Oil, Circuits, and Cheese: An Additive Model of Failure

No ratings

Presented at GrrCON Cyber Security Summit and Hacker Conference 2023 by

The Swiss cheese model, developed in 1990 by James Reason, is based on the idea that errors can never be eliminated entirely due to complex systems but are instead “layered� like slices of swiss cheese. This model has become a well-known concept in the field of risk management that highlights how multiple layers of defense can fail, leading to a catastrophic outcome. This model aims to provide information to decision-makers to help them reduce the chances of incidents occurring. It is crucial to keep in mind that all safety measures within an organization are linked, and by implementing appropriate policies and standards, risk can be minimized. So how can we apply this model to cybersecurity, where multiple layers of security can be breached during a compromise? This talk will explore how the Swiss cheese model can be used to understand the vulnerabilities and cybersecurity risks posed to organizations. We will also examine how the layers of defense, including people, processes, and technology, can fail and lead to a breach.