Cyber Resilience

← Exposures · the model

The exposure model — five ways to draw it

Nine layers (where a weakness lives), five weakness classes (what kind it is), two annotation dimensions (operated-by · reachability), and the resilience track deliberately outside. Five figures, from the three-second version to the full model.

Last updated: 12 August 2026 00:47 UTC . Model frozen 2026-07-09.  ← back to the hub

Figure A — the stack with a spanning management plane

Your instinct, drawn

Business process User Identity Data Applications OS Network Physical single-approval payments · unverified vendor changes vishing susceptibility · targetable executives password-only tenants · over-scoped roles · agent identities world-readable buckets · over-retention CVEs · OWASP · prompt injection the CVE bulk · unhardened builds attacker-usable paths · flat segments · exposed edges tailgating · no interior segregation Management plane cloud control plane · vCenter · BMC · MDM · AD ← administers every layer
the strata, the one-line exposure vocabulary per layer, and the management plane as the thing that touches everything — the three-second mental model.
weakness classes, the third-party dimension, and any sense of which layers have depth behind them.
the hero figure — homepage, first slide, top of the paper.
Figure B — layers × weakness classes

The actual model, as a matrix

Softwaredefect (CVE) Misconfiguration/ bad state Instruction–dataconfusion (AI) Lack ofknowledge Missingvalidation unpatched service world-readable bucket instructions in data reset by phone call one-approval payment Business process User Identity Data Applications Management plane OS Network Physical OS × software defect — the CVE bulkOS × misconfiguration — DISA STIG host hardeningApplications × software defect — CVEs / OWASPApplications × instruction–data confusion — prompt injection / OWASP LLMIdentity × misconfiguration — over-scoped roles, the identity lensUser × lack of knowledge — the social-engineering cohort (seed) core class at this layer occurs rare / n-a populated on the site today (links to its lens)
the two-axis insight itself — layers are where, classes are what — plus an honest coverage map of which cells have real data behind them.
the spanning quality of the management plane (here it's just a row), the third-party dimension, and narrative flow.
the methodology page and the model section of the paper — this is the model.
Figure C — concentric rings, management as a radial spoke

The defense-in-depth poster

Management plane Business process User Identity Data Applications OS Network Physical attacker works inward; management plane cuts straight to the core
depth — the attacker crosses rings inward toward the business — and the management plane's true menace: one spoke, straight to the core.
everything the matrix shows; ring geometry falsely implies each layer fully encloses the next.
talks and posters — the most memorable, least precise of the five.
Figure D — the stack, annotated with both other axes

One figure carrying the whole model

LAYER WEAKNESS CLASSES OPERATED BY (illustrative) Business process User Identity Data Applications Management plane OS Network Physical M V A K D M A M D M A D M D M D M M K Resilience gaps — deliberately outside the model missing detective & corrective controls (no logging, untested backups): amplify impact, create no foothold — tracked beside exposures, never counted among them Dsoftware defect Mmisconfiguration / state Ainstruction–data confusion Klack of knowledge Vmissing validation unpatched service world-readable bucket instructions in data reset by phone call one-approval payment operated by us operated by a third party (SaaS · IaaS · MSP · model vendor)
all three axes at once — layer, class, and responsibility — plus the resilience track explicitly fenced off.
nothing, which is its weakness: it's the busiest of the five, and the management plane loses its spanning drama.
the reference figure — methodology deep-dive, appendix, the hub's expandable view.
Figure E — three small figures, one idea each

The stepwise version, for the paper

Business process User Identity Data Applications OS Network Physical Management plane 1 · Where exposures live D M A K V Software defect Misconfiguration Instruction–data confusion Lack of knowledge Missing validation an unpatched, reachable service a world-readable bucket instructions hidden inside data help desk resets on a phone call payment on a single approval 2 · What kind of weakness (attacker-side phrasing) Operated by us third party Reachability internet internal adjacent Resilience gaps no logging · untested backups · no EDR coverage — amplify impact, create no foothold. Beside, not inside. 3 · Annotations — and what stays outside
one idea per figure, in teaching order: where → what → how annotated. Each survives being redrawn on a whiteboard.
the interactions — nothing shows classes meeting layers (that's the matrix's job).
the paper, where the model is introduced stepwise; onboarding decks.