Defense in depth aims to avoid accidents by embracing a safety culture, but also accepts that mechanical (and human) failures are inevitable. Any possible problem - however unlucky - is then anticipated and factored into the design with multiple redundancies. The goal, therefore, is to provide depth to the safety systems; akin to the way Russian dolls have several layers before reaching the core doll. When one element fails, there is another, and another, and another that still functions.

