fig. 01 - the framework · the business stack

How we think about security.

{Layer10} is named for what we do: we're the tenth layer - security oversight that wraps around every other layer of your business. The Business Stack is how we see the companies we protect: not as servers and software, but as physical assets, operations, financial systems, intellectual property, people, customers and vendors, reputation, compliance obligations, and strategic direction. Each one is a layer of value. Each one needs protection.

Oversight is the baseline. When your business needs hands-on help - managing endpoints, running vulnerability scans, configuring security tools - we reach into any layer and operate. Build to fit means you decide where oversight stops and operations starts. We match your reality, not a brochure.

sec. 01 - the stack

Ten layers. One protective layer.

L1–3 are how you run the business. L4–6 are how you build it. L7–9 are how you lead it. L10 protects every one.

L1Assets
L2Operations
L3Financial
L4Intellectual
L5People
L6Customers, Vendors & Data
L7Reputation
L8Compliance
L9Strategy
L10{Layer10}
L1run

Physical assets

Your facilities, equipment, inventory, and supply chain. The foundation layer - everything your business physically relies on. A lock on the server room door is layer-1 security. So is vendor access to your warehouse.

OSI parallel → Physical layer (the wire)
sec. 02 - the tiers

Run · Build · Lead.

The stack groups naturally into three phases of business maturity.

Run · L1–L3

Assets, Operations, Financial. These are the layers every business must have to exist at all. Security here means protecting the ability to operate - keeping the lights on, the supply chain moving, the cash flowing.

Build · L4–L6

Intellectual Property, People, Customers, Vendors & Data. These are the value-creation layers. IP is what makes you unique. People are how you execute. Customers are why you exist. Security here means protecting competitive advantage and revenue.

Lead · L7–L9

Reputation, Compliance, Strategy. These are the strategic layers. Your brand, your license to operate, your direction of travel. Security here means protecting trust, staying out of regulatory trouble, and enabling confident growth.

sec. 03 - background

Where the ten layers come from.

{Layer10} grew out of networking. The OSI model - seven layers from physical wire to application logic - is how engineers think about communication. We extended it to ten because security doesn't stop at the application layer. The Business Stack translates that same idea: if your business were a network, here's how we'd protect it.

This is a metaphor, not a protocol. It's how we think - not a standard you need to learn.

OSI Physical → Physical assets - facilities, equipment, inventory
The wire is your facility. Both are foundational - if either fails, nothing above it works.
OSI Data Link → Operations - processes, workflows, delivery
Frames are your workflows. Both move things reliably from point A to point B.
OSI Network → Financial systems - payables, receivables, banking
Routing is your cash flow. Both direct where things go and find the best path.
OSI Transport → Intellectual property - designs, data, trade secrets
Segments are your proprietary data. Both must arrive intact, in order, uncorrupted.
OSI Session → People & access - employees, roles, credentials
Sessions are who you trust. Both establish identity, maintain it, and tear it down securely.
OSI Presentation → Customers, Vendors & Data - contracts, revenue, PII, third-party risk
Encoding is how you present to the world. A consistent, trusted external face - including the vendors you trust with your data.
OSI Application → Reputation & trust - brand, market position
Apps are what the user touches. Reputation is what the market touches. Same idea: you are what you deliver.
L8 - The user → Compliance & legal - regulatory, standards, audit
The user layer is the human context the stack operates within. For business, that context is regulation.
L9 - Management → Strategy & growth - direction, risk, governance
Someone has to steer. Management in networking is configurations and policies. In business, it's the boardroom.
L10 - Security oversight → {Layer10} - the protective layer across every business layer
No OSI parallel - because security oversight isn't built into the network. That's the gap {Layer10} exists to close.
sec. 04 - why it matters

A frame for your business, not our tools.

Most security providers show you their product and work backward to your problem. We start with your actual business layers - what you build, how you operate, where your value lives - and build the security from there. The Business Stack keeps us honest: if we can't name which layer of your business we're protecting, we haven't thought hard enough about what you need.

We also use AI to accelerate our own operations - threat correlation, report drafting, pattern detection - and every output is reviewed by a human who has run incident response. AI is a tool; we keep it in its toolbox.

Let's map your business stack.

Thirty minutes. We'll walk through your layers - physical to strategic - and show you what protection looks like at every one.

request_info{}