Assume the breach
The defining mindset of modern defense is uncomfortable but liberating: assume you will be breached. Not "if we build a strong enough wall, nothing gets in," but "something will eventually get in, so how do we limit the damage when it does?"
This follows directly from the first lesson's asymmetry: the attacker needs one success and the defender must stop them every time, so over a long enough horizon, some attack gets through. Perfect prevention is not a realistic goal. A defense built entirely on keeping everyone out is one mistake away from total failure, because it has no answer for what happens after the first breach.
The response is defense in depth: multiple independent layers of security, so that defeating one does not defeat the whole system. If the first layer fails, the second contains the damage; if that fails, a third detects the intruder; and so on. Like a castle with a moat, walls, guards, and a locked keep rather than a single gate, no one failure is catastrophic.
This reframes the goal of security from the impossible "never be breached" to the achievable "make a breach hard to start, slow to spread, quick to detect, and limited in damage." Every technique in this lesson is a layer serving one of those aims, and together they map neatly onto breaking the attack chain from the first lesson at multiple points.

