Integrating Zero Trust, Risk Management Framework and Defense-in-Depth: A Multi-case Study Analysis of Enterprise Cybersecurity Architectures
Suleiman S. Abba
*
University of the Cumberlands, 6178 College Station Drive, Williamsburg, KY 40769, United States of America.
Oluwadayo Mafolasere Olaniyi
University of the Cumberlands, 6178 College Station Drive, Williamsburg, KY 40769, United States of America.
Odunayo Sekinat Sobowale
University of Arkansas Fayetteville, 1 University of Arkansas, Fayetteville, AR 72701, United States of America.
Sunday Abayomi Joseph
Ottawa University, 1001 S Cedar St, Ottawa, KS 66067, United States of America.
Abayomi Titilola Olutimehin
Royal Holloway University of London, Egham, Surrey, United Kingdom.
*Author to whom correspondence should be addressed.
Abstract
Enterprise cybersecurity has shifted from perimeter defence toward continuously verified architectures, yet zero trust, layered defence, and formal risk governance are typically adopted in isolation, producing fragmented estates in which expenditure rises while measurable resilience does not. Existing literature examines each paradigm separately, leaving their interaction at enterprise scale unexamined. This study developed the Integrated Architecture Resilience Model, expressing available control surface as a weighted composite of governance, layering, and verification, and relating it to observed resilience. Two open datasets were analysed, comprising a versioned adversary technique catalogue and a community breach repository, yielding 638 qualifying incidents across financial services, healthcare, government, and critical infrastructure. Regression, configurational analysis, and stratified cross-validation were applied, with coding reliability assessed independently. Threat profiles differed significantly by sector, and 111 of 697 active techniques, representing 15.9 per cent, carried no mapped mitigation, concentrating in discovery. Layering dominated coverage while verification remained weakest. Chance-corrected coding agreement reached 0.683, indicating substantial reliability. The composite explained 35.9 per cent of variance in-sample but failed under cross-validation, establishing that documented coverage and enacted protection are distinct. The study contributes a reproducible diagnostic framework and evidence that control breadth alone does not secure resilience, redirecting attention toward verification depth.
Keywords: Zero trust architecture, defense-in-depth, risk management framework, cyber resilience, control mapping