A layer, not a silo
Security
Security architecture, Zero Trust, detection and response, vulnerability and patch management, monitoring and incident handling across every other layer.

The five Zero Trust control planes
Every access decision in a modern estate is evaluated across all five planes. A gap in one undermines the others, which is why tool count is a poor measure of coverage.
Identity
Is this really the account holder, right now?
Signals evaluated
- Authentication method strength
- Sign in risk
- Group and role membership
- Token age
Controls applied
- Phishing resistant MFA
- Conditional access
- Just in time privilege
- Legacy auth blocked
Common gap, Standing global admin rights and a token replayed after MFA has already succeeded.
Device
Is this device known, healthy and managed?
Signals evaluated
- Enrolment state
- Compliance policy result
- Patch level
- EDR health
Controls applied
- Management enrolment
- Configuration baselines
- Disk encryption
- Local admin removal
Common gap, Access granted from an unenrolled personal device because a policy excluded a group.
Network
Should this source be able to reach this destination at all?
Signals evaluated
- Source location and address
- Named network
- East west flow records
- DNS queries
Controls applied
- Segmentation
- Explicit allow rules
- Private access instead of VPN
- Egress filtering
Common gap, A flat internal network where one compromised host can reach every server.
Application
Is this the app's intended use by an authorised session?
Signals evaluated
- Session context
- Granted OAuth scopes
- Application risk rating
- Anomalous API volume
Controls applied
- App consent governance
- Least privilege scopes
- Session controls
- Reverse proxy inspection
Common gap, A user consented third party app holding broad mailbox and file permissions indefinitely.
Data
Is this data classified, protected and recoverable?
Signals evaluated
- Classification label
- Sharing scope
- Download and export events
- Backup status
Controls applied
- Classification and labelling
- Loss prevention policy
- Encryption at rest
- Immutable backups
Common gap, Sensitive records in an unlabelled share with anonymous links and untested restores.
Data Security
Certificates & PKI
The hierarchy of certificate authorities, policies and lifecycle processes that issue and validate digital identities.
ReadData Loss Prevention
Detecting and controlling sensitive data in email, endpoints, cloud storage and SaaS based on classification and policy.
ReadEncryption
Protecting data confidentiality and integrity in transit, at rest and increasingly in use, with key management as the hard part.
ReadSecurity Architecture
Cloud Security
Securing cloud platforms through identity, configuration posture, network controls, workload protection and control plane monitoring.
ReadIdentity Security
Protecting the identity control plane itself, credentials, tokens, directories, privilege and the policies that govern them.
ReadIT Attack Paths
How real intrusions chain individually minor weaknesses into full compromise, and where defensive controls interrupt the chain.
ReadNetwork Security
Controls that constrain how traffic moves: segmentation, filtering, inspection, egress control and monitoring.
ReadRisk Management
Identifying, analysing, treating and monitoring technology risk so decisions are explicit rather than accidental.
ReadDetection & Response
EDR
Endpoint Detection and Response continuously records endpoint behaviour, detects malicious activity, and enables remote investigation and containment.
ReadEmail Security
Protecting the most used attack channel with authentication, filtering, link and attachment analysis, and user reporting.
ReadEndpoint Security
The layered controls that protect devices: hardening, application control, exploit mitigation, EDR and disk encryption.
ReadIncident Response
Exposure Management
Patch Management
The controlled process of testing, deploying and verifying software and firmware updates across an estate.
ReadVulnerability Management
The continuous cycle of discovering assets, identifying weaknesses, prioritising by real risk, remediating and verifying.
ReadSecurity Operations
Security Awareness
Building the human capability to recognise and report social engineering, and measuring reporting rather than blame.
ReadSecurity Monitoring
Continuous collection and evaluation of telemetry to detect malicious or anomalous activity across every layer.
ReadSecurity Operations
The people, process and platform that monitor, triage, investigate and respond to security events continuously.
ReadSIEM
Security Information and Event Management centralises telemetry from across the estate, correlates it into detections, and supports investigation and reporting.
ReadSOAR
Security Orchestration, Automation and Response executes playbooks across tools to enrich, decide and act consistently.
ReadThreat Hunting
Proactively searching telemetry for adversary activity that automated detections have missed, driven by hypotheses rather than alerts.
ReadThreat Intelligence
Contextual knowledge about adversaries, their techniques and infrastructure, used to prioritise defence and guide detection.
Read