Six-layer security framework illustrated as a castle — the approach behind Cipherex’s co-managed IT services

You’re Already Paying for Security. Is It Actually Protecting You?

13 August 2026
Siamak Behbahani, Founder & CEO

Picture a house built without a blueprint.

Nobody cheaped out. The windows are top-of-the-line. The front door is a work of art. The appliances cost more than your first car. But no one ever drew up how the pieces fit together — so the rooms don’t quite connect, the load-bearing walls landed in odd places, and that gorgeous door hangs in a frame nobody squared.

Every single component: excellent. The house: doesn’t work. And when the first real storm hits, it fails at the seam no one planned for.

That holds true whether you run IT entirely in-house, lean on managed IT support services, or work with a co-managed IT services partner alongside your own team — the blueprint problem shows up regardless of who’s holding the tools.

The money was spent in good faith — often on genuinely great tools. But each one was bought on its own: a vendor’s pitch here, a scary headline there, whatever the budget allowed that quarter. Nobody ever drew the blueprint. So now there’s advanced threat detection standing guard over servers that were never patched, protecting accounts whose password is “Spring2024!” — shared by a dozen people.

Each tool is capable. Together? That’s not security. That’s expensive theater.

Here’s the good news: you almost certainly don’t need to start over, and you probably don’t need to buy much. You need a way to see what you already own as one system — where the pieces back each other up, where they overlap, and where the gap is hiding.

Turns out there’s a mental model for this. It’s been battle-tested for about a thousand years.


Nobody ever built a castle at random. Every piece had a job, and every piece covered for the others: the moat, the gates, the walls, the keep, the watchtower, and the charter that governed the whole thing.

Security people call this defense-in-depth — layered protection where no single control has to be perfect. The castle is simply the clearest picture of it: six layers, each one making the others stronger.

And the castle gives you something even better than a metaphor. It gives you a map. Lay your current tools against the six layers and you’ll see — in minutes — which layers are solid, which are half-built, and which are standing wide open. Most companies find they’ve built three or four layers reasonably well… while one sits completely open. Guess which one the attacker uses.

Holding it all together is the blueprint. In security, the blueprint is governance: your risk tolerance, your compliance obligations, your budget. That’s what keeps the pieces fitting instead of overlapping. (More on this at Layer 6 — it’s much more interesting than it sounds. Okay, slightly more interesting.)

Six-layer security framework illustrated as a castle — the approach behind Cipherex’s co-managed IT services

Most wasted security spend doesn’t come from bad tools — it comes from tools bought for the wrong reasons: a vendor’s pitch, a conference buddy’s tip, a scary headline. Nobody stops to check whether the purchase overlaps with what you already own, and it usually traces back to the same missing blueprint.

Three patterns show up again and again:

  • The “someone told me to” purchase. A vendor, a conference buddy, a headline that ruined your morning coffee. The tool gets bought. Nobody asks where it fits with what you already own.
  • The shiny-object purchase. Usually the impressive 24/7 monitoring platform — while a dull essential in another layer sits untouched. It’s buying a home theater for a house with no locks.
  • The half-installed purchase. The license is paid. The rollout stalled at 60%. The features sit unconfigured, and the alerts go to an inbox nobody has opened since 2023.

Three different receipts, one root cause: buying without a blueprint.

It’s how a company ends up with a gleaming watchtower guarding gates that were never closed — before anyone even switched on Multi-Factor Authentication (MFA). That’s the simple second-step login check that Microsoft’s research shows blocks more than 99 percent of account-takeover attacks.1 Ninety-nine percent. It’s usually already included in what you pay for.

Now picture the security dashboard lighting up a thousand times a day — because that one basic protection was never turned on, or only covers half the company. That’s not a security win. That’s a very expensive way to watch the symptoms of a preventable disease.

Here’s why the layers matter: each one lightens the load on the others. Strong outer layers mean fewer threats ever reach your monitoring — so the alerts that do fire actually mean something. Close the right gap, and every dollar you’ve already spent starts working harder.

The six layers, coming up. Keep score as you read.


Think of your security stack as a castle with six layered defenses, each covering for the one behind it: the Moat holds off outside threats, the Gates control who gets in, the Walls slow down anyone who does, the Keep protects what matters most, the Watchtower catches what slips through, and the Charter holds the other five together.

Here is what each layer does:

Layer 1 — The Moat: web, email, and your people. The moat keeps the fight far from your walls. Web filtering blocks dangerous sites before they load. Email security catches the phishing that makes up most attacks. And your team gets regular practice spotting manipulation — because in Verizon’s 2025 Data Breach Investigations Report, 60 percent of breaches involved a human being tricked into helping.2 Your people aren’t the weakest link. They’re the moat — if you train them.

Layer 2 — The Gates: identity and devices. The gates decide who gets in. MFA lives here, alongside a simple rule: people and devices get only the access they actually need. Pair those two and a stolen password stops being a catastrophe — it opens one narrow door instead of the whole building.

Layer 3 — The Walls: hardening everything inside. Anyone who slips past the gates should hit resistance at every step: patched systems, locked-down laptops, secured servers, and a network split into sections so trouble in one room can’t wander the halls. This is also where you test yourself — scan for weaknesses and hire someone to safely attempt a break-in before a real attacker volunteers.

Layer 4 — The Keep: your data and your comeback plan. The keep protects the crown jewels even if everything outside falls: your proprietary information, your customer data, and above all your backups. Modern ransomware goes hunting for backups first — in Sophos’s 2025 study, attackers went after them in 94 percent of ransomware attacks.3 Backups kept offline or made impossible to alter turn a ransom demand from a catastrophe into an annoying Tuesday.

Layer 5 — The Watchtower: monitoring and response. No defense is perfect, so someone has to watch — around the clock, with a real human ready to act. That’s the difference between quietly containing a breach and discovering one months later in a ransom note. Just as important: a written response plan you actually rehearse. Companies with a tested plan cut average breach costs by more than two hundred thousand dollars, per IBM.4

Layer 6 — The Charter: the blueprint behind everything. Governance isn’t paperwork you bolt on at the end — it’s the blueprint you consult from the start. Define your risk tolerance, your compliance obligations, and your trade-offs early, whether that means SOC 2 (a common security audit), CMMC (for defense suppliers), the FTC Safeguards Rule, or something specific to your industry. A clear charter is what keeps Layers 1 through 5 complementing each other instead of overlapping or leaving gaps. Bonus: when the auditors show up, documenting a castle you actually designed is a formality — not a fire drill.


Co-managed IT isn’t about replacing what you’ve built — it’s about walking your existing fortifications with someone who can see the whole map at once. A partner audits your current stack against the six layers and shows you where to spend your next dollar, instead of pushing you toward a rebuild.

Unfortunately, that’s not how a lot of security advice frames it. Most of it assumes you have to start from zero. You don’t. You have licenses with years left on them, tools your team actually knows, and controls that are genuinely working. Good — keep them.

That’s the whole idea behind co-managed IT services and managed IT support services — bringing in outside help without replacing what your team has already built.

The exercise isn’t demolition. It’s walking your own fortifications with a map. Do it and three things happen:

  • You find your open layer. The gap that makes everything else moot — and the obvious home for your next dollar.
  • You find your redundancies. Two products doing half of the same job. Retire one; it funds closing the gap. Security that pays for itself.
  • You find your half-finished projects. Capable tools you already pay for that just need to be fully deployed. This is routinely the cheapest security win available — the fix for your most dangerous gap is often a feature you already own, sitting switched off.

That’s the difference between buying security and architecting it — and it’s exactly the difference a good partner is supposed to make. Not a bigger stack. A stack that fits.

Want a quick score? Rate each of the six layers from “not started” to “complete.” Your weakest layer is almost always where to start.


IBM’s 2025 Cost of a Data Breach Report puts the global average breach at $4.44 million. But that number is for everyone, from three-person startups to trillion-dollar banks. The last time IBM broke costs out by company size, in 2023, organizations under 500 employees averaged $3.31 million per breach.4 IBM hasn’t republished that split since — but overall costs have kept climbing since 2023, and smaller companies have never had the incident-response teams or cyber insurance leverage that keep large-enterprise numbers down. There’s no reason to think the SMB number went anywhere but up. Full layered security for that same company typically runs a few thousand dollars a month.

Run those numbers side by side and security stops looking like a cost center. It’s some of the cheapest insurance a business can buy — and for a smaller company, one serious breach can be existential. Done right, the castle protects the things you can’t buy back: your intellectual property and your customers’ trust.

You don’t have to do everything at once. You don’t have to abandon what you’ve built. You have to find the open layer, close it, and make the pieces work as one system. Security isn’t a project you finish. It’s a posture you keep.


You don’t find gaps by staring harder at a dashboard — you find them by mapping what you run against the six layers and seeing where the coverage thins out. That’s the value of an outside set of eyes: they catch the blueprint problem you’re too close to see, and hand you a plain-language list of what to fix first.

You don’t need to guess. You need someone to check.

Cipherex offers a Free Security Review for qualified companies. We map your current tools and practices against the six layers of the castle and hand you a plain-language report of what we find: the layer standing open, the tools quietly overlapping, and the paid-for features sitting switched off.

No jargon, no 40-page PDF, no pressure to buy anything. Just a clear picture of where your gaps are — and which one to close first.

You can’t fix a gap you don’t know exists. Start there.


SOURCES

1. Microsoft, “How effective is multifactor authentication at deterring cyberattacks?” and related Microsoft Security research — Multi-Factor Authentication blocks more than 99 percent of account-compromise attacks. https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/

2. Verizon, 2025 Data Breach Investigations Report — 60 percent of breaches involve a human element. https://www.verizon.com/business/resources/reports/dbir/

3. Sophos, The State of Ransomware 2025 — attackers attempted to compromise backups in 94 percent of ransomware attacks. https://www.sophos.com/en-us/content/state-of-ransomware

4. IBM, Cost of a Data Breach Report 2025 (global average cost) — https://www.ibm.com/reports/data-breach; and IBM, Cost of a Data Breach Report 2023 (most recent year IBM segmented cost by company size) — https://www.ibm.com/reports/data-breach/2023