Your exposure is more than unpatched CVEs
It is nine layers — and a weakness can hit any of them. A CVE is one kind of weakness at one layer; identity, configuration, data, and the human surface each carry their own. Two axes: where a weakness lives (the layers) and what kind it is (five weakness classes). This is the same shift the industry made toward continuous threat-exposure management — here, kept honest about what we can back with live data.
Last updated: 12 August 2026 00:47 UTC · 3 of 9 layers have live data today. · The model · alternative views →
Where exposure lives
The model, and an honest coverage map
The nine layers
Each card carries the weakness classes that live at that layer [D/M/A/K/V], a live headline stat where we have data, and an honest status. Roadmap layers name the data that would seed them and link nowhere until they are built — no vaporware. The two built-out lenses are Identity (pilot) and Configuration (the M-class surface across OS, Identity, and Data).
Business process
RoadmapWhere the organisation's rules can be gamed — approvals, segregation of duties, vendor changes. [V M]
not built yet — seeded by a process-control taxonomy (segregation of duties, approval thresholds, vendor-change verification); no data ingested yet.
User
RoadmapThe human attack surface — social-engineering susceptibility that turns a person into an entry point. [K A]
not built yet — seeded by the social-engineering actor cohort (112 tracked actors use phishing T1566, 84 use valid accounts T1078) and the 17 NIST AT awareness-&-training controls.
Identity
PilotCredentials, accounts, and access that can be abused — the pilot of this whole reframing. [M D A]
12,185 identity-weakness CVEs · 129 identity-using actors
Open the identity lens (pilot) →Data
RoadmapExposure in the data itself — where it sits, who can read it, and how long it lingers. [M]
not built yet — seeded by data-state exposures (world-readable buckets, over-retention); no data-posture ingest yet.
Applications
PartialThe software your org runs and builds — CVEs, OWASP, and the instruction–data-confusion class of AI apps. [D A M]
3,833 AI-related CVEs · 34 tagged OWASP LLM01 prompt injection — the AI weakness class lands here
See the AI-application surface →Management plane
RoadmapSpans every layer: the admin plane that administers all the others — one console, straight to the core. [M D]
not built yet — seeded by admin-plane exposures (cloud control plane, vCenter, BMC, MDM, Active Directory); no data yet.
OS
PartialThe operating system underneath — the CVE bulk and the hardening state that keeps a build from drifting. [D M]
3,616 DISA STIG host-hardening rules across 12 baselines · plus the CVE bulk
Open the configuration lens →Network
RoadmapThe paths between everything — segments, edges, and the routes an attacker can actually traverse. [M D]
not built yet — seeded by network edges/paths (flat segments, exposed edges); no topology ingest yet.
Physical
RoadmapThe building and its doors — tailgating, no interior segregation. [M K]
not built yet — building security is out of current data scope.
The five weakness classes
A weakness class is what kind of weakness it is, phrased attacker-side. Its preventive-control name is the defender-side dual.
The four site pillars (Vulnerabilities, Threats, Assets, Controls) are unchanged — this hub sits across them, it does not replace them.