HomeBlog5 Powerful Steps for Security in Depth Success
All PostsSmall Business Cybersecurity Basics

5 Powerful Steps for Security in Depth Success

Kevin MabryJuly 20, 2026
CybersecuritySecurity in DepthSmall Business ITData Breach PreventionLayered SecuritySentree Systems
5 Powerful Steps for Security in Depth Success

Protect your small firm from data breaches with Security in Depth. Learn five powerful steps to build a multi-layered defense and ensure business resilience.

Imagine arriving at your office on a Monday morning, just like today, July 20, 2026. You sit down with your coffee, open your laptop, and instead of your email, you see a bright red screen. It tells you that every client file, every tax record, and every piece of sensitive intellectual property your firm owns has been encrypted. The price to get it back? $450,000, payable in Bitcoin within 48 hours. This isn't a plot from a movie; it is the reality facing thousands of small professional service firms this year. According to the 2025 IBM Cost of a Data Breach Report, the average cost of a data breach has climbed to a staggering $4.88 million globally, but for a small firm with under 100 employees, even a "small" $200,000 hit is often enough to force a permanent closure within six months.

I’ve been in this industry since 1999. Back then, "cybersecurity" meant putting a password on your desktop and making sure the door was locked when you left for the night. In the 26 years since I founded Sentree Systems, the world has changed, but the mindset of many small business owners hasn't caught up. They still think, "I'm too small for a hacker to care about." They couldn't be more wrong. Automated bots and AI-driven scripts don't care if you're a solo practitioner or a Fortune 500 company; they just look for the unlocked window. That is why we use a strategy called Security in Depth. It is the only way to sleep soundly in 2026.

Security in depth isn't about buying the most expensive software on the market. It is a philosophy that assumes one thing: your first line of defense will fail. And when it does, you need a second, third, and fourth layer waiting to catch the intruder. In my two and a half decades of helping firms just like yours, I have seen that the most resilient businesses aren't the ones with the biggest budgets, but the ones with the most disciplined, layered approach to their protection. Let's look at how you can build that shield for your firm without getting lost in technical jargon or vendor hype.

Key Takeaways: Building a Resilient Shield

  • Assume Breach: Operate under the assumption that one layer of your security will eventually fail. Security in depth ensures that a single failure doesn't result in a total catastrophe.
  • Human Error is the #1 Risk: According to the 2024 Verizon Data Breach Investigations Report (DBIR), 68% of breaches involved a non-privileged human element, including errors or social engineering. Training your team is a primary security layer.
  • Physical Security Still Matters: Digital threats get the headlines, but a stolen laptop or an unlocked server closet can bypass all your firewalls in seconds.
  • Identity is the New Perimeter: In a world of remote work, your office walls don't matter. Who is logging in and how they prove their identity (Multi-Factor Authentication) is your most vital technical gatekeeper.
  • The Power of "Least Privilege": Most employees don't need access to everything. Restricting access to only what is necessary for a job role significantly limits the "blast radius" of a potential attack.
  • Regular Backups are Your "Get Out of Jail Free" Card: If all else fails, an isolated, off-site backup is the only thing that prevents you from having to pay a ransom.
  • ROI of Prevention: Investing in layered security typically costs a fraction (often less than 1%) of the total cost of recovering from a major data breach and the subsequent loss of client trust.

The Concept of Security in Depth: Why One Wall Isn't Enough

The term "Security in Depth" actually comes from military strategy. Think of a medieval castle. You didn't just have a stone wall. You had a moat. You had a drawbridge. You had archers on the ramparts. You had a secondary inner keep where the most valuable assets were kept. If the enemy crossed the moat, they still had to face the wall. If they breached the wall, they were trapped in the courtyard under fire. This is exactly how we need to think about your law firm, your accounting practice, or your medical clinic.

Historical Origins and Modern Adaptation

In the early days of Sentree Systems—around 2002 or 2003—most of my clients felt safe if they had a basic Cisco firewall and Norton Antivirus. That was the "eggshell" model of security: hard on the outside, soft on the inside. Once a hacker cracked that outer shell, they had free rein over everything. I remember a specific case in 2005 where a local accounting firm was compromised because a temp worker plugged a personal USB drive into a networked computer. Because there were no internal layers, the virus spread to every client file in under ten minutes. That firm spent three weeks rebuilding their data manually.

Today, the "eggshell" is dead. We live in a "zero-trust" world. Modern security in depth means we treat every device, every user, and every connection as a potential threat until proven otherwise. We aren't just building one wall; we are building a series of concentric circles around your data. If a hacker steals an employee's password (Layer 1), they get stopped by Multi-Factor Authentication (Layer 2). If they manage to bypass that, they find the data they want is encrypted (Layer 3). If they try to download it, an automated system flags the unusual behavior and locks the account (Layer 4). This is the only way to manage risk effectively in 2026.

The Economics of Cybersecurity for Small Firms

I often hear small business owners complain that cybersecurity is a "black hole" for money. I disagree. It is an insurance policy with a massive Return on Investment (ROI). Let's look at the numbers. The FTC reported that small business losses to fraud and cyber-attacks have increased by nearly 30% year-over-year. For a firm with 20 employees, a total system outage costs roughly $10,000 to $25,000 per day in lost billable hours and overhead. Compare that to the cost of implementing a robust security stack.

Security Incident / Measure Estimated Cost (Firm of 20 Employees) Potential Impact
Ransomware Cleanup & Ransom $150,000 - $500,000+ Potential Bankruptcy, Reputation Loss
Business Email Compromise (Wire Fraud) $50,000 - $150,000 Immediate Cash Flow Crisis
Implementing Multi-Layered Security $1,500 - $3,000 / month Ongoing Protection, Compliance, Peace of Mind
Security Awareness Training $100 - $200 / month Reduces Phishing Risk by up to 70%

When you look at it this way, the cost of doing nothing is far higher than the cost of doing it right. In my 26 years, I’ve never had a client regret spending money on a backup system, but I’ve seen plenty of former business owners regret skipping it.

The 5 Pillars of a Security in Depth Strategy

To make this practical for your firm, we break the strategy down into five specific pillars. You don't have to master these yourself—that's what experts are for—but as the leader of your firm, you must ensure these pillars are standing tall.

Pillar 1: The Human Layer (The "Squishy" Layer)

I call this the "squishy" layer because humans are unpredictable. You can have a $50,000 firewall, but it won't matter if your office manager clicks a link in an email that looks like it's from "UPS" asking to verify a delivery address. According to KnowBe4’s 2024 Phishing Industry Benchmarking Report, roughly 33% of untrained users will click on a malicious link within their first year of employment. After just one year of consistent training, that number drops to under 6%.

I once worked with a legal firm where the managing partner prided himself on being "tech-savvy." During a routine security test we conducted, he was the first person to enter his credentials into a fake login page we created. He was embarrassed, but it was a vital lesson: everyone is a target. Security awareness training isn't a one-time HR meeting; it's a culture. It’s about teaching your team to pause, look at the sender’s email address, and never, ever give out a password over the phone.

Pillar 2: Physical Security (The Foundation)

We often get so caught up in "the cloud" that we forget about the ground. Physical security is the literal foundation of your depth strategy. If I can walk into your office, pick up a backup drive, and walk out, your encryption might not save you if the "key" is written on a post-it note under the keyboard (yes, I still see this in 2026).

Physical security includes things like:

  • Access Control: Who has keys or fobs to the office? Do you revoke them immediately when someone leaves the firm?
  • Clean Desk Policies: Sensitive client files should not be left out overnight for the cleaning crew to see.
  • Device Management: If a lawyer leaves a laptop in a cab, do you have the ability to remotely wipe that device before someone cracks the password?
  • Surveillance: Simply having cameras in the server room or main entry points acts as a significant deterrent.

Pillar 3: Identity and Access Management (IAM)

In 2026, the "perimeter" of your business is no longer the office wall; it's the login screen. IAM is about ensuring the right people have the right access to the right things—and nothing else. The most important tool here is Multi-Factor Authentication (MFA). Microsoft has stated that MFA can block 99.9% of automated account takeover attacks. If you don't have MFA turned on for your email and your practice management software, you are essentially leaving your front door wide open with a sign that says "Welcome."

Another key concept here is the Principle of Least Privilege (PoLP). In many small firms, every employee is an "Administrator" on their own computer because it's "easier." This is a nightmare scenario. If a staff member with admin rights gets infected with malware, that malware has the power to install itself deep into the system. If they are a "Standard User," the malware is often blocked from executing. I’ve seen this one simple change save firms from total system wipes dozens of times.

Pillar 4: Network and Endpoint Security

This is the technical "meat" of the sandwich. Network security involves your firewalls and Wi-Fi protection. Your Wi-Fi should be segmented: one network for your staff to access client files, and a completely separate "Guest" network for clients to use while they wait. Never let a client (or a client's kid with a tablet) onto the same network where your financial data lives.

Endpoint Security refers to the individual devices: laptops, desktops, and mobile phones. In the old days, we used "Antivirus" which looked for a list of known "bad files." Today, we use EDR (Endpoint Detection and Response). EDR is much smarter; it uses AI to look for behavior. If a computer suddenly starts encrypting 5,000 files a minute, EDR knows that isn't normal human behavior and shuts the process down instantly, even if it doesn't recognize the specific virus.

Pillar 5: Data Security and Backups

At the end of the day, the hackers aren't after your computers; they are after your data. Data security involves encrypting your files so that even if they are stolen, they are unreadable. But more importantly, it involves your 3-2-1 Backup Strategy:

  1. 3 Copies of Data: Your live data and two backups.
  2. 2 Different Media: For example, one on a local NAS drive and one in the cloud.
  3. 1 Off-site/Immutable Copy: A backup that is physically or logically disconnected from your network so ransomware can't reach it.
"I tell my clients that a backup is only as good as the last time you tested it. I've seen firms go to restore their data after a crash only to realize the backup had been failing for six months and no one noticed. We test restores monthly. You should too." — Kevin Mabry

Implementation Best Practices: 10 Action Steps

Feeling overwhelmed? Don't be. You don't have to do everything by tomorrow. Cybersecurity is a journey, not a destination. Here is a practical roadmap I recommend for any professional service firm under 100 employees:

  1. Audit Your Assets: You can't protect what you don't know you have. Make a list of every laptop, server, and cloud service (like Dropbox, Clio, or QuickBooks Online) your firm uses.
  2. Turn on MFA Everywhere: This is non-negotiable. If a service doesn't offer Multi-Factor Authentication, find a different service.
  3. Implement a Password Manager: Stop letting employees use "Summer2026!" for everything. Use a firm-wide password manager like 1Password or Bitwarden to generate and store complex, unique passwords.
  4. Standardize Your Hardware: It is much harder to secure a "bring your own device" (BYOD) environment. Issue firm-owned laptops that are pre-configured with your security settings.
  5. Patch, Patch, Patch: Those annoying "Update Available" pop-ups on Windows or Mac? Those are often fixing critical security holes. Set your systems to update automatically overnight.
  6. Set Up Standard User Accounts: Remove administrative rights from daily-use accounts. Only use admin accounts when absolutely necessary for software installation.
  7. Train Your Team Monthly: Use a service that sends out "fake" phishing emails and provides 5-minute training videos. Keep security top-of-mind.
  8. Encrypt All Laptops: Ensure that if a laptop is stolen, the hard drive is encrypted (using BitLocker for Windows or FileVault for Mac). This makes the data useless to a thief.
  9. Create an Incident Response Plan: Write down exactly who you call first when something goes wrong. Who is your IT provider? Who is your insurance agent? Do you have a "breach coach" lawyer?
  10. Review Your Cyber Insurance: Not all policies are created equal. Ensure your policy covers ransomware, data recovery, and "social engineering" (wire fraud).

Frequently Asked Questions

Is "Security in Depth" too expensive for a firm with only 5 or 10 employees?

Actually, it's often more affordable for small firms because you have fewer "endpoints" to protect. Many of the most critical layers—like MFA, standard user accounts, and basic training—cost very little but provide massive protection. The cost of a single breach is what you truly can't afford.

Why isn't my basic antivirus software enough anymore?

Modern hackers don't always use "viruses." They use "fileless malware" or stolen credentials. Antivirus looks for a specific "signature" of a known bad file. If a hacker logs in with a stolen password they bought on the dark web, antivirus sees that as a legitimate user. You need layers like IAM and EDR to catch those more sophisticated entries.

What is the biggest threat to professional service firms in 2026?

Right now, it is AI-enhanced social engineering. Hackers are using AI to generate voice clones of CEOs or partners to authorize fraudulent wire transfers, and they are writing perfectly grammatical, highly personalized phishing emails that no longer have the "bad spelling" red flags we used to look for.

Do I really need to worry about physical security if everything is in the cloud?

Yes. Your employees still use physical devices to access that cloud data. If an unlocked laptop is stolen from a car, the thief can often bypass the need for a password if the browser has "remembered" the login for your cloud services. Physical access is still the fastest way into a digital system.

How often should we update our security policies?

I recommend a full review once a year, or whenever you make a major change to how you work (like moving to a fully remote model or adopting a new piece of core software). Cybersecurity isn't "set it and forget it."

Does using a Mac make my firm safer than using Windows?

In 1999, maybe. In 2026, no. As Macs have become more popular in the business world, hackers have developed plenty of tools to target them. The "Macs don't get viruses" myth is a dangerous one. Both platforms require the same layered security approach.

What should I do first if I think we've been hacked?

Disconnect the affected device from the internet (unplug the cable or turn off Wi-Fi) but do not turn it off. Turning it off can sometimes erase volatile memory that forensic experts need to see what happened. Call your IT security provider immediately.

Conclusion: The ROI of Resilience

After 26 years in this business, I’ve learned that security isn't about being perfect. It’s about being a "hard target." Hackers are like burglars walking down a street at night; they are looking for the house with the door standing open and no lights on. By implementing security in depth, you are putting up the fence, installing the floodlights, and putting a "Beware of Dog" sign in the yard. Most hackers will simply move on to a firm that hasn't taken these steps.

The ROI of a security in depth strategy isn't just about avoiding a ransom payment. It's about your reputation. In the professional services world—whether you are a lawyer, a doctor, or a CPA—your entire business is built on trust. If you lose your clients' data, you lose their trust, and that is something no insurance policy can buy back. Building these layers today is how you ensure your firm is still thriving 26 years from now, just as Sentree Systems is today. Don't wait for the red screen to appear. Start building your depth today.

Watch: What should small medical practices do after a data theft incident?

7 viewsJun 2, 2026Watch on YouTube →
KM

Kevin Mabry

Founder & CEO, Sentree Systems

Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.

His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.

Take Action

Is your business protected?

Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.

Schedule Your Free Assessment