Cyber Resilience

Your exposure is more than unpatched CVEs

It is nine layers — and a weakness can hit any of them. A CVE is one kind of weakness at one layer; identity, configuration, data, and the human surface each carry their own. Two axes: where a weakness lives (the layers) and what kind it is (five weakness classes). This is the same shift the industry made toward continuous threat-exposure management — here, kept honest about what we can back with live data.

Last updated: 12 August 2026 00:47 UTC · 3 of 9 layers have live data today. · The model · alternative views →

Figure A — the nine layers

Where exposure lives

Business process User Identity Data Applications OS Network Physical single-approval payments · unverified vendor changes vishing susceptibility · targetable executives password-only tenants · over-scoped roles · agent identities world-readable buckets · over-retention CVEs · OWASP · prompt injection the CVE bulk · unhardened builds attacker-usable paths · flat segments · exposed edges tailgating · no interior segregation Management plane cloud control plane · vCenter · BMC · MDM · AD ← administers every layer
Nine layers, top to bottom, with the management plane drawn as a spanning side bar because it administers every layer at once — one console, straight to the core.
Figure B — layers × weakness classes

The model, and an honest coverage map

Softwaredefect (CVE) Misconfiguration/ bad state Instruction–dataconfusion (AI) Lack ofknowledge Missingvalidation unpatched service world-readable bucket instructions in data reset by phone call one-approval payment Business process User Identity Data Applications Management plane OS Network Physical OS × software defect — the CVE bulkOS × misconfiguration — DISA STIG host hardeningApplications × software defect — CVEs / OWASPApplications × instruction–data confusion — prompt injection / OWASP LLMIdentity × misconfiguration — over-scoped roles, the identity lensUser × lack of knowledge — the social-engineering cohort (seed) core class at this layer occurs rare / n-a populated on the site today (links to its lens)
Layers are where; the five classes are what. The amber dots mark the cells we can back with live data on the site today — each links to the lens behind it. Empty cells are the roadmap, named honestly below.

The nine layers

Each card carries the weakness classes that live at that layer [D/M/A/K/V], a live headline stat where we have data, and an honest status. Roadmap layers name the data that would seed them and link nowhere until they are built — no vaporware. The two built-out lenses are Identity (pilot) and Configuration (the M-class surface across OS, Identity, and Data).

Business process

Roadmap

Where the organisation's rules can be gamed — approvals, segregation of duties, vendor changes. [V M]

not built yet — seeded by a process-control taxonomy (segregation of duties, approval thresholds, vendor-change verification); no data ingested yet.

User

Roadmap

The human attack surface — social-engineering susceptibility that turns a person into an entry point. [K A]

not built yet — seeded by the social-engineering actor cohort (112 tracked actors use phishing T1566, 84 use valid accounts T1078) and the 17 NIST AT awareness-&-training controls.

Identity

Pilot

Credentials, accounts, and access that can be abused — the pilot of this whole reframing. [M D A]

12,185 identity-weakness CVEs · 129 identity-using actors

Open the identity lens (pilot) →

Data

Roadmap

Exposure in the data itself — where it sits, who can read it, and how long it lingers. [M]

not built yet — seeded by data-state exposures (world-readable buckets, over-retention); no data-posture ingest yet.

Applications

Partial

The software your org runs and builds — CVEs, OWASP, and the instruction–data-confusion class of AI apps. [D A M]

3,833 AI-related CVEs · 34 tagged OWASP LLM01 prompt injection — the AI weakness class lands here

See the AI-application surface →

Management plane

Roadmap

Spans every layer: the admin plane that administers all the others — one console, straight to the core. [M D]

not built yet — seeded by admin-plane exposures (cloud control plane, vCenter, BMC, MDM, Active Directory); no data yet.

OS

Partial

The operating system underneath — the CVE bulk and the hardening state that keeps a build from drifting. [D M]

3,616 DISA STIG host-hardening rules across 12 baselines · plus the CVE bulk

Open the configuration lens →

Network

Roadmap

The paths between everything — segments, edges, and the routes an attacker can actually traverse. [M D]

not built yet — seeded by network edges/paths (flat segments, exposed edges); no topology ingest yet.

Physical

Roadmap

The building and its doors — tailgating, no interior segregation. [M K]

not built yet — building security is out of current data scope.

The five weakness classes

A weakness class is what kind of weakness it is, phrased attacker-side. Its preventive-control name is the defender-side dual.

D software defect (CVE)e.g. unpatched service
M misconfiguration / bad statee.g. world-readable bucket
A instruction–data confusion (AI)e.g. instructions in data
K lack of knowledgee.g. reset by phone call
V missing validatione.g. one-approval payment
Resilience gaps — beside the model, not inside it. Missing detective and corrective controls (no logging, untested backups, no EDR coverage) amplify impact but create no foothold — so they are tracked beside the exposure model, never counted among the weakness classes above.

The four site pillars (Vulnerabilities, Threats, Assets, Controls) are unchanged — this hub sits across them, it does not replace them.

Recent news — Exposures

All news · RSS feed