the Swiss cheese model

expression

securitygovernance & riskops culture

James Reason's accident model: every defense layer has holes, and disasters happen when the holes line up.

Each slice - firewall, review, monitoring, training - is imperfect, which is fine; the design goal is ensuring the holes never align. It is the theory underneath defense in depth, and the honest answer to 'but we had a control for that': you had one slice.

James Reason's model represents each defence as a slice of cheese with holes, where the holes are that layer's weaknesses. No layer is complete, and an incident happens only when holes in every layer line up to allow a path through. It is the standard model in aviation and healthcare safety and it transfers cleanly to security and reliability.

Its value over the weakest link metaphor is that it explains why systems mostly work despite every component being flawed, and why serious incidents are almost always a combination rather than a single failure. It also predicts something useful: the holes move, since a layer's weaknesses change with configuration, staffing and load, so a path that was blocked last month may be open now.

What follows for practice is that adding a layer helps only if its holes are in different places, which is the same independence argument as belt and suspenders. It also reframes incident analysis: the question is not which control failed, since several did, but why the holes aligned and what would have blocked the path. That is a more productive investigation than finding the single point to blame, and it is why the model is associated with blameless postmortems.

Also known as: Swiss-cheese model

All glossary entries