integrating people, technology, and operations capabilities”.

The layers below — network, devices, identity, data, then detection and response, then people — are one common way to picture it, not an official list. The closest official list is CISA’s zero trust model, which has five pillars: “Identity, Devices, Networks, Applications and Workloads, and Data.”

The frameworks that organise the work

A framework is a checklist of outcomes or controls, not a product. There are four different kinds.

  • NIST Cybersecurity Framework (CSF) 2.0, dated 26 February 2024, lists outcomes and “does not prescribe how outcomes should be achieved.” Its six functions, in NIST’s words:
    • Govern: “The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored.”
    • Identify: “The organization’s current cybersecurity risks are understood.”
    • Protect: “Safeguards to manage the organization’s cybersecurity risks are used.”
    • Detect: “Possible cybersecurity attacks and compromises are found and analyzed.”
    • Respond: “Actions regarding a detected cybersecurity incident are taken.”
    • Recover: “Assets and operations affected by a cybersecurity incident are restored.”
  • CIS Critical Security Controls, version 8.1, published by the non-profit Center for Internet Security: 18 controls and “a total of 153 Safeguards”, sorted into three Implementation Groups. The first, IG1, is defined as “essential cyber hygiene,” and CIS says “Every enterprise should start with IG1.”
  • ISO/IEC 27001:2022 is a standard for running security as a managed process (an information security management system) that an organisation can be certified against by an auditor. In the 2022 edition “the controls listed in the standard have decreased from 114 to 93”, grouped into four areas: “Organizational, People, Physical and Technological.”
  • MITRE ATT&CK is not a checklist of defences but “a knowledge base of cyber adversary behavior”. It sorts attacks by tactic, the attacker’s goal (MITRE says tactics represent the “why”), and by technique, the method. Its main Enterprise matrix now lists 15 tactics, up from 14: version 19, released in April 2026, made “the split of the Defense Evasion Tactic in Enterprise ATT&CK into the Stealth and Defense Impairment Tactics”.
  • The Cyber Kill Chain, from a Lockheed Martin paper, describes an intrusion as seven ordered steps: “reconnaissance, weaponization, delivery, exploitation, installation, command and control (C2), and actions on objectives.” Its defensive point: “just one mitigation breaks the chain”. MITRE says the two models are “complementary”: “ATT&CK Tactics are unordered and may not all occur in a single intrusion”, “whereas the Cyber Kill Chain uses ordered phases”.

The network layer

Firewalls. A firewall is “a gateway that limits access between networks in accordance with local security policy.” NIST noted long ago that the traditional firewall at the edge of a network has a blind spot: “attacks sent from one internal host to another often do not pass through network firewalls.” A next-generation firewall is an industry name rather than a formally defined grade; NIST’s glossary gives it no definition, but its network guide describes the feature that sets it apart: “The distinguishing feature of NGFW is application data awareness.” In plain words, it can tell which app is talking, not just which address.

Segmentation. Instead of one big flat network, segmentation divides it “into multiple segments, each acting as its own subnetwork”, with controlled doors between them. A flat network makes it “easier for threat actors to move laterally” once they are in. Microsegmentation is the same idea at a finer grain, to “prevent attack escalation.”

VPNs and zero-trust access. A company VPN puts a remote worker on the company network, like handing them a key to the building. The newer approach grants access to one application at a time after checking who is asking and from what device. CISA and its partners urged “business owners of all sizes to move toward more robust security solutions” in June 2024, noting that CISA had found “over 22 Known Exploited Vulnerabilities (KEVs) related to VPN compromise”.

Intrusion detection and prevention. Intrusion detection is “the process of monitoring the events occurring in a computer system or network and analyzing them for signs of possible incidents”; prevention adds “attempting to stop detected possible incidents.” Neither is perfect: NIST says they all generate false alarms and misses.

Protective DNS. Every time a device looks up a web address, a protective DNS service checks it against lists of known-bad destinations and “blocks, redirects, or sinkholes the query response” if it matches. CISA runs one for US federal civilian agencies, and offers it to some critical-infrastructure organisations through a limited pilot.

Email: SPF, DKIM and DMARC. Three DNS records let receiving mail servers check whether an email that claims to come from your domain really does. SPF lets you “publish IP addresses which should be trusted for your domain”; DKIM “allows you to cryptographically sign email you send”; DMARC “allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks.” The current DMARC standard is RFC 9989, published in May 2026, which replaces RFC 7489. It is frank about its limits: “DMARC can only be used to combat specific forms of exact-domain spoofing directly.” It does not stop look-alike domain names or a fake display name.

Denial-of-service protection. A DDoS attack “is a form of DoS attack that originates from more than one source.” CISA is candid: “there is no way to completely avoid becoming a target”. Protection is mostly upstream — a provider that “detects abnormal traffic flows and redirects traffic away from your network” — plus a plan for when it happens.

The device layer

Antivirus, EDR and XDR. Antivirus is “a program that monitors a computer or network to identify all major types of malware and prevent or contain malware incidents.” EDR (endpoint detection and response) has no definition in NIST’s glossary, which lists only the abbreviation. In practice it is software on each device that records what the device does so that people can spot and investigate suspicious activity. In January 2025 CISA described its federal rollout as “over 920,000 Endpoint Detection and Response (EDR) agents across 51 agencies, enabling analysts to hunt actively for intrusions”. XDR (“extended” detection and response) is a vendor category name for extending the same idea beyond individual devices; NIST’s glossary again lists only the abbreviation.

Patching, and the list that tells you what to patch first. CISA’s Known Exploited Vulnerabilities catalogue lists flaws already used in real attacks; on 22 September 2026 it held 1,721 entries. CISA says organisations “should use the KEV catalog as an input to their vulnerability management prioritization framework.” For US federal agencies the rule changed on 10 June 2026: the old directive, BOD 22-01, “has been revoked. It is superseded by BOD 26-04”, which ties deadlines to risk — whether the device is exposed to the internet, whether the flaw is in the catalogue, whether an attacker can automate the exploit, and how much control it gives them. The deadlines in its table run from 3 days to 60 days, and to “fix on system upgrade” for the lowest risk. It binds only US federal civilian agencies. The lesson for everyone else: patch first what is reachable from the internet and already being exploited.

Application allowlisting. Instead of trying to recognise every bad program, only programs “authorized to be present or active on a host according to a well-defined baseline” may run. Australia calls it application control and puts it in its Essential Eight.

Mobile device management. MDM is “the administration of mobile devices such as smartphones, tablets, computers, laptops, and desktop computers” from one place, typically pushing settings and updates and wiping a lost device.

The identity layer

When staff work from anywhere and data lives in cloud services, who is asking matters more than where the request comes from.

  • Identity and access management is “about establishing and managing the roles and access privileges of individual network users”: who works here, what they may touch, and switching access off when they leave.
  • Single sign-on means “one account and its authenticators are used to access multiple applications”. One login becomes very valuable, so it needs the strongest two-step verification.
  • Two-step verification (MFA) is “authentication using two or more different factors”. CISA’s warning is that “not all forms of MFA are equally secure”, and that “phishing-resistant MFA is the gold standard”. The crash course explains the kinds.
  • Privileged access. Administrator accounts can “perform system control, monitoring, administration functions, or security-relevant functions that ordinary users are not authorized to perform”, so they are the prize. Keep them few, separate from everyday accounts and used only when needed. The principle is least privilege: access “to the minimum necessary to accomplish assigned tasks.”
  • Zero trust. NIST’s model assumes a network “viewed as compromised” and decides each request on its merits, because “Network location alone does not imply trust.” Its seven tenets include “All communication is secured regardless of network location” and “Access to individual enterprise resources is granted on a per-session basis.”

The data layer

  • Encryption is the “cryptographic transformation of data (called “plaintext”) into a form (called “ciphertext”) that conceals the data’s original meaning”. “At rest” means stored (disks, databases, backups); “in transit” means moving across a network.
  • Key management covers “the entire lifecycle of the keys, including their generation, storage, establishment, entry and output, use and destruction.” Lose the key and the data is gone; leak it and the encryption is worthless.
  • Backups. The crash course explains the 3-2-1 rule. The organisational point: “Maintain offline, encrypted backups of critical data”, because “many ransomware variants attempt to find and subsequently delete or encrypt accessible backups”.
  • Data loss prevention is a system’s ability “to identify, monitor, and protect data in use (e.g. endpoint actions), data in motion (e.g. network actions), and data at rest” — for example, flagging customer records attached to an outgoing email.

Detection and response

Logs and SIEM. Logs are the diary every system keeps. A SIEM (security information and event management) is, in NIST’s glossary, “a program that provides centralized logging capabilities for a variety of log types”; NIST’s incident-response guide recommends using such tools “to continuously monitor log events for known malicious and suspicious activity”. SOAR (security orchestration, automation and response) is an industry category name for tools that automate and coordinate response work; NIST’s guide lists it beside SIEM for monitoring and correlating log events.

The security operations centre. A SOC is the team that watches the alerts and starts the response. NIST lists several ways to staff incident handling, including “outsourcing a security operations center [SOC] to a managed security services provider [MSSP]”.

Threat intelligence is “threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes.”

Incident response. NIST’s guide was revised in April 2025 (Rev. 3). The familiar four phases — preparation; detection and analysis; containment, eradication and recovery; post-incident activity — are now its previous model. The new one says “All six NIST Cybersecurity Framework (CSF) 2.0 Functions play vital roles in incident response”, and that organisations “should use the incident response life cycle framework or model that suits them best.” It is blunt about why: “another incident is inevitable.”

Practising. A tabletop exercise is a meeting where a team talks through a made-up incident to find the gaps. Free packs exist: CISA offers “over 100” exercise packages, covering physical as well as cyber scenarios, and the NCSC’s Exercise in a Box “is used by small and medium sized enterprises”.

Testing your own defences, from cheapest to most realistic:

  • A vulnerability scan is “a technique used to identify hosts/host attributes and associated vulnerabilities.” It is broad and cheap, and “can have a high false positive error rate”.
  • A penetration test is testing “in which assessors mimic real-world attacks to identify methods for circumventing the security features” of a system, within agreed limits.
  • A red team is “a group of people authorized and organized to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture.”

Letting outsiders report holes. A vulnerability disclosure policy says what finders may do “in order to find and report vulnerabilities in a legally authorized manner.” It is “similar to, but distinct from, a “bug bounty.””, in which “organizations pay for valid and impactful findings”. Whether a policy protects a finder legally depends on the country; this is not legal advice. For websites, a simple first step is a security.txt file saying who to contact, explained in the website crash course.

Who does what

The US NICE Framework describes cybersecurity work as work roles and says outright that “Work Roles are not synonymous to job titles or occupations.” The job titles below are ours, matched to the roles NICE describes:

Common job titleWhat the work is (NICE’s wording)
Head of security (CISO)“Executive Cybersecurity Leadership”: “establishing vision and direction for an organization’s cybersecurity operations and resources”
SOC analyst“Defensive Cybersecurity”: “analyzing data collected from various cybersecurity defense tools to mitigate risks.”
Incident responder“Incident Response”: “investigating, analyzing, and responding to network cybersecurity incidents.”
Governance, risk and complianceAn industry label; the nearest roles include “Security Control Assessment” and “Technology Program Auditing”

Security is not only the IT team’s job. NIST’s guide gives leadership its own role: it “oversees incident response, allocates funding, and may have decision-making authority on high-impact response actions”. The NCSC’s version for small organisations: “Every member of the team should realise that cyber security is everyone’s business.”

Awareness training is where the evidence is disputed. Government baselines recommend it, while the strongest test we found, a 2025 randomised study, found common training formats “offer limited value”. The crash course sets out both sides. The practical answer is the same either way: put first the controls that do not depend on someone noticing, such as phishing-resistant two-step verification and calling back before any payment change.

What a small organisation needs

Almost everything above describes large organisations. None of the small-organisation baselines we checked (the UK NCSC’s small organisations guide and the UK and US Cyber Essentials) starts with a security operations centre, a SIEM or a red team. NIST itself says the right incident-response model “depends on many factors”, and that “larger and more technology-dependent organizations are likely to benefit more” from one “emphasizing continuous improvement”. On who handles incidents, it notes that many organisations may use more than one approach, “such as internally performing basic incident response and engaging third-party resources for assistance with certain incidents.” A small firm’s security operations centre can be a contract with a provider, or a named person plus the phone numbers of whoever helps in an emergency.

The crash course lists the UK’s Cyber Essentials controls and Australia’s Essential Eight. Mapped onto the layers above, in our reading:

LayerFirst step for a small organisation
NetworkFirewall on: the first of the UK Cyber Essentials controls.
DevicesUpdates on; patch internet-facing, actively exploited flaws first.
IdentityTwo-step verification on every account, phishing-resistant for admin and email; separate admin accounts.
DataOffline, tested backups.
Detection and responseA written who-to-call plan, one tabletop exercise a year, and rented monitoring if needed.
PeopleEveryone owns it; controls come before training.

The UK NCSC’s guide for small organisations says its steps are ones “many of which can be completed in as little as 5 minutes”. And CIS’s advice for any organisation starting out: “Every enterprise should start with IG1.”

Myths, checked

Myth “A firewall is enough.” NIST’s firewall guide already noted that “attacks sent from one internal host to another often do not pass through network firewalls.” Layers exist because any one of them can fail.

Myth “Zero trust is a product you can buy.” NIST: “ZT is not a single architecture but a set of guiding principles for workflow, system design and operations”, and it “cannot simply be accomplished with a wholesale replacement of technology.” CISA adds that it “may require a change in an organization’s philosophy and culture around cybersecurity.” Products can implement parts of it.

Myth “Compliant means secure.” The NCSC in so many words: “Compliance and security are not the same thing. They may overlap”, and compliance “can coexist with, and mask, very weak security practices.” A certificate is evidence of a baseline, not proof of safety. Where a law requires compliance, you still need it; this is not legal advice.

Myth “With good detection, you don’t need backups.” Detection tools miss things: NIST says intrusion detection systems “all generate false positives” and “false negatives (failing to identify malicious activity).” And ransomware goes after backups directly; the NCSC notes that ransomware incidents “have also compromised connected cloud storage locations containing backups.”

Partly true “Air-gapped means safe.” Cutting a computer off from the network removes one route in, not every route. The US Congressional Research Service described a worm that spread “through the use of thumb drives in computers that were not connected to the Internet”, and noted that it “can be spread through an air-gapped network by a removable device, such as a thumb drive”.

What changed recently

TopicEarlier figureAs of September 2026
MITRE ATT&CK Enterprise tactics1415, since version 19 (April 2026)
DMARCRFC 7489RFC 9989 (May 2026), which replaces it
NIST incident responseThe four-phase lifecycleRev. 3 (April 2025), organised around the CSF 2.0 functions
CISA patch deadlines (US federal)Two weeks, or six months for older flawsBOD 26-04 (June 2026): by risk, from 3 days to 60 days or the next system upgrade
ISO/IEC 27001114 controls (2013 edition)93 controls (2022 edition)

Sources

Checked September 2026.

Related: Cybersecurity crash course · Website security crash course

  • cybersecurity
  • security
  • security infrastructure
  • web tools
  • cheat sheet
  • fact check

SHARE & CITE

Hacks Vitae. "How Cybersecurity Is Built: The Layers, the Tools and Who Does What, in Plain Words." September 23, 2026. https://www.hacksvitae.com/life-hack/how-cybersecurity-is-built-the-layers-the-tools-and-who-does-what-in-plain-words

That's what we found. The rest is your call.

118 articles, each with its sources listed. Spotted something off? hacksvitae@gmail.com

Open the library