CT4-DEFENSE™
The 6-layer cyber defense model — 3 asset layers + 3 capability layers.
CT4-DEFENSE™ — Defined
CT4-DEFENSE™ is the spatial map of cybersecurity. It answers a deceptively simple question: where exactly are your controls?
The framework divides cybersecurity into six layers — three asset layers (what you protect) and three capability layers (how you protect it). The asset layers are nested: Identity is what wraps every interaction with Infrastructure, which itself houses Data. The capability layers are operational: Security Operations watches everything; Resilience prepares for failure; Testing validates that defenses actually work.
"Attackers don't break in — they log in." That single insight, drawn from a decade of incident response work, drives the architecture of CT4-DEFENSE™. Identity is no longer a layer of cybersecurity — it is the central battlefield.
The Building Blocks
-
Asset Layer 1 — Data
The crown jewels. Classification, encryption (at rest, in transit, in use), DLP, rights management, sensitive data discovery. Data is what attackers ultimately want.
-
Asset Layer 2 — Infrastructure
Network, systems, applications, cloud. Segmentation, hardening, patch management, configuration management. The terrain on which everything happens.
-
Asset Layer 3 — Identity
The new perimeter. IAM, MFA, PAM, identity governance, conditional access, zero trust. Most modern attacks succeed because identity controls failed — not because firewalls were bypassed.
-
Capability Layer 1 — Security Operations
The eyes. SIEM, SOAR, SOC, EDR/XDR, threat intelligence, incident detection. Real-time visibility into what is happening across the asset layers.
-
Capability Layer 2 — Resilience
The recovery muscle. Backup & restore, business continuity, disaster recovery, incident response. The controls that activate when prevention fails — and prevention will fail.
-
Capability Layer 3 — Testing & Assurance
The proof. Penetration testing, red teaming, breach simulations, control validation, compliance audits. The controls you have not tested are not controls — they are theories.
The Strategic Impact
Most security architectures are stacks of disconnected tools. CT4-DEFENSE™ provides the unifying spatial logic: every tool, every control, every project must map to one of the six layers. This makes coverage gaps visible. It surfaces redundant tools. And it forces budget discussions to be about layers, not vendors.
From Theory to Practice
Map your existing controls into the 6-layer model. You will discover three things: (1) one or two layers are heavily over-resourced; (2) one or two layers have alarming gaps; (3) the capability layers are almost always weaker than the asset layers. Re-balance investment toward the gaps. Pay particular attention to the Identity asset layer and the Resilience capability layer — these are the most commonly underbuilt across SMBs.
Apply CT4-DEFENSE
Read the chapter. Try the framework. Engage the team that built it.