Skip to content
Research Article Open access CC BY 4.0

Integrating Zero Trust, Risk Management Framework and Defense-in-Depth: A Multi-case Study Analysis of Enterprise Cybersecurity Architectures

Suleiman S. Abba, Oluwadayo Mafolasere Olaniyi, Odunayo Sekinat Sobowale, Sunday Abayomi Joseph, Abayomi Titilola Olutimehin

Journal of Engineering Research and Reports · pp. 190–206 · Published 24 Aug 2026

10.9734/jerr/2026/v28i81984

Abstract

Enterprise cybersecurity has shifted from perimeter defence toward continuously verified architectures, yet zero trust, layered defence, and formal risk governance are typically adopted in isolation, producing fragmented estates in which expenditure rises while measurable resilience does not. Existing literature examines each paradigm separately, leaving their interaction at enterprise scale unexamined. This study developed the Integrated Architecture Resilience Model, expressing available control surface as a weighted composite of governance, layering, and verification, and relating it to observed resilience. Two open datasets were analysed, comprising a versioned adversary technique catalogue and a community breach repository, yielding 638 qualifying incidents across financial services, healthcare, government, and critical infrastructure. Regression, configurational analysis, and stratified cross-validation were applied, with coding reliability assessed independently. Threat profiles differed significantly by sector, and 111 of 697 active techniques, representing 15.9 per cent, carried no mapped mitigation, concentrating in discovery. Layering dominated coverage while verification remained weakest. Chance-corrected coding agreement reached 0.683, indicating substantial reliability. The composite explained 35.9 per cent of variance in-sample but failed under cross-validation, establishing that documented coverage and enacted protection are distinct. The study contributes a reproducible diagnostic framework and evidence that control breadth alone does not secure resilience, redirecting attention toward verification depth.

Zero trust architecture defense-in-depth risk management framework cyber resilience control mapping

Cited by 0

No indexed citations yet.

Article metrics

Real usage data collected on this platform.

0

Page views

0

PDF downloads

0

Outbound clicks

0

Citations

Views by country

Approximate, from request IP at view time — not citizenship or institution. Countries with fewer than 5 views are grouped as "Other".

No views recorded yet.

Traffic sources

Referring site, by host.

No traffic recorded yet.

Views and downloads exclude known bots/crawlers. Citations combines this platform's own DOI-resolved index with each external source's own reported total — see Cited by above for individually listed citing works. Last refreshed 0 seconds ago.