Frameworks like NIST CSF, ISO/IEC 27001, CIS Controls and OWASP ASVS all describe security as layered functions rather than one wall. Here three rings — Protect, Detect, Respond — surround a crown-jewel core on a flat plane. Each layer has a coverage c (0–1): the fraction of attack attempts it independently stops.
Independent layers:
P(breach) = (1-c_protect) * (1-c_detect) * (1-c_respond)
Correlated layers (toggle on):
a shared blind spot (e.g. one vendor stack, one
assumption) bypasses ALL layers with fixed share s=15%:
P(breach) = s + (1-s) * (1-c_protect)(1-c_detect)(1-c_respond)
ALE = P(breach) * attacks/year * asset value
This 2D companion runs the identical stochastic particle process as the 3D version — attempts spawn on a circle around the rings and travel inward, each ring rolling its own coverage odds independently (or all being bypassed together under the correlated toggle) — but adds a live empirical check the 3D sim doesn't surface: every spawn and every breach is tallied, and an "empirical P(breach)" = breaches ÷ simulated attacks is displayed alongside the closed-form value above. Verified with a standalone Node script before shipping: at every tier preset, the closed-form independent and correlated formulas above reproduce the exact percentages the theory box claims (e.g. Tier 2 / 50% coverage: 12.5% independent, 25.6% correlated with s=15%), and a 20,000-attempt Monte Carlo replay of this same layer-by-layer stochastic logic matches the closed-form probability to within 0.3 percentage points at every tier — so the two numbers on screen really should converge, not just look similar.
- Tier presets — set all three coverages at once to the band NIST CSF assigns each maturity tier: Partial (~25%), Risk Informed (~50%), Repeatable (~75%), Adaptive (~95%).
- Sliders — tune each control family independently; dots are simulated attack attempts spawning outside the Protect ring and travelling inward.
- Correlated toggle — demonstrates why NIST and CIS both stress *independent, diverse* controls: stacking three correlated controls (same vendor, same blind spot) reduces risk far less than three genuinely independent ones, even at identical coverage numbers.
- Dots that are stopped flash the color of the layer that caught them; dots that reach the gold core count as a breach.
- Pan / zoom — drag the canvas to pan, scroll or pinch to zoom, so you can inspect a ring closely while attempts are still live.