Most enterprise security programs still measure strength by counting controls.
MFA is deployed. EDR is deployed. Logging is centralized. Privileged access is monitored. Cloud guardrails are active. The dashboard shows broad framework coverage, so leadership concludes that the organization has defense in depth.
That conclusion may be wrong.
The problem is not necessarily that the controls are weak. The problem is that several supposedly independent controls may rely on the same underlying service.
An identity provider may authenticate administrators to the EDR console, SIEM, cloud environment, ticketing system, and incident-response platform. A centralized telemetry pipeline may supply detection data to multiple tools. Several controls may reside in the same cloud account, depend on the same DNS or time service, or be managed through one administrative plane.
On a control matrix, these appear to be separate layers.
In the actual system, they may be branches of the same tree.

