This document discusses defense-in-depth strategies for improving cybersecurity in industrial control systems. It outlines several security challenges, including network perimeter flaws, common protocol attacks, field device attacks, database injection attacks, and lack of patching. The document then presents a strategic framework for defense-in-depth with multiple architectural zones separated by firewalls. Specific countermeasures are discussed like intrusion detection systems, policies and procedures for logging, security training, and incident response. The goal is to provide guidance on applying cybersecurity mitigation strategies to industrial control system environments.