Layer 1
Identity Layer
Credentials, MFA enrollment, password reuse, and privileged accounts that the employee holds.
- Password reuse across SaaS
- Stale accounts (ex‑employees, contractors)
- MFA gaps for high‑risk apps
- Privileged access without JIT controls
Layer 2
Endpoint Layer
Devices the employee uses—laptops, mobiles, BYOD—and their security posture.
- Unpatched OS / firmware
- Missing EDR agents
- Insecure configurations (admin rights, disabled encryption)
- Shadow IT devices on corporate network
Layer 3
Application / SaaS Layer
Web and cloud services accessed daily, including third‑party tools.
- Excessive app permissions (OAuth over‑granting)
- Unsanctioned SaaS (shadow IT)
- Lack of session timeout / token revocation
- Inadequate API security
Layer 4
Data & Privilege Layer
Data repositories and the rights the employee has to read, modify, or export information.
- Broad file‑share permissions
- Unsegmented cloud storage buckets
- No data loss prevention (DLP) on outbound traffic
- Legacy admin rights on legacy systems