How Does Defensible 10 Apply to Your Industry?

Introducing D10S Applied Industries
Every industry depends on its own combination of systems, devices, applications, data, identities, operational processes, and supporting technologies, but all ten cybersecurity domains must still work together to protect them. D10S Applied Across Industry Sectors is a new research-driven program that translates the Defensible 10 Standards into sector-aware guidance practitioners can recognize and use, beginning with Healthcare and expanding into Manufacturing, Financial Services, Energy & Utilities, and Transportation.
The Challenge Is Not the Framework. It Is the Translation.
Cybersecurity frameworks and standards provide essential outcomes, governance expectations, and risk-management foundations. The NIST Cybersecurity Framework 2.0, ISO/IEC 27001, and sector requirements give organizations important direction for managing cybersecurity risk.
The practical challenge begins when practitioners must determine what those expectations mean inside the systems that make their industry operate.
A healthcare organization must connect cybersecurity requirements to networked medical devices, clinical platforms, patient data, emergency access, and care-delivery dependencies.
A manufacturer must apply them across production cells, industrial control systems, engineering workstations, plant networks, and safety systems.
A financial institution must interpret them across payment rails, trading platforms, transaction data, customer identities, APIs, and third-party processors.
The cybersecurity outcomes may be broadly applicable, but the systems, dependencies, technologies, and operational consequences are sector-specific.
When that translation is incomplete, important relationships can remain hidden. Security may be introduced after architecture or acquisition decisions have already been made.
Teams may address domains independently while missing the dependencies between them. Boundaries involving suppliers, operators, applications, cloud services, and third parties can become technical blind spots.
D10S Applied Makes the Sector Relationship Visible
D10S Applied begins with the industry, not with an isolated control, product, or technology.
The program first identifies the distinctive architecture elements that support the sector. It then shows where each Defensible 10 domain appears, what it supports, and how it integrates with the complete security system.
This helps practitioners understand:
Where each domain appears: Connect D01 through D10 to familiar sector systems and operations.
What each domain supports: Relate the domains to data, identities, devices, applications, services, and dependencies.
How the domains integrate: Expose cross-domain relationships instead of presenting security as isolated control lists.
Where to continue: Connect the sector guide to the applicable Defensible 10 Parent Standards, Associate Standards, Evidence Workbooks, and supporting sector guidance.
The practical value is a clearer path from general cybersecurity language to a sector-aware explanation practitioners can apply to the environments they know.
Research First. Practitioner Guidance Second.
Each D10S Applied Sector Security Guide will be supported by research conducted through PatternArc, the research technology platform of the ISAUnited Technical Research Center.
PatternArc provides the structured environment for collecting evidence, identifying sector architecture elements, developing D10S crosswalks, and preserving traceability from the research foundation to the public guide.
The technology supports the research process; it does not determine the conclusions. ISAUnited researchers and participating practitioners evaluate the evidence, examine the architecture relationships, and develop the final guidance.
The research-to-guide path follows four stages:
Sector research: Gather authoritative evidence about the industry, its operating environment, and its cybersecurity dependencies.
Architecture elements: Identify the systems, technologies, data, identities, devices, services, and dependencies that make the sector distinctive.
D10S crosswalk: Determine where all ten domains appear and how their architecture relationships intersect.
Applied Sector Guide: Translate the research into a concise, readable, and traceable practitioner explanation.
This approach preserves the research depth behind each guide without requiring practitioners to work through complex research instruments or analytical workbooks.
One Governing Principle: All Ten Domains Apply
Every D10S Applied Sector Security Guide follows one governing principle:
'All ten D10S domains apply. What changes is where each domain appears, which sector elements depend on it, how the domains interact, and how much explanation the practitioner guide provides.'
An industry may place greater operational emphasis on certain domains, but none of the ten disappears from the security foundation.
Healthcare still depends on network architecture, cloud services, compute platforms, applications, data protection, identity and access, threat and vulnerability management, monitoring and response, cryptographic trust, and secure system change.
The same is true for manufacturing, financial services, energy and utilities, transportation, and every other modern sector.
Different environments create different relationships, not optional cybersecurity domains.
Industry First. Technology in Context.
D10S Applied intentionally begins with the industry sector as the parent adoption context.
Technologies such as artificial intelligence, API ecosystems, IoT and edge computing, enterprise low-code platforms, and distributed systems will be examined as they appear within sector architectures and support sector operations.
For example:
IoT and edge technologies may appear as networked medical devices in Healthcare, field devices in Energy, or connected equipment in Manufacturing.
APIs may support financial transactions, clinical data exchange, transportation platforms, or third-party service integration.
Artificial intelligence may influence diagnostic systems, fraud detection, industrial automation, operational forecasting, or monitoring and response.
Distributed systems may support payment processing, healthcare services, energy operations, and transportation platforms.
Starting with the sector prevents these technologies from being examined as isolated trends. It keeps the analysis connected to operational purpose, architecture dependencies, cybersecurity responsibilities, and real-world consequences.
What the Sector Security Guides Will—and Will Not—Do
D10S Applied Sector Security Guides are intended to help practitioners understand how the Defensible 10 domains relate to their industry environments.
The guides will:
Map all ten D10S domains to recognizable sector architecture elements.
Explain cross-domain interactions and systemic dependencies.
Provide vendor-neutral, practitioner-oriented guidance.
Support earlier cybersecurity consideration during acquisition, architecture, engineering, deployment, operations, and system change.
Connect readers to applicable D10S standards and supporting guidance.
Complement existing cybersecurity frameworks, sector standards, safety requirements, and regulatory obligations.
The guides will not:
Assess an organization: They will not score or grade organizational maturity or compliance.
Serve as implementation manuals: They will not provide step-by-step product configurations.
Prescribe vendors: They will not require particular products, platforms, or service providers.
Interpret regulations: They will not provide legal advice or replace jurisdictional requirements.
Replace existing standards: They are designed to work alongside NIST, ISO, HIPAA, NERC CIP, and other applicable sources.
The guides explain the sector relationship. Organizations remain responsible for determining their specific implementation, risk, compliance, and operational requirements.
Healthcare Will Lead the Program
The first planned D10S Applied Sector Security Guide will focus on Healthcare.
Healthcare combines networked medical devices, clinical platforms, sensitive patient and telemetry data, cloud services, legacy technologies, third-party dependencies, emergency access, and immediate care-delivery requirements.
This makes Healthcare an important starting point for demonstrating how all ten cybersecurity domains operate as one integrated security foundation.
Following the Healthcare pilot, planned sector guides will address:
Manufacturing: Production cells, industrial control, engineering stations, plant networks, and safety systems.
Financial Services: Payments, trading platforms, transaction data, APIs, and customer identity.
Energy & Utilities: Grid and plant operations, field devices, OT networks, and control telemetry.
Transportation: Fleets, terminals, signaling, passenger systems, and operational platforms.
What Comes Next
The ISAUnited Technical Research Center and ISAU Task Group 70 are developing the research foundation, crosswalk method, and practitioner-guide structure supporting D10S Applied Across Industry Sectors.
Defensible10.org will publish the D10S Applied research whitepaper, Healthcare pilot information, and upcoming Sector Security Guides as they become available.
In the meantime, practitioners and organizations can:
Explore the core standards: Review the Defensible 10 Parent Standards and learn how the ten domains establish a unified cybersecurity architecture and engineering foundation.
Understand implementation and proof: Explore the D10S Evidence Workbooks and their role in verification, validation, and structured evidence.
Follow the program: Watch Defensible 10 News for the whitepaper, Healthcare pilot, guide previews, and future participation opportunities.
NOTE: An Open Call for Industry Expertise Is Coming
D10S Applied will be strengthened by practitioners who understand how their industries operate. An open call will invite qualified industry technical experts, including cybersecurity practitioners, architects, engineers, operators, and sector specialists, to help identify sector elements, validate D10S domain relationships, and contribute to the development and technical review of upcoming Sector Security Guides.
Stay tuned to Defensible10.org for guide priorities, participation criteria, and open-call details.
See your industry through all ten domains.
D10S Applied Across Industry Sectors is coming soon to Defensible10.org.
Research foundation: ISAUnited Technical Research Center and ISAU Task Group 70.

