In December 2021, we had the Log4J / Log4Shell Zero day This isn't a talk about Log4Shell itself. It's the story of how an customers application was initially compromised but protected from exploit success before a patch was deployed, not because we predicted the vulnerability, but because years earlier we'd implemented a layered security approach based on default-deny principles. The technology has changed since 2021. The principles haven't.