64f73371c9
New documents: - core/engagement-model.md: Full client-facing engagement lifecycle (Sections 1-6) plus consultant delivery discipline (Section 7) - core/consultant-field-guide.md: Decision models, client qualification, module selection, 10 common mistakes, technical onboarding, proposal writing - core/about-cqre.md: Company overview template with [PLACEHOLDER] markers for client-facing use - core/about-cqre-cs.md: Czech version of company overview (O společnosti CQRE) - core/executive-summary-cs.md: Czech translation of the board executive summary - assessment-templates/nist-csf-baseline.md: Full Brownhat Diagnostic workshop methodology (NIST CSF 2.0) - assessment-templates/nist-csf-baseline-cs.md: Czech version of Brownhat Diagnostic (for Czech-language workshops) - assessment-templates/module-completion-report.md: Module completion package template - assessment-templates/risk-register-example.md: 8 fully populated risk entries (Meridian Logistics GmbH fictional engagement) - playbooks/privileged-access-architecture.md: Module 13 - Teleport, Tailscale/Headscale, JIT access, vendor governance - playbooks/sovereign-communications.md: Module 14 - Delta Chat chatmail relay, Matrix/Element, crisis channels Updated documents: - playbooks/sovereign-tool-stack.md: Added Elysium, CAExporter, E8-CAT, macOS_IntuneManagement, IntunePolicyParser, M365-Scripts; updated capability matrix and module pairings - core/modular-engagements.md: Module 2 now includes CAExporter as first step; Module 6 includes Elysium password audit - reference/nist-csf-mapping.md: Added back-reference to nist-csf-baseline.md - assessment-templates/README.md: Changed Q1/Q2/Q3/Q4 to Phase 1/2/3/4, added Status column - index.md: Registered all new documents; restructured consultant navigation into three labeled groups (1-25) - README.md: Updated directory tree; updated Quick Start for Consultants Czech localization pointers: - executive-summary.md: Added Česká verze pointer - nist-csf-baseline.md: Added Česká verze pointer - engagement-model.md: Added note that client-facing Czech translation is planned Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
132 lines
10 KiB
Markdown
132 lines
10 KiB
Markdown
# Antifragile Enterprise Consulting Repository
|
||
|
||
> *"Wind extinguishes a candle and energizes fire. You want to be the fire and wish for the wind."* — Nassim Nicholas Taleb
|
||
|
||
This repository contains reusable frameworks, playbooks, and assessment resources for consulting engagements focused on building **antifragile organizations**—enterprises that do not merely survive disruption but grow stronger from it.
|
||
|
||
## What Is Antifragile?
|
||
|
||
Most security and resilience frameworks optimize for **robustness**—the ability to withstand shocks. Antifragility goes further. An antifragile system:
|
||
|
||
- **Benefits from volatility** and stressors
|
||
- **Learns faster** from failures than from successes
|
||
- **Decentralizes critical functions** to avoid single points of failure
|
||
- **Treats optionality as a strategic asset**, not overhead
|
||
|
||
## Repository Structure
|
||
|
||
```
|
||
├── core/ # Foundational frameworks and principles
|
||
│ ├── about-cqre.md # Company overview template — fill before sharing with clients
|
||
│ ├── about-cqre-cs.md # Czech version of company overview (O společnosti CQRE)
|
||
│ ├── move-fast-and-fix-things.md # Company philosophy: speed, repair, existing tools (Brownhat brand)
|
||
│ ├── engagement-model.md # How engagements work: lifecycle, deliverables, pricing, consultant discipline
|
||
│ ├── consultant-field-guide.md # Internal playbook: decision models, qualification, mistakes, technical onboarding
|
||
│ ├── antifragile-manifest.md # The five pillars of antifragile enterprise
|
||
│ ├── modular-engagements.md # Menu of independent, self-contained modules
|
||
│ ├── ai-sovereignty-framework.md # AI sovereignty as a strategic mandate
|
||
│ ├── ai-operations-inevitability.md # Why defensive AI is inevitable (business AI is optional)
|
||
│ ├── azure-openai-sovereignty-bridge.md # Azure OpenAI/Foundry as sovereignty stepping stone
|
||
│ ├── organizational-resilience.md # Dev/Sec/Ops merger and shift-left arguments
|
||
│ ├── quality-management-engagement.md # Embedded process assurance for teams feeling "not in control"
|
||
│ ├── blue-purple-team-foundation.md # Building defensive capability from existing tools
|
||
│ ├── retained-capability.md # What to keep in-house when outsourcing security (MSSP, pentest, compliance)
|
||
│ ├── executive-summary.md # One-page board brief
|
||
│ ├── executive-summary-cs.md # Czech version of board brief (Výkonné shrnutí)
|
||
│ ├── c-suite-conversation-guide.md # Persuasion scripts for top management
|
||
│ └── t0-asset-framework.md # Tier 0 asset classification and protection
|
||
├── playbooks/ # Executable modernisation and response plans
|
||
│ ├── rapid-modernisation-plan.md # 30-60-90-180 day transformation roadmap
|
||
│ ├── endpoint-management-entry-vector.md # Intune/device management as engagement entry point
|
||
│ ├── ai-assisted-tvm.md # AI-powered vulnerability management blueprint
|
||
│ ├── zero-budget-vulnerability-discovery.md # Script-based vuln discovery without commercial scanners
|
||
│ ├── perimeter-scanning-capability.md # External attack surface scanning strategy
|
||
│ ├── osquery-custom-platform.md # Build a sovereign vuln/asset discovery platform on osquery
|
||
│ ├── m365-antifragile-project.md # M365 greenfield/modernisation with antifragile design
|
||
│ ├── m365-e3-hardening.md # M365 E3-specific tactical hardening
|
||
│ ├── ad-endpoint-hardening.md # On-prem AD, Windows endpoint, hybrid identity
|
||
│ ├── zero-budget-hardening.md # Maximize existing tool investment
|
||
│ ├── implementation-playbook.md # Step-by-step operational guide
|
||
│ ├── sovereign-tool-stack.md # Open-source arsenal and capability map
|
||
│ ├── privileged-access-architecture.md # PAM: Teleport, Tailscale/Headscale, JIT access (Module 13)
|
||
│ ├── sovereign-communications.md # Delta Chat chatmail, Matrix/Element, crisis channels (Module 14)
|
||
│ └── business-case-template.md # Financial justification and ROI framework
|
||
├── assessment-templates/ # Diagnostic tools and maturity models
|
||
│ ├── README.md # Assessment roadmap and development plan
|
||
│ ├── nist-csf-baseline.md # The Brownhat Diagnostic: 2-half-day NIST CSF workshop (entry engagement)
|
||
│ ├── nist-csf-baseline-cs.md # Czech version of Brownhat Diagnostic workshop questionnaire
|
||
│ ├── module-completion-report.md # Template for the module completion package (every module)
|
||
│ ├── risk-register-example.md # 8 fully populated risk entries from a realistic engagement
|
||
│ ├── antifragile-risk-register.md # Antifragile risk taxonomy and register template
|
||
│ └── m365-project-risk-register.md # M365 project-specific risk register
|
||
├── reference/ # External standards, mappings, and citations
|
||
│ ├── cis-controls-mapping.md # CIS Controls v8 alignment
|
||
│ ├── nist-csf-mapping.md # NIST CSF 2.0 alignment
|
||
│ ├── vertical-power-utilities.md # Power generation, transmission, water utilities
|
||
│ ├── vertical-telco.md # Telecommunications and mobile operators
|
||
│ └── vertical-banking.md # Financial services regulatory alignment
|
||
└── assets/ # Diagrams, visuals, and presentation materials
|
||
```
|
||
|
||
## Our Posture: Move Fast and Fix Things
|
||
|
||
This practice is built on a simple, actionable stance: **move fast and fix things**. We do not wait for perfect plans. We identify the kill chain, extract value from existing investments, and close existential gaps before they become incidents.
|
||
|
||
- **Speed is a security control.** A 90% solution deployed today outperforms a 100% solution that ships in six months.
|
||
- **Work beats purchases.** Most organizations own 60-80% of the capabilities they need. We configure and operationalize before we shop.
|
||
- **Every fix must produce a signal.** A remediation without telemetry is a remediation that will rot.
|
||
|
||
Read the full [Move Fast and Fix Things](core/move-fast-and-fix-things.md) philosophy.
|
||
|
||
## Core Pillars
|
||
|
||
1. **[Structural Decoupling](core/antifragile-manifest.md#pillar-1-structural-decoupling)** — Remove hidden dependencies before they become fatal ones
|
||
2. **[Optionality Preservation](core/antifragile-manifest.md#pillar-2-optionality-preservation)** — Maintain strategic exits and alternatives at every layer
|
||
3. **[Stress-to-Signal Conversion](core/antifragile-manifest.md#pillar-3-stress-to-signal-conversion)** — Turn failures, attacks, and outages into intelligence
|
||
4. **[Sovereign Intelligence](core/antifragile-manifest.md#pillar-4-sovereign-intelligence)** — Own your cognitive infrastructure; never rent your ability to think
|
||
5. **[Asymmetric Payoff Design](core/antifragile-manifest.md#pillar-5-asymmetric-payoff-design)** — Engineer outcomes where small investments yield disproportionate protection
|
||
|
||
## Standards Alignment
|
||
|
||
Our approach is not an alternative to established frameworks. It is the fastest path to meeting them while building real resilience:
|
||
|
||
- **[CIS Controls v8](reference/cis-controls-mapping.md)** — IG1 as a non-negotiable 90-day floor, achieved primarily through existing tool configuration
|
||
- **[NIST CSF 2.0](reference/nist-csf-mapping.md)** — All six functions addressed with emphasis on GOVERN as the missing keystone
|
||
|
||
## Quick Start for Executives and Board Members
|
||
|
||
1. **Read** [Executive Summary](core/executive-summary.md) — one page, five minutes, the full case
|
||
2. **Review** [Business Case Template](playbooks/business-case-template.md) — financial justification, ROI, and risk quantification
|
||
3. **Browse** [C-Suite Conversation Guide](core/c-suite-conversation-guide.md) — how your advisors should frame the conversation
|
||
|
||
## Platform Independence
|
||
|
||
This framework is **platform-agnostic at the strategic level**. The Antifragile Manifest, assessment methodology, and Sovereign Tool Stack operate independently of any vendor ecosystem.
|
||
|
||
Many playbooks use Microsoft 365 as the reference environment because it is the most common client footprint (E3/Business Premium). Consultants working with Google Workspace, AWS-native, or mixed environments should read the **Platform Adaptation** appendix in [Modular Engagements](core/modular-engagements.md#platform-adaptation-non-microsoft-environments), which maps every M365-specific module to equivalent non-Microsoft tooling.
|
||
|
||
## Quick Start for Consultants
|
||
|
||
1. **Open** `core/move-fast-and-fix-things.md` — understand the engagement posture and the Brownhat brand
|
||
2. **Read** `core/engagement-model.md` — understand how engagements are structured, scoped, priced, and delivered
|
||
3. **Read** `core/consultant-field-guide.md` — internalize the decision models, learn to qualify clients, understand the common mistakes
|
||
4. **Read** `core/antifragile-manifest.md` — understand the philosophy
|
||
4. **Study** `core/modular-engagements.md` — the full module menu (Modules 1–14) and platform adaptation guide
|
||
5. **Run** `assessment-templates/nist-csf-baseline.md` — the Brownhat Diagnostic: mandatory entry engagement for every new client
|
||
6. **Study** `playbooks/sovereign-tool-stack.md` — the full tool arsenal, commercial partnerships, and when to use each
|
||
7. **Study** `playbooks/m365-e3-hardening.md` — primary client environment for MS clients (most are E3)
|
||
8. **Study** `playbooks/ad-endpoint-hardening.md` — on-premises AD and endpoint gaps
|
||
9. **Study** `playbooks/zero-budget-hardening.md` — extract value from existing tools in 30 days
|
||
10. **Deploy** `playbooks/rapid-modernisation-plan.md` — run the 30-60-90-180 day roadmap
|
||
11. **Reference** `core/t0-asset-framework.md` and `core/ai-sovereignty-framework.md` — classify assets and own intelligence
|
||
12. **Map** `reference/cis-controls-mapping.md` and `reference/nist-csf-mapping.md` — align to standards
|
||
13. **Adapt** `reference/vertical-power-utilities.md`, `reference/vertical-telco.md`, or `reference/vertical-banking.md` — tailor for regulated critical infrastructure clients
|
||
|
||
## Usage and Licensing
|
||
|
||
These documents are designed for reuse across client engagements. Adapt, remix, and extend. Credit the framework when presenting externally.
|
||
|
||
---
|
||
|
||
*Built for practitioners who defend the future, not just the perimeter.*
|