Initial commit: establishing the cqre.net perimeter

This commit is contained in:
2026-06-15 07:59:56 +02:00
commit 7aed2b4f70
65 changed files with 5131 additions and 0 deletions
+14
View File
@@ -0,0 +1,14 @@
# macOS
.DS_Store
# Hugo build output
/public/
/resources/_gen/
# Hugo lock file
.hugo_build.lock
# Hugo binaries
hugo.exe
hugo.darwin
hugo.linux
+161
View File
@@ -0,0 +1,161 @@
# CQRE.NET Website — Agent Guide
## Project Overview
This is the static site for [cqre.net](https://cqre.net), built with [Hugo](https://gohugo.io/). It is a bilingual (English and Czech) corporate website for CQRE.NET Ltd, a UK-registered cybersecurity consultancy operating primarily from Prague. The site promotes:
- **Open-source M365 governance tools**: PULSAR (audit log ingestion), ASTRAL (configuration snapshots / drift detection), and AURORA (commercial AI-assisted operations layer).
- **Consulting services**: Antifragile security consulting under the Brownhat methodology, and fractional vCISO engagements.
The site is intentionally simple: no JavaScript frameworks, no npm, no asset pipelines beyond Hugo itself. A single hand-written CSS file drives the dark-themed UI.
## Technology Stack
| Layer | Technology |
|-------|------------|
| Static Site Generator | Hugo Extended, v0.120+ |
| Templating | Hugo Go Templates |
| Styling | Single vanilla CSS file (`static/css/main.css`) |
| Content Format | Markdown with YAML front matter |
| Translations | Hugo i18n (`i18n/en.yaml`, `i18n/cs.yaml`) |
| Hosting | Static — deploy the `public/` directory |
## Project Structure
```
.
├── hugo.yaml # Site config: baseURL, languages, params, markup
├── content/
│ ├── en/ # English content (default language)
│ │ ├── _index.md # Homepage (front-matter only, no body)
│ │ ├── about.md # About & contact
│ │ ├── vciso.md # Virtual CISO service page
│ │ ├── consulting/
│ │ │ ├── _index.md # Consulting methodology
│ │ │ └── skills.md # 14 consulting modules listing
│ │ └── products/
│ │ ├── _index.md # Products overview
│ │ ├── pulsar.md
│ │ ├── astral.md
│ │ └── aurora.md
│ └── cs/ # Czech content — mirrors en/ structure exactly
├── layouts/
│ ├── _default/
│ │ ├── baseof.html # Base HTML skeleton (head, header, footer blocks)
│ │ ├── single.html # Single page template (products, about, vciso)
│ │ └── list.html # Section list template (consulting/, products/)
│ ├── index.html # Homepage layout (heavily custom)
│ └── partials/
│ ├── head.html # Meta tags, CSS link, favicon
│ ├── header.html # Sticky nav with language switcher
│ └── footer.html # Footer links and copyright
├── i18n/
│ ├── en.yaml # English UI strings (nav, buttons, labels)
│ └── cs.yaml # Czech UI strings
└── static/css/main.css # Complete site stylesheet (dark theme, ~400 lines)
```
## Build and Development Commands
**Prerequisite**: Hugo Extended edition must be installed (v0.120 or newer).
```bash
# Local development server with draft content
hugo server -D
# Site is available at http://localhost:1313
# Production build (minified)
hugo --minify
# Output is written to public/
```
There is no test suite, no linting, and no package manager. The build is a single Hugo invocation.
## Content Editing Conventions
### Front Matter
Every content file uses YAML front matter. Common fields:
| Field | Purpose |
|-------|---------|
| `title` | Page title (used in `<title>`, headings, navigation) |
| `description` | Meta description and SEO |
| `eyebrow` | Small label above the main heading on single pages |
| `lead` | Introductory paragraph below the heading |
| `actions` | Array of CTA buttons `{ label, url, primary, external }` |
| `icon` | Emoji displayed in product cards |
| `badge` | Product badge `{ text, color }` where color is `green`, `orange`, or `blue` |
The homepage (`_index.md`) has no Markdown body. All homepage content is defined in front matter and rendered by `layouts/index.html`.
### Rich Layouts in Markdown
Because `markup.goldmark.renderer.unsafe` is enabled in `hugo.yaml`, content files may contain raw HTML for layout components. Common patterns:
- **Feature lists**: `<div class="feature-list">` containing `<div class="feature-item">` with an icon div and body div.
- **Pillars**: `<div class="pillars">` containing `<div class="pillar">` with a numbered heading.
- **Module grids**: `<div class="modules-grid">` containing `<div class="module-card">` with metadata badges.
- **CTA strips**: `<div class="cta-strip">` with a heading, paragraph, and action buttons.
When editing content that uses these blocks, preserve the CSS class names exactly — they are tightly coupled to `static/css/main.css`.
### Bilingual Content
- English is the default language (`defaultContentLanguage: en`).
- Czech content lives under `content/cs/` and mirrors the English structure file-for-file.
- The header partial generates language switcher links automatically via `.Translations`.
- Internal links in templates must use `relLangURL` to preserve the correct language prefix.
- UI strings (navigation labels, buttons, footer text) live in `i18n/en.yaml` and `i18n/cs.yaml`.
When adding a new page, create it in **both** `content/en/` and `content/cs/` and add any new UI strings to both i18n files.
## Code Style Guidelines
### Templates
- Use 2-space indentation in all HTML and Go template files.
- Prefer `relLangURL` for all internal links so language switching works correctly.
- Use `i18n` function for all user-facing strings in templates.
- The `baseof.html` layout defines a `main` block; all page templates override it with `{{ define "main" }}`.
### CSS
- The entire site uses a single stylesheet: `static/css/main.css`. Do not add additional CSS files.
- The design is a dark theme based on CSS custom properties in `:root` (navy backgrounds, sky-blue accent, muted text).
- Utility classes exist at the bottom of the file (e.g., `.mt-4`, `.text-center`).
- Keep CSS simple and dependency-free.
### Markdown / Content
- Use standard Markdown for prose.
- Use tables for structured comparisons (the about page uses this for principles).
- When embedding HTML in Markdown, keep it well-indented and use the established component classes.
## Testing
There are no automated tests. Verify changes by:
1. Running `hugo server -D`.
2. Checking both language versions of affected pages.
3. Testing responsive layout at mobile widths (the CSS has breakpoints at 768px and 480px).
4. Verifying internal links and the language switcher work correctly.
## Deployment
The `public/` directory is the deployable artifact. Copy it to any static web host.
The README includes an example Gitea Actions workflow (`.gitea/workflows/deploy.yml`) for self-hosted Gitea instances. The repo is also mirrored to GitHub (`github.com/cqrenet`).
## Security Considerations
- **`unsafe: true` is enabled** in the Goldmark renderer (`hugo.yaml`). This allows raw HTML inside Markdown content files. It is required because pages use rich layout components (feature lists, module grids, etc.) written as inline HTML. Do not disable this setting without migrating those components to shortcodes.
- The site has **no backend, no forms, and no user data collection**. It is a purely static read-only site.
- External links use `target="_blank" rel="noopener"` (generated by the `single.html` template when `external: true` is set in front matter).
- The favicon is an inline SVG data URI containing a lock emoji — no external image request.
## External References
- **GitHub org**: https://github.com/cqrenet
- **Gitea**: https://git.cqre.net
- **Contact email**: hello@cqre.net
+77
View File
@@ -0,0 +1,77 @@
# CQRE.NET Website
Hugo static site for [cqre.net](https://cqre.net). Bilingual: English and Czech.
## Prerequisites
- [Hugo](https://gohugo.io/installation/) extended edition, v0.120+
## Local development
```bash
hugo server -D
```
The site will be available at http://localhost:1313.
## Build
```bash
hugo --minify
```
Output goes to `public/`. Deploy the `public/` directory to your web server or static hosting.
## Structure
```
content/
en/ # English content
_index.md # Home page
products/ # PULSAR, ASTRAL, AURORA
consulting/ # Antifragile consulting + skills
vciso.md # Virtual CISO page
about.md # About & contact
cs/ # Czech content (mirrors en/ structure)
layouts/ # Hugo templates
static/css/ # Stylesheet (single file)
i18n/ # Translation strings (en.yaml, cs.yaml)
hugo.yaml # Site config
```
## Editing content
All content is in Markdown files under `content/en/` and `content/cs/`. Front matter (the `---` block at the top) controls page title, description, hero text, and actions. The page body is standard Markdown.
To add a page: create a `.md` file in the appropriate section directory. Hugo picks it up automatically.
## Language switching
The language switcher in the navigation links to the translated version of the current page. Translations are in `i18n/en.yaml` and `i18n/cs.yaml`.
## Deployment on Gitea / self-hosted
Push this repository to your Gitea instance. For automatic deployment, configure a Gitea Action or webhook that runs `hugo --minify` and copies `public/` to your web root.
Example Gitea Actions workflow (`.gitea/workflows/deploy.yml`):
```yaml
name: Deploy
on:
push:
branches: [main]
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: peaceiris/actions-hugo@v3
with:
hugo-version: 'latest'
extended: true
- run: hugo --minify
- name: Deploy
# Add your deployment step here (rsync, scp, etc.)
run: echo "Deploy public/ to your server"
```
+16
View File
@@ -0,0 +1,16 @@
---
heroTitle: "Antifragilní kybernetická bezpečnost"
heroSub: "Open-source nástroje pro správu M365. Praktické poradenství. Bezpečnost, která se z každého narušení stává silnější."
productsTitle: "Sada nástrojů pro správu M365"
productsSub: "Tři komplementární nástroje — PULSAR, ASTRAL a AURORA — které dohromady odpovídají na každou otázku o tom, co se stalo a co se změnilo ve vašem Microsoft 365 tenantovi."
pulsarTagline: "Co se stalo, kdy a kdo to udělal?"
astralTagline: "Jak vypadá moje konfigurace a co se změnilo?"
auroraTagline: "Co to znamená a co mám dělat?"
pulsarDesc: "Průběžná ingesta auditních logů M365 s neomezenou dobou uchování, vyhledávacím rozhraním, REST API, upozorněními, SIEM forwarding a MCP serverem pro dotazování pomocí AI."
astralDesc: "Git-sledované snímky konfigurace M365. Automatická detekce drift, workflow pro revizi pomocí PR, obnovení základní linie a neomezená historie."
auroraDesc: "Sjednocená AI vrstva propojující PULSAR a ASTRAL. Diagnostika napříč nástroji, podpora více scopů, obohacené SIEM forwarding."
servicesTitle: "Bezpečnost, která sílí"
servicesSub: "Poradenské a strategické služby postavené na jednom principu: každé narušení by mělo vaši organizaci zanechat schopnější než dříve."
consultingDesc: "Metodika Brownhat — začínáme tím, co vlastníte, uzavíráme útočný řetězec, budujeme schopnosti, které u vás zůstanou. Modulární angažmá od 30 dní výše."
vcisoDesc: "Frakcionální bezpečnostní vedení pro organizace, které potřebují strategické směřování bez plného pracovního úvazku. Vlastnictví rizik, reporting vedení, správa dodavatelů."
---
+52
View File
@@ -0,0 +1,52 @@
---
title: "O společnosti CQRE"
description: "Specializovaná poradenská společnost v oblasti kybernetické bezpečnosti a vývojář open-source nástrojů. Antifragilní bezpečnost pro organizace, které přerostly generické rady."
eyebrow: "O nás"
lead: "CQRE.NET Ltd je specializovaná poradenská společnost v oblasti kybernetické bezpečnosti registrovaná ve Velké Británii, působící primárně z Prahy. Pracujeme s organizacemi po celé střední Evropě a Velké Británii."
---
## Kdo jsme
Pomáháme organizacím překlenout propast mezi jejich investicemi do bezpečnosti a jejich skutečnou bezpečnostní pozicí. V praxi to znamená upřímné auditování toho, co existuje — ne toho, co politiky říkají, že by mělo existovat — maximalizaci hodnoty z již zakoupených nástrojů a budování schopností uvnitř klientských organizací, ne závislostí na nás.
Vůči klientům vystupujeme pod značkou **Brownhat** — název odráží naši základní filozofii: pracujeme v brownfield prostředích (zavedených, obydlených, nesoucích tíhu minulých rozhodnutí) a naším úkolem je kultivovat to, co existuje, dříve než cokoliv doporučíme koupit.
Budujeme také open-source nástroje — **PULSAR** a **ASTRAL** — používané M365 administrátory a bezpečnostními týmy, kteří potřebují průběžné uchovávání auditních logů a správu konfigurace bez vendor lock-in. **AURORA**, naše komerční intelligence vrstva, sedí nad oběma.
## Jak přemýšlíme
Pět principů formuje každé naše doporučení:
| Princip | Co to znamená v praxi |
|---------|----------------------|
| **Strukturální oddělení** | Identifikujeme a odstraňujeme skryté závislosti dříve, než se stanou fatálními. Nepřidáváme složitost, která vytváří nové závislosti. |
| **Zachování opcí** | Investujeme váš rozpočet do věcí, které zachovávají vaši schopnost změnit směr. Každý zbytečný nákup snižuje strategickou flexibilitu. |
| **Přeměna stresu na signál** | Každý incident, selhání a téměř-miss jsou zpravodajství. Budujeme systémy, které se z narušení učí. |
| **Svrchované zpravodajství** | Vaše proprietární data by měla zlepšovat vaše vlastní schopnosti, nikoli model dodavatele. |
| **Design asymetrického výnosu** | Malé, cílené investice do existenčních rizik přinášejí nepřiměřenou ochranu. Soustřeďujeme úsilí tam, kde by selhání bylo fatální. |
## Co neděláme
**Neprovozujeme 24/7 operační centrum.** Nasazujeme, konfigurujeme a zprovozňujeme monitorovací nástroje. Pro nepřetržitou řízenou odezvu spolupracujeme s komerčními partnery nebo pomáháme klientům budovat interní schopnost.
**Nepodepisujeme compliance audity.** Připravujeme klienty na audity — mapujeme kontroly, budujeme balíčky důkazů a uzavíráme mezery. Auditní stanovisko náleží kvalifikovanému auditorovi.
**Nenahradzujeme váš IT tým.** Pracujeme po boku vašich lidí, předáváme znalosti v průběhu angažmá a odcházíme, když angažmá skončí. Váš tým musí být schopen provozovat to, co jsme vybudovali.
**Zveřejňujeme naše obchodní vztahy.** Máme obchodní partnerství s Huntress, Tailscale, Thinkst Canary a Tenable. Pokud doporučujeme jeden z těchto nástrojů, říkáme to a vysvětlujeme, proč open-source alternativa neodpovídá konkrétní potřebě.
## Kontakt {#contact}
Nejlepší způsob, jak začít, je poslat nám zprávu popisující vaši situaci. Odpovíme upřímným hodnocením toho, zda a jak vám můžeme pomoci.
| | |
|-|-|
| **E-mail** | hello@cqre.net |
| **Web** | cqre.net |
| **Jazyky** | Čeština, angličtina |
| **Geografie** | Česká republika, Slovensko, Velká Británie; vzdálená angažmá po celé EU |
| **Doba odezvy** | Počáteční odpověď do 1 pracovního dne |
Pro otázky, hlášení chyb a příspěvky k open-source nástrojům prosím použijte přímo GitHub repozitáře:
- [github.com/cqrenet/pulsar](https://github.com/cqrenet/pulsar)
- [github.com/cqrenet/astral](https://github.com/cqrenet/astral)
+74
View File
@@ -0,0 +1,74 @@
---
title: "Antifragilní poradenství"
description: "Metodika Brownhat — modulární bezpečnostní poradenství, které začíná tím, co vlastníte, uzavírá útočný řetězec a buduje schopnosti, které u vás zůstanou."
eyebrow: "Metodika Brownhat"
lead: "Pomáháme organizacím překlenout propast mezi jejich investicemi do bezpečnosti a jejich skutečnou bezpečnostní pozicí. Každé angažmá začíná diagnostikou. Žádná doporučení, dokud nerozumíme prostředí."
---
## Princip antifragilnosti
Většina bezpečnostních programů optimalizuje pro robustnost — schopnost odolat otřesům. Antifragilita jde dále. Antifragilní organizace nejen přežívá narušení. **Z každého narušení vychází silnější.**
Každý incident produkuje strukturální zlepšení. Každý neúspěch konkurence vytváří tržní příležitost. Každý regulatorní požadavek je splněn důkazy, ne sliby.
## Pět pilířů
<div class="pillars">
<div class="pillar">
<div class="pillar-num">01</div>
<h4>Strukturální oddělení</h4>
<p>Identifikujeme a odstraňujeme skryté závislosti dříve, než se stanou fatálními. Nepřidáváme složitost, která vytváří nové závislosti.</p>
</div>
<div class="pillar">
<div class="pillar-num">02</div>
<h4>Zachování opcí</h4>
<p>Investujeme váš rozpočet do věcí, které zachovávají vaši schopnost změnit směr. Každý zbytečný nákup nástroje snižuje strategickou flexibilitu.</p>
</div>
<div class="pillar">
<div class="pillar-num">03</div>
<h4>Přeměna stresu na signál</h4>
<p>Každý incident, selhání a téměř-miss jsou zpravodajství. Budujeme systémy, které se z narušení učí, místo aby ho jen přežily.</p>
</div>
<div class="pillar">
<div class="pillar-num">04</div>
<h4>Svrchované zpravodajství</h4>
<p>Vaše proprietární data by měla zlepšovat vaše vlastní schopnosti, nikoli model dodavatele. Vlastněte nástroje a systémy, na kterých závisíte.</p>
</div>
<div class="pillar">
<div class="pillar-num">05</div>
<h4>Design asymetrického výnosu</h4>
<p>Malé, cílené investice do existenčních rizik přinášejí nepřiměřenou ochranu. Soustřeďujeme úsilí tam, kde by selhání bylo fatální.</p>
</div>
</div>
## Jak angažmá fungují
Neprodáváme monolitické transformační projekty. Prodáváme **nezávislé moduly, které se skládají**. Každý modul přináší měřitelnou hodnotu za 30–90 dní a vytváří přirozený apetit pro další fázi.
Každé angažmá začíná **Brownhat Diagnostikou** — strukturovaným dvoudenním hodnocením základní linie NIST CSF 2.0, které přinese upřímný, prioritizovaný obraz situace organizace. Neposkytujeme doporučení modulů, dokud nerozumíme prostředí.
**Co každé angažmá produkuje:** definovaný rozsah, definovaný výstup a aktiva dodaná do vašeho vlastního repozitáře. Každý skript, pravidlo detekce, konfigurace a runbook, který vytvoříme, patří vám. Když angažmá skončí, jste provozně nezávislí.
## Soulad se standardy
Sada modulů Brownhat se přímo mapuje na hlavní regulatorní rámce:
- **NIS2 (EU 2022/2555)** — opatření dle čl. 21: správa konfigurace (ASTRAL), protokolování a monitoring (PULSAR), řízení přístupu, detekce incidentů
- **DORA (EU 2022/2554)** — záznamy o správě ICT změn (Git stopa ASTRAL), uchovávání auditních logů (PULSAR), správa rizik třetích stran v oblasti ICT
- **GDPR čl. 32** — průběžné řízení konfigurace a uchovávání auditních logů jako „vhodná technická opatření"
- **ISO 27001** — A.8.9 správa konfigurace, A.8.15 protokolování; důkazy o kontrolách jako přirozený výstup angažmá
## Brownfield track
Hlavní model angažmá předpokládá konzultanta vcházejícího do podnikové infrastruktury někoho jiného. Brownfield Handbook aplikuje stejnou metodiku na infrastrukturu, kterou jste vybudovali sami — self-hostovaný stack, který se postupně vrstvil, homelab, který se stal produkcí, jeden server, na němž tiše visí vše ostatní. Discovery pozorováním, prořezávání, mazlíčci versus dobytek, rebuildability a záměrný stres: antifragilní pětidílný oblouk aplikovaný na infrastrukturu, kterou nikdo nenavrhl.
Tento track je pro self-hostery, malé platformy a týmy, které potřebují antifragizovat vlastní organicky vzniklou infrastrukturu — a chtějí celou metodiku validovat na prostředí, kde jsou důsledky jejich.
<div class="cta-strip">
<h2>Začněte Brownhat Diagnostikou</h2>
<p>Vstupní bod pro každého nového klienta. Strukturované dvoudenní hodnocení, které přinese prioritizovaný obraz vaší situace a doporučené pořadí modulů.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+76
View File
@@ -0,0 +1,76 @@
---
title: "Modul 0 — Brownhat Diagnostika"
description: "Vstupní bod každého angažmá. Strukturované dvoudenní hodnocení NIST CSF 2.0, které produkuje prioritizovaný bezpečnostní plán, zmapovaný kill chain a dimenzované remediační kvantum."
eyebrow: "Konzultační modul"
lead: "Před jakýmkoliv doporučením modulů potřebujeme upřímný obraz vaší skutečné situace. Brownhat Diagnostika je strukturovaný dvoudenní workshop — bez instalace nástrojů, bez skenování — který přináší nejjasnější pohled na vaši bezpečnostní pozici a co je nejdůležitější opravit."
actions:
- label: "Rezervovat diagnostiku"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co diagnostika přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📋</div>
<div class="feature-item-body">
<h4>Zpráva o mezerách NIST CSF 2.0</h4>
<p>Upřímné ohodnocení vaší pozice napříč všemi šesti funkcemi CSF 2.0 — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — s jasným oddělením mezer, na kterých záleží, od těch, které počkají.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🗺️</div>
<div class="feature-item-body">
<h4>Mapa kill chainu</h4>
<p>Pomocí aplikace Kill Chain Assessment modelujeme vaše prostředí jako graf útoku. Aplikace vypočítá nejkratší cestu z útočníkova vstupního bodu ke korunním klenotům — kill chain — a přesně identifikuje, které články je třeba přerušit jako první.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚡</div>
<div class="feature-item-body">
<h4>Remediační plán dimenzovaný do kvant</h4>
<p>Každý nález na kill chainu je zařazen do remediačního kvanta: Kritické (hodiny), Závažné (dny), Standardní (sprint) nebo Temné (nejprve nutná discovery). Odcházíte s plánem seřazeným podle času do existenčního dopadu, nikoli podle skóre CVSS.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📦</div>
<div class="feature-item-body">
<h4>Prioritizovaný plán modulů</h4>
<p>Doporučená posloupnost modulů odvozená přímo z vašeho obrazu mezer a kill chainu. Nikoli generické doporučení dle frameworku — posloupnost postavená na tom, co jsme skutečně našli ve vašem prostředí.</p>
</div>
</div>
</div>
## Jak to funguje
Diagnostika je strukturovaný workshop ve dvou polodenních blocích s vaším IT lídrem, vlastníkem obchodního procesu a osobou zodpovědnou za bezpečnostní rozhodnutí. Bez přípravy předem. Bez dotazníků k vyplnění. Předvyplněné dotazníky přinášejí aspirační odpovědi; workshop přináší upřímné.
**Setkání 1 — Kontext a základy:** Domény GOVERN a IDENTIFY. Kdo je zodpovědný za bezpečnost, jak se rozhoduje, jaká aktiva existují a jak se hodnotí rizika. Zde vycházejí na povrch mezery v řízení — obvykle rychleji, než klienti čekají.
**Setkání 2 — Kontroly, detekce a obnova:** PROTECT, DETECT, RESPOND a RECOVER. Jaké kontroly jsou skutečně zavedeny a vynucovány (nejen nakonfigurovány), jak se zpracovávají alarmy, jak se řídí incidenty a zda byla obnova někdy testována. Syntéza kill chainu probíhá průběžně.
## Výstupy
Vše putuje do vašeho repozitáře. Na konci dvou dnů obdržíte: zprávu o mezerách NIST CSF 2.0, diagram kill chainu a analýzu nejkratší cesty, priority remediace rozdělené do kvant (P0/P1/P2 s časovými odhady), plán modulů s doporučenou posloupností a zdůvodněním, a osazený backlog nálezů připravený pro housekeeping stream.
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 2 polodenní bloky (4 hodiny každý) |
| **Formát** | Preferovaně osobně; vzdáleně s kamerou je přijatelné |
| **Účastníci** | IT lídr, executive sponzor (povinně); vlastník obchodního procesu (doporučeno) |
| **Předpoklady** | Žádné — toto je výchozí bod |
| **Navazující** | Přináší plán modulů; další moduly jsou volitelné |
<div class="cta-strip">
<h2>Začněte zde</h2>
<p>Každé angažmá začíná Brownhat Diagnostikou. Je to jediný poctivý způsob, jak zvolit posloupnost modulů.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Rezervovat diagnostiku</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Modul 1 — Správa endpointů"
description: "Inventarizace zařízení, enrollment do Intune, základní linie dodržování předpisů, discovery shadow IT a nasazení ASTRAL pro detekci drift. Kompletní přehled celé flotily za 30–45 dní."
eyebrow: "Konzultační modul"
lead: "Nemůžete spravovat to, co nevidíte. Správa endpointů je téměř vždy správný první modul po diagnostice — přináší okamžitý přehled o každém zařízení a vytváří základ, na kterém závisí každá další bezpečnostní kontrola."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📱</div>
<div class="feature-item-body">
<h4>Kompletní inventarizace zařízení</h4>
<p>Každé spravované zařízení zaevidováno v Intune: verze OS, úroveň záplat, stav šifrování, stav dodržování předpisů. Shadow IT zařízení označena. Odcházíte s reálným obrazem vaší flotily — ne co by tam mělo být, ale co tam je.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">✅</div>
<div class="feature-item-body">
<h4>Základní linie dodržování předpisů</h4>
<p>Šifrování vynuceno, minimální verze OS nastaveny, antivirus vyžadován, zámek obrazovky nakonfigurován. Zařízení nesplňující požadavky jsou označena červeně a blokována od přístupu k datům prostřednictvím integrace s Conditional Access.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔀</div>
<div class="feature-item-body">
<h4>Nasazení ASTRAL pro detekci drift v Intune</h4>
<p>ASTRAL zachycuje vaši konfiguraci Intune jako verzionované snapshoty v Gitu. Každá změna policy otevře pull request s čitelným diffem. Neoprávněné změny jsou detekovány dříve, než se stanou incidentem.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Discovery shadow IT</h4>
<p>Inventarizace aplikací napříč všemi zaevidovanými zařízeními odhalí schválený i neschválený software — včetně spotřebitelských AI nástrojů na firemních zařízeních. Každá neschválená aplikace je potenciální cesta pro exfiltraci dat nebo vstup malwaru.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔐</div>
<div class="feature-item-body">
<h4>Integrace s Conditional Access</h4>
<p>Stav dodržování předpisů zařízení zapojen do Conditional Access tak, aby nevyhovující zařízení nemohla přistupovat k e-mailu, SharePointu ani Teams. Kontrola zařízení se stane skutečným vynucovacím signálem, nikoli jen metrikou na dashboardu.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 30–45 dní |
| **Prostředí** | M365 E3+ (Intune je součástí) |
| **Předpoklady** | Přístup globálního administrátora; ověřena proveditelnost enrollment zařízení |
| **Přirozené navazující** | Modul 2 (Zabezpečení identity) — mezery v identitě se odhalují během enrollmentu |
<div class="cta-strip">
<h2>Jste připraveni vidět svou flotilu?</h2>
<p>Kompletní přehled zařízení za 30 dní. Základ, na kterém závisí každá další bezpečnostní kontrola.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+63
View File
@@ -0,0 +1,63 @@
---
title: "Modul 10 — Red Team a adversariální validace"
description: "Simulace útočníka zaměřená na konkrétní kill chain identifikovaný při Brownhat Diagnostice. Ověřuje, zda hardening modulů přinesl skutečné bezpečnostní zlepšení, nebo jen zlepšení compliance dashboardu."
eyebrow: "Konzultační modul"
lead: "Klient má MFA. Má Conditional Access. Má Intune. Dashboard je zelený. To je nejnebezpečnější prostředí, do kterého lze vstoupit — nikoli proto, že je špatně nakonfigurováno, ale protože všichni věří, že funguje. Modul 10 zjistí, které kontroly jsou reálné a které jsou jen zobrazení."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Cílená validace kill chainu</h4>
<p>Simulace útočníka probíhá specificky proti kill chainu identifikovanému při Brownhat Diagnostice a modifikovanému předchozími hardening moduly. Nikoli broad-scope red team — soustředěný test toho, zda cesty, o nichž jsme tvrdili, že jsou uzavřeny, skutečně uzavřeny jsou.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔐</div>
<div class="feature-item-body">
<h4>Testování předpokladů identity a privilegií</h4>
<p>Kerberoasting, simulace DCSync, pokusy o obejití PIM a zneužití OAuth souhlasu — techniky, které uspívají i v hardened prostředích, protože hardening existuje, ale nebyl testován. Kontrola, která nikdy nebyla prověřena, je hypotéza. Tento engagement hypotézy mění na důkazy.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧪</div>
<div class="feature-item-body">
<h4>Validace detekce</h4>
<p>Bezpečnostní alarmy záměrně spouštěny pro testování toho, zda detekční pravidla reagují, zda alarmy dosáhnou člověka a zda ten člověk ví, co dělat. Mnoho prostředí generuje správný alarm do fronty, kterou nikdo nečte. Validace detekce rozlišuje mezi „toto detekujeme" a „toto detekujeme a reagujeme na to."</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏗️</div>
<div class="feature-item-body">
<h4>Strukturální nález, nikoli seznam CVE</h4>
<p>Každá nalezená mezera produkuje strukturální doporučení — nikoli „záplatujte toto CVE", ale „tato cesta existuje kvůli této architektonické podmínce; k jejímu přerušení je zapotřebí tato změna." Výstupem je kratší kill chain, nikoli delší backlog remediace.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 15–30 dní |
| **Prostředí** | Jakékoli |
| **Předpoklady** | Písemné oprávnění pokrývající všechny testovací aktivity; alespoň dva hardening moduly dokončeny; počáteční kill chain z Modulu 0 zdokumentován |
| **Přirozené navazující** | Aktualizovat mapu kill chainu s validovanými nálezy; strukturální mezery vrátit do plánu modulů |
<div class="cta-strip">
<h2>Zjistěte, které kontroly jsou reálné</h2>
<p>Zelené dashboardy a netestovaná realita jsou nejnebezpečnější kombinace v bezpečnosti. Modul 10 jednu z nich mění v druhou.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Modul 11 — Blue/Purple Team Foundation"
description: "Detection engineering, ladění alarmů, vývoj SIEM pravidel a playbooks pro threat hunting. Vaše stávající nástroje, které skutečně fungují."
eyebrow: "Konzultační modul"
lead: "Většina organizací vlastní Ferrari-grade bezpečnostní stack a řídí ho jako půjčené auto. Problémem nejsou nástroje. Tento modul buduje provozní rytmus, detekční pravidla a hunting playbooks, které mění bezpečnostní telemetrii na bezpečnostní výsledky."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">⚙️</div>
<div class="feature-item-body">
<h4>Audit schopností</h4>
<p>Engagement začíná hodnocením nikoli nástrojů, ale schopnosti týmu je používat. Pokrytí alarmů Defender for Endpoint, kvalita analytických pravidel Sentinelu, proces revize Defender for Office 365, doba reakce na ochranu identity — vše hodnoceno z pohledu toho, co nástroj dokáže versus co se skutečně děje. Mezera je téměř vždy v procesech, nikoli v technologii.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔔</div>
<div class="feature-item-body">
<h4>Ladění alarmů a vrstvený triage</h4>
<p>Vysoce věrné alarmy odděleny od šumu. Nasazen model vrstveného triage, aby analytici věděli, které alarmy vyžadují okamžitou reakci, které vyšetřování a které jsou informační. Konfigurace „200 alarmů denně bez triage procesu" — produkující analytické vyhoření a přehlédnuté detekce stejnou měrou — nahrazena funkčním přístupem.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📐</div>
<div class="feature-item-body">
<h4>Detection engineering</h4>
<p>Vlastní detekční pravidla postavena na konkrétních útočných technikách relevantních pro vaše prostředí — nikoli defaultní pravidla vendora pokrývající všechna odvětví, ale pravidla naladěná na vaše korunní klenoty, topologii identit a kill chain identifikovaný při diagnostice.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Playbooks pro threat hunting</h4>
<p>Strukturované hunt hypotézy a prováděcí playbooks pro techniky nejpravděpodobněji úspěšné ve vašem prostředí. Analytici přestanou čekat na alarmy a začnou hledat důkazy kompromitace, která ještě žádný alarm nespustila. Hunt je opakovatelný a plánovaný, nikoli ad-hoc a příležitostný.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔄</div>
<div class="feature-item-body">
<h4>Smyčka kontinuálního zlepšování</h4>
<p>Každý alarm, každý hunt a každý incident napájí cyklus ladění. Přehlédnuté detekce produkují nová pravidla. Falešné poplachy jsou potlačovány rozsahem, nikoli tichem. SIEM se v čase zlepšuje, místo aby se stával irelevantním, jak se prostředí mění.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 45–90 dní |
| **Prostředí** | Microsoft Defender stack a/nebo Sentinel |
| **Předpoklady** | PULSAR nasazen pro auditní log intelligence; počáteční kill chain z Modulu 0 pro ukotvení rozsahu detekce |
| **Přirozené navazující** | Modul 10 (Red Team a validace) pro testování, zda detekce zachytí simulované útoky |
<div class="cta-strip">
<h2>Nechte fungovat nástroje, které již vlastníte</h2>
<p>Tooling, který již máte, dokáže detekovat útoky, jimž skutečně čelíte. Modul 11 buduje schopnost ho použít.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+63
View File
@@ -0,0 +1,63 @@
---
title: "Modul 12 — Ochrana T0 aktiv"
description: "Klasifikace Tier 0 aktiv napříč identitou, infrastrukturou a daty. Architektura ochrany zajišťující, že korunní klenoty jsou nedosažitelné z kompromitace Tier 1 nebo Tier 2."
eyebrow: "Konzultační modul"
lead: "T0 aktivum není jen důležité. Je existenční — jeho kompromitace nezpůsobí výpadek, způsobí zánik. Většina organizací nikdy explicitně neklasifikovala, která aktiva sem patří, což znamená, že je nikdy specificky nechránila."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🏆</div>
<div class="feature-item-body">
<h4>Klasifikace T0 aktiv</h4>
<p>Každé aktivum klasifikováno do vrstev: T0 (existenční — kompromitace ničí provoz), T1 (kritické — materiální škoda), T2 (důležité — výrazné narušení), T3 (standardní). Klasifikace není cvičení se spreadsheetem — je to rozhovor o tom, bez čeho organizace skutečně nemůže fungovat. Doménové kontrolery, ADCS, synchronizační server Entra Connect a kryptografický klíčový materiál patří na T0.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🛡️</div>
<div class="feature-item-body">
<h4>Architektura ochrany korunních klenotů</h4>
<p>Design ochrany pro každé T0 aktivum: řízení přístupu, síťová segmentace, požadavky na monitoring a hranice privilegií. Primární podmínka architektury: T0 musí být vždy nedosažitelné z kompromitace T1 nebo T2 systému. Pokud útočník vlastní member server, nesmí dosáhnout doménového kontroleru.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔒</div>
<div class="feature-item-body">
<h4>Vynucení vrstev privilegií</h4>
<p>Administrátorský přístup vynucen per vrstva — T0 administrátoři používají vyhrazené, hardened pracovní stanice a vyhrazené účty, které se nepřihlašují do T1 nebo T2 systémů. Service accounts, které v současnosti překračují vrstvy, identifikovány a rozděleny. Oprávnění synchronizačního účtu Entra Connect zpřísněna.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📡</div>
<div class="feature-item-body">
<h4>Monitoring T0 a design alarmů</h4>
<p>Vlastní detekční pravidla zaměřená specificky na T0 aktiva — jakýkoli pokus o autentizaci, jakákoli eskalace privilegií, jakákoli změna konfigurace na T0 systému generuje vysoce věrný alarm, který okamžitě dosáhne člověka. Šum z T1 a T2 nepohřbí T0 signály.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 30–60 dní |
| **Prostředí** | Jakékoli |
| **Předpoklady** | Modul 0 (Diagnostika) pro identifikaci korunních klenotů; Modul 6 pokud je v rozsahu on-premises AD |
| **Přirozené navazující** | Modul 13 (Architektura privilegovaného přístupu) pro PAM vrstvu, která vrstvy privilegií v praxi vynucuje |
<div class="cta-strip">
<h2>Chraňte to, co organizace nemůže ztratit</h2>
<p>Vše ostatní lze přebudovat. T0 aktiva nikoli. Modul 12 zajišťuje, aby to architektura odrážela.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+63
View File
@@ -0,0 +1,63 @@
---
title: "Modul 13 — Architektura privilegovaného přístupu"
description: "PAM design využívající Teleport, Tailscale/Headscale a JIT přístup. Správa vzdáleného přístupu dodavatelů, efemerální přihlašovací údaje, záznam sezení a nulový trvalý přístup."
eyebrow: "Konzultační modul"
lead: "Vaše VPN autentizuje lidi k vaší síti. PAM autentizuje lidi ke konkrétním zdrojům uvnitř ní. Většina organizací řeší první problém špatně a druhý zcela ignoruje. Výsledek: kompromitovaný VPN přihlašovací údaj dosáhne všeho. Tento modul uzavírá tuto mezeru dvouvrstvou architekturou."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🌐</div>
<div class="feature-item-body">
<h4>Vrstva síťového přístupu — Tailscale nebo Headscale</h4>
<p>Tailscale (nebo Headscale pro suverénní nasazení) nahrazuje legacy VPN pro T1 workloady — cloudové zdroje, Kubernetes clustery, multicloudové management planes. ACL per uzel, integrace Entra OIDC a MFA per sezení přes expiraci klíčů. Útočník s odcizeným přihlašovacím údajem dosáhne pouze konkrétních zdrojů, ke kterým je přihlašovací údaj oprávněn, nikoli celé sítě.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔐</div>
<div class="feature-item-body">
<h4>Vrstva privilegovaného přístupu — Teleport</h4>
<p>Teleport nasazen jako protokol-aware přístupová vrstva pro SSH, RDP, Kubernetes a databázový přístup. Každé privilegované sezení je proxováno, zaznamenáno a auditovatelné. Efemerální certifikáty nahrazují dlouhodobé přihlašovací údaje — žádné SSH klíče ke krádeži, žádná uložená RDP hesla, žádné trvalé přihlašovací údaje k databázi. Přístup je schválený, časově ohraničený a standardně logovaný.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⏱️</div>
<div class="feature-item-body">
<h4>JIT přístup a nulová trvalá privilegia</h4>
<p>Workflow just-in-time přístupu, takže privilegovaný přístup ke kritickým systémům vyžaduje žádost o schválení, uděluje časově ohraničený přístup a automaticky expiruje. Žádná trvalá admin sezení, žádné persistentní privilegované účty s širokým dosahem. Útočník, který kompromituje admin účet ve 3 ráno, zjistí, že nemá aktuálně přístup k ničemu podstatnému.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏢</div>
<div class="feature-item-body">
<h4>Správa vzdáleného přístupu dodavatelů</h4>
<p>Dodavatelé třetích stran — MSP, dodavatelé hardware, software vendoři s přístupem k vzdálené podpoře — zahrnuti pod stejnou PAM architekturu. Každé sezení dodavatele omezeno na konkrétní zdroje, které potřebují, zaznamenáno a okamžitě odvolatelné. Přístup dodavatelů je významný a často přehlížený útočný povrch.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 45–60 dní |
| **Prostředí** | Jakékoli (cloud, on-premises, hybridní, multicloud) |
| **Předpoklady** | Modul 12 (Ochrana T0 aktiv) pro stanovení hranic vrstev; inventarizace požadavků na privilegovaný přístup |
| **Přirozené navazující** | Modul 11 (Blue/Purple Team) pro budování detekce anomálií privilegovaného přístupu |
<div class="cta-strip">
<h2>Žádný trvalý přístup. Žádné trvalé riziko.</h2>
<p>Každé privilegované sezení ohraničeno, zaznamenáno a časově omezeno. Útočník, který ukradne přihlašovací údaj, zjistí, že mu standardně nic neudělí.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+63
View File
@@ -0,0 +1,63 @@
---
title: "Modul 14 — Suverénní komunikace"
description: "Delta Chat chatmail relay, nasazení Matrix/Element a design out-of-band kanálu pro krizové situace. Komunikační infrastruktura, která zůstane dostupná a privátní, i když je váš primární nástroj kompromitován."
eyebrow: "Konzultační modul"
lead: "Váš plán reakce na incidenty předpokládá, že vaše komunikační platforma je dostupná. Váš plán reakce na incidenty je špatný. Když ransomware vyřadí firemní IT, Teams padne také. Když je Active Directory kompromitováno, útočník může sledovat vaši reakci v reálném čase. Tento modul buduje alternativu."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">💬</div>
<div class="feature-item-body">
<h4>Delta Chat — krizový out-of-band kanál</h4>
<p>Delta Chat nasazen na nezávislé chatmail relay infrastruktuře za méně než 10 minut na uživatele. Šifrovaný, funguje na mobilu, nevyžaduje firemní účet ani firemní síť. Když je firemní identity provider nedostupný nebo kompromitován, váš tým reakce na incidenty stále má bezpečný, ověřený kanál — vždy nezávislý na tom, co zrovna selhává.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏠</div>
<div class="feature-item-body">
<h4>Matrix/Element — suverénní primární platforma (volitelně)</h4>
<p>Pro organizace, které chtějí vlastnit celou svou primární komunikaci: self-hostovaný Matrix homeserver s klientem Element. Žádná závislost na vendorovi, žádný Microsoft nebo Google účet potřebný pro přístup, plně federovaný dle potřeby. Vaše komunikační infrastruktura se stane suverénní — stejně jako by měla být vaše autentizační infrastruktura.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📋</div>
<div class="feature-item-body">
<h4>Krizový komunikační runbook</h4>
<p>Zdokumentovaný, otestovaný out-of-band komunikační protokol — kdo kontaktuje koho, na jakém kanálu, v jakém pořadí, pro jaké typy incidentů. Runbook existuje na papíře a na osobním zařízení každého respondenta, nezávisle na firemní infrastruktuře. Otestován při tabletop cvičení — poprvé pod tlakem nemůže být zároveň poprvé celkově.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔑</div>
<div class="feature-item-body">
<h4>Ověření klíčů a navázání důvěry</h4>
<p>Šifrovací klíče ověřeny out-of-band před incidentem, aby respondenti věděli, že komunikují mezi sebou, a nikoli s útočníkem, který kompromitoval firemní adresář. Důvěra navázaná předem je jediná důvěra, která drží pod tlakem incidentu.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 15–30 dní |
| **Prostředí** | Jakékoli |
| **Předpoklady** | Žádné — tento modul lze dodat samostatně jako krizovou připravenost |
| **Přirozené navazující** | Modul 7 (Obnova a odolnost) — suverénní komunikace se integruje s celkovou schopností reakce na incidenty |
<div class="cta-strip">
<h2>Zůstaňte v kontaktu, i když vše ostatní nefunguje</h2>
<p>Krizový komunikační kanál musí být nezávislý na infrastruktuře, která může při krizi selhat. Modul 14 ho buduje.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+77
View File
@@ -0,0 +1,77 @@
---
title: "Modul 2 — Zabezpečení identity M365"
description: "Kompletní census identit, architektura Conditional Access, vynucení MFA, eliminace legacy autentizace, nasazení PIM a auditní log intelligence přes PULSAR."
eyebrow: "Konzultační modul"
lead: "Identita je perimetr. Každá další kontrola, kterou nasadíte, závisí na tom, zda se správní lidé — a jen oni — mohou autentizovat. Tento modul učiní vaši identitní architekturu explicitní, vynucenou a auditovatelnou."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">👥</div>
<div class="feature-item-body">
<h4>Kompletní census identit</h4>
<p>Každý uživatelský účet, administrátorský účet, service principal, registrace aplikace a identita hosta vyčíslena a ohodnocena. Osiřelé účty, nadprivilegované role a nepoužívané service principals označeny a zařazeny do fronty remediace.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏗️</div>
<div class="feature-item-body">
<h4>Architektura Conditional Access</h4>
<p>Kompletní, zdokumentovaná sada CA politik pokrývající vynucení MFA, blokování legacy autentizace, signály shody zařízení, pojmenovaná umístění a autentizaci odolnou vůči phishingu pro administrátory. Postupné nasazení s obdobím report-only před vynucením, aby nedošlo k výpadku.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔒</div>
<div class="feature-item-body">
<h4>Vynucení MFA a eliminace legacy autentizace</h4>
<p>MFA vynuceno přes Conditional Access (nikoli per-user MFA). Legacy autentizační protokoly — IMAP, POP, SMTP AUTH, basic auth — blokovány na úrovni tenanta. Tyto protokoly zcela obcházejí MFA a jsou vstupním bodem pro většinu útoků na přihlašovací údaje.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⏱️</div>
<div class="feature-item-body">
<h4>Nasazení PIM nebo JIT proces</h4>
<p>Privileged Identity Management nasazen tak, aby administrátorské role byly aktivovány na vyžádání se schvalovacím workflow a časově omezeným přístupem, místo trvalého přiřazení. Žádný trvalý přístup Global Admin, kde je to možné. Breakglass účty zřízeny a zdokumentovány.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📡</div>
<div class="feature-item-body">
<h4>PULSAR — auditní log intelligence</h4>
<p>PULSAR nasazen pro průběžnou ingesti auditních logů M365 s neomezenou retencí. Rozhraní pro vyhledávání, alerting na vysoce rizikové události a MCP server pro dotazování s podporou AI. Získáte schopnost odpovědět na otázku „co se stalo, kdy a kdo to byl" — zpětně i v reálném čase.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧹</div>
<div class="feature-item-body">
<h4>Audit přístupu hostů a jeho řízení</h4>
<p>Všechny identity hostů vyčísleny. Staré hosty (neaktivní, bez známého vlastníka, bez přiřazeného projektu) označeny a odstraněny. Nastavení externí spolupráce zpřísněno. Politika přístupu hostů zdokumentována a nastaven pravidelný cyklus přezkumu.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 30–60 dní |
| **Prostředí** | M365 E3+ |
| **Předpoklady** | Přístup globálního administrátora; existující CA politiky zinventarizovány |
| **Přirozené navazující** | Modul 3 (Hardening M365) staví na identitní základně |
<div class="cta-strip">
<h2>Uzavřete mezery v identitách</h2>
<p>Nejčastější kill chain začíná kompromitovanými přihlašovacími údaji. Modul 2 zajistí, že samotné přihlašovací údaje nestačí.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Modul 3 — Hardening M365"
description: "Ladění Exchange Online Protection, auditování poštovních schránek, forwarding Unified Audit Log, základní linie Secure Score, ASR pravidla a zachycení konfigurace v ASTRAL — bez nových licencí pro E3 klienty."
eyebrow: "Konzultační modul"
lead: "Většina M365 E3 tenantů využívá jen zlomek bezpečnosti, kterou licence již obsahuje. Tento modul tuto hodnotu systematicky extrahuje — zpřísní existující kontroly, zapne logování, které by mělo běžet, a zachytí základní linii, aby byl drift detekovatelný od prvního dne."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📧</div>
<div class="feature-item-body">
<h4>Ladění Exchange Online Protection</h4>
<p>Politiky anti-phishing, anti-malware a anti-spam přezkoumány a zpřísněny. DKIM, DMARC a SPF ověřeny. Označování externích odesílatelů zapnuto. Automatické přeposílání na externí adresy zablokováno — jeden z nejspolehlivějších mechanismů persistence při kompromitaci business e-mailu.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📒</div>
<div class="feature-item-body">
<h4>Auditování poštovních schránek a forwarding UAL</h4>
<p>Auditování poštovních schránek zapnuto pro všechny uživatelské a administrátorské akce v celém tenantu. Unified Audit Log nakonfigurován pro forwarding do SIEM nebo PULSAR. Každý přístup k poštovní schránce, změna sdílení kalendáře a změna oprávnění se stane prohledávatelnou, uchovanou událostí.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📊</div>
<div class="feature-item-body">
<h4>Základní linie Secure Score a plán zlepšení</h4>
<p>Aktuální Secure Score zdokumentováno s každým otevřeným doporučením klasifikovaným: přijmout, napravit nebo zmírnit. Realistický 90denní plán zlepšení cílí na položky s nejvyšším dopadem v rámci stávající licence E3 — k uzavření většiny mezer není třeba nový výdaj.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🛡️</div>
<div class="feature-item-body">
<h4>Pravidla Attack Surface Reduction</h4>
<p>ASR pravidla nasazena přes Intune nejprve v audit módu, pak postupně převedena do enforcement. Pravidla pokrývají zneužití maker Office, krádež přihlašovacích údajů z LSASS a podezřelé spouštění procesů — nejběžnější cesty spouštění malwaru, aniž by blokovala legitimní pracovní toky.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📸</div>
<div class="feature-item-body">
<h4>Zachycení základní linie v ASTRAL</h4>
<p>ASTRAL nasazen pro Git-verzionovaný snapshot konfigurace po hardeningu. Každá následná změna otevře pull request s diffem a AI-generovaným popisem. Hardened stav se stane obnovitelnou základní linií — pokud cokoliv zdriftuje, víte o tom okamžitě a můžete deterministicky obnovit.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 30–60 dní |
| **Prostředí** | M365 E3+ |
| **Předpoklady** | Přístup globálního administrátora; Modul 2 (Zabezpečení identity) dokončen nebo probíhá paralelně |
| **Přirozené navazující** | Modul 4 (Správa dat a compliance) pro štítky citlivosti a DLP |
<div class="cta-strip">
<h2>Vytěžte bezpečnost, kterou vaše licence již obsahuje</h2>
<p>Většina E3 tenantů nechává většinu své bezpečnostní hodnoty nenakonfigurovanou. Tento modul tuto mezeru systematicky uzavírá.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Modul 4 — Správa dat a compliance"
description: "Nasazení štítků citlivosti, zásady retence, DLP, připravenost na eDiscovery, správa Teams a kontroly externího sdílení na SharePointu. Důkazy o souladu se standardy vznikají jako přirozený výstup."
eyebrow: "Konzultační modul"
lead: "Data nezůstávají tam, kde je uložíte. Kopírují se, přeposílají, synchronizují a sdílí — a ve většině tenantů nikdo nedokáže zjistit, kam odešla, ani je stáhnout zpět. Tento modul činí datové toky viditelnými, řiditelnými a auditovatelnými."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🏷️</div>
<div class="feature-item-body">
<h4>Nasazení štítků citlivosti</h4>
<p>Praktická taxonomie štítků nasazena napříč M365 — ne šestistupňová compliance architektura, kterou nikdo nepoužívá, ale schéma, které vaše organizace skutečně bude aplikovat. Štítky proudí e-mailem, Teams, SharePointem a aplikacemi Office. Klasifikace se stane signálem, na který může reagovat každá návazná kontrola.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📅</div>
<div class="feature-item-body">
<h4>Zásady retence pro všechny M365 workloady</h4>
<p>Retence nakonfigurována pro Exchange, SharePoint, OneDrive, zprávy Teams a záznamy ze schůzek Teams. Regulatorní minima splněna. Nadměrně uchovaná data, která zbytečně rozšiřují rozsah eDiscovery, identifikována a naplánována k odstranění.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🚫</div>
<div class="feature-item-body">
<h4>DLP politiky</h4>
<p>Politiky Data Loss Prevention cílené na vaše skutečně regulovaná data — čísla platebních karet, rodná čísla, zdravotní data nebo proprietární klasifikace — s postupným nasazením nejprve jen s alertem, pak s blokováním. Automatické přeposílání na externí adresy zablokováno. Sdílení „Kdokoli s odkazem" omezeno nebo odstraněno.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚖️</div>
<div class="feature-item-body">
<h4>Připravenost na eDiscovery</h4>
<p>Rozsah vyhledávání obsahu ověřen, proces identifikace custodianů zdokumentován, workflow pro legal hold otestován. Pokud obdržíte regulatorní žádost nebo soudní příkaz, můžete reagovat bez improvizace pod tlakem.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">👥</div>
<div class="feature-item-body">
<h4>Správa Teams a kontroly přístupu hostů</h4>
<p>Nasazena politika životního cyklu Teams, aby opuštěné týmy neakumulovaly zapomenutá datová úložiště. Oprávnění přístupu hostů zpřísněna. Nastavení externího sdílení sladěna napříč úrovněmi tenanta, webu a Teams kanálu — tři vrstvy, které se rutinně neshodují a způsobují nečekané expozice.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 45–90 dní |
| **Prostředí** | M365 E3+ |
| **Předpoklady** | Modul 2 (Identita) dokončen — kontroly přístupu hostů a externího sdílení závisí na čisté identitní základně |
| **Přirozené navazující** | Modul 7 (Obnova a odolnost) pro zajištění, že uchovaná data jsou zálohována nezávisle na nativní retenci Microsoftu |
<div class="cta-strip">
<h2>Učiňte datové toky viditelnými</h2>
<p>Každé sdílení je kopií vašeho blast radius předanou straně, kterou plně nekontrolujete. Modul 4 to učiní viditelným a řiditelným.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Modul 5 — AI Sovereignty Bridge"
description: "Inventarizace shadow AI, nasazení Azure OpenAI s privátními endpointy, Conditional Access pro AI nástroje, první RAG pipeline na proprietárních datech a politika správy AI."
eyebrow: "Konzultační modul"
lead: "Většina organizací již má zaměstnance používající cloudové AI. Otázkou není, zda se to děje — ale zda data tekoucí přes tyto nástroje máte právo auditovat, stáhnout zpět a udržet suverénní. Tento modul tuto mezeru uzavírá."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Inventarizace shadow AI</h4>
<p>Data z endpointů a proxy použita k výčtu AI nástrojů skutečně používaných — ne co povoluje politika přijatelného užití, ale co zaměstnanci spouštějí. Spotřebitelští AI asistenti, nástroje pro doplňování kódu, rozšíření prohlížečů a vložené AI funkce SaaS zanechávají stopy. Nemůžete řídit nástroj, o jehož existenci nevíte.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔒</div>
<div class="feature-item-body">
<h4>Azure OpenAI na privátních endpointech</h4>
<p>Azure OpenAI nasazen v hranici vašeho tenanta s privátním síťovým endpointem — inference provoz zůstává uvnitř vaší Azure virtuální sítě, nikdy neprojde veřejným internetem. Požadavky na datovou rezidenci jsou splněny strukturálně, nikoli pouze smluvním ujištěním.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🚦</div>
<div class="feature-item-body">
<h4>Conditional Access pro AI nástroje</h4>
<p>CA politiky omezující přístup ke schváleným AI nástrojům na vyhovující, spravovaná zařízení a schválené uživatele. Přístup ke spotřebitelským AI nástrojům z firemních zařízení blokován nebo omezen přes proxy politiku. Hranice mezi schváleným a neschváleným AI se stane vynutitelnou.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧠</div>
<div class="feature-item-body">
<h4>První RAG pipeline nebo fine-tuned model</h4>
<p>Funkční retrieval-augmented generation pipeline — nebo fine-tuned model — postavena na vašich proprietárních datech. Obecný cloudový model se zlepšuje pro úkoly všech. Model trénovaný na vašich datech se zlepšuje pouze pro vaše úkoly. Tento rozdíl se časem prohlubuje a žádný vendor ho nemůže dohnat bez přístupu k vašim datům.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📜</div>
<div class="feature-item-body">
<h4>Politika správy AI</h4>
<p>Zdokumentovaná, praktická politika správy AI pokrývající schválené nástroje, přijatelné klasifikace dat pro vstup do AI, požadavky na lidský přezkum AI-asistovaných rozhodnutí a proces hodnocení vendorů při nových AI nákupech. Navržena k vynucení, nikoli k archivaci.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 30–60 dní |
| **Prostředí** | Azure subscription; M365 E3+ pro CA integraci |
| **Předpoklady** | Modul 2 (Identita) pro vynucení CA; Modul 1 (Správa endpointů) pro discovery shadow AI z telemetrie zařízení |
| **Přirozené navazující** | AURORA pro cross-tool AI operace po nasazení PULSAR a ASTRAL |
<div class="cta-strip">
<h2>Vaše data by měla zůstat vaše</h2>
<p>Proprietární data zpracovaná cloudovým modelem trénují ten model — ne váš. Modul 5 buduje alternativu.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Modul 6 — Hardening on-premises AD a endpointů"
description: "Kompletní census identit AD, audit kompromitovaných přihlašovacích údajů, rotace KRBTGT, LAPS, Sysmon, PAW architektura a hardening Entra Connect pro hybridní prostředí."
eyebrow: "Konzultační modul"
lead: "Cloudu patří titulky. Active Directory se kompromituje. Většina AD lesů nese desetiletí akumulovaných privilegií, service accounts s hesly, která predatují současný bezpečnostní tým, a Group Policy objekty, na které se nikdo neodváží sáhnout. Tento modul opravuje kill chain v on-premises vrstvě."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🗂️</div>
<div class="feature-item-body">
<h4>Kompletní census identit AD</h4>
<p>Každý uživatel, počítač, service account a administrátorská skupina vyčíslena a ohodnocena. Staré účty (žádné přihlášení za 90+ dní), osiřelé objekty (vlastník odešel) a service accounts s neexpirujícími hesly označeny. Mapa privilegií, o které jste nevěděli, že existuje.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔑</div>
<div class="feature-item-body">
<h4>Audit kompromitovaných přihlašovacích údajů</h4>
<p>Hashe hesel AD porovnány s databázemi známých kompromitovaných přihlašovacích údajů (Elysium / korpus Have I Been Pwned). Účty používající hesla, která se objevují v databázích úniků, identifikovány a nuceny k resetu — dříve než je použije útočník. Toto konzistentně odhaluje účty, které jsou tiše kompromitovány měsíce.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔄</div>
<div class="feature-item-body">
<h4>Rotace KRBTGT a invalidace Golden Ticket</h4>
<p>Účet KRBTGT dvakrát po sobě rotován (nutné pro invalidaci všech existujících Kerberos tiketů, včetně padělaných golden tiketů). Postup zdokumentován pro budoucí rotace. Nerotovaný KRBTGT je persistentní útočníkova opora, která přežívá každou jinou provedenou remediaci.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">💻</div>
<div class="feature-item-body">
<h4>LAPS a Privileged Access Workstations</h4>
<p>Local Administrator Password Solution nasazeno tak, aby každý stroj měl unikátní, rotující heslo lokálního administrátora — čímž se eliminuje cesta laterálního pohybu přes sdílené přihlašovací údaje lokálního administrátora. PAW architektura navržena pro administrátorské úkoly, aby zabránila krádeži přihlašovacích údajů z pracovních stanic používaných ke správě Tier 0 systémů.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📡</div>
<div class="feature-item-body">
<h4>Nasazení Sysmon a hardening Entra Connect</h4>
<p>Sysmon nasazen na endpointy pro detailní logování vytváření procesů, síťových spojení a změn registru. Oprávnění synchronizačního účtu Entra Connect zpřísněna a synchronizační server izolován: most mezi on-premises a cloudem je Tier 0 aktivum a musí být jako takové chráněno.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 45–60 dní |
| **Prostředí** | On-premises AD s M365 nebo bez |
| **Předpoklady** | Přístup Domain Admin; Modul 2 (Identita) pro cloudovou část, pokud je hybridní |
| **Přirozené navazující** | Modul 12 (Ochrana T0 aktiv); Modul 13 (Architektura privilegovaného přístupu) |
<div class="cta-strip">
<h2>Cloud je jen tak bezpečný jako AD za ním</h2>
<p>Většina kill chainů prochází on-premises AD i tehdy, když cílem jsou cloudové zdroje. Modul 6 tuto cestu uzavírá.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Modul 7 — Obnova a odolnost"
description: "Přezkum architektury zálohování, nasazení neměnitelných záloh, runbooky pro disaster recovery, tabletop cvičení a ASTRAL základní linie jako plán obnovy. Otestovaná obnova, ne předpokládaná."
eyebrow: "Konzultační modul"
lead: "Nejčastější lež v odvětví: 'máme zálohy.' Mít zálohu není totéž jako umět obnovit. Tento modul nahrazuje předpoklad otestovanou, zdokumentovanou a nacvičenou schopností — aby obnova při incidentu byla procedura, nikoli improvizace."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Přezkum architektury zálohování</h4>
<p>Aktuální pokrytí zálohami zhodnoceno pro každý workload. Mezery, které se konzistentně objevují — M365 data, o nichž zaměstnanci věří, že je zálohuje Microsoft, ale bez nezávislé point-in-time zálohy; zálohovací systémy dostupné ze stejné sítě jako produkce; zálohovací přihlašovací údaje uložené ve stejném správci hesel jako vše ostatní — nalezeny a zdokumentovány dříve, než je najde útočník.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧱</div>
<div class="feature-item-body">
<h4>Nasazení neměnitelných záloh</h4>
<p>Neměnitelné zálohy mimo síť nasazeny pro kritické workloady. Operátoři ransomwaru mažou nebo šifrují zálohy před útokem na produkci — záloha dosažitelná z kompromitované infrastruktury není zálohou. Neměnitelnost zajišťuje, že zálohu nelze upravit ani smazat ani plně kompromitovaným administrátorským účtem.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📖</div>
<div class="feature-item-body">
<h4>Runbooky disaster recovery</h4>
<p>Postupy obnovy krok za krokem napsány pro každý kritický workload — včetně scénářů, které nikdo nedokumentuje: obnova AD lesa, obnova konfigurace M365 tenanta a rebuild cloudové infrastruktury ze základní linie ASTRAL. Každý runbook je otestován, nejen napsán.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Tabletop cvičení</h4>
<p>Strukturovaný průchod scénářem — typicky incident s ransomwarem nebo kompromitací identity — provedený se skutečným týmem reakce na incidenty. Mezery v komunikaci, rozhodovacích pravomocích a technickém postupu se odhalí při tabletop cvičení, nikoli při živém incidentu. Každá mezera nalezená při cvičení je mezera, která nebyla nalezena pod tlakem.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔀</div>
<div class="feature-item-body">
<h4>ASTRAL základní linie jako plán obnovy</h4>
<p>Git repozitář ASTRAL — zachycující konfiguraci M365 a Intune — se stane autoritativní základní linií obnovy. Po katastrofickém selhání konfigurace nebo kompromitaci tenanta má odpověď na „do čeho obnovujeme?" deterministickou odpověď. Pipeline pro obnovu aplikuje stav known-good bez manuální rekonstrukce z paměti.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 30–60 dní |
| **Prostředí** | M365 a/nebo on-premises |
| **Předpoklady** | ASTRAL nasazen (Modul 1 nebo 3) pro konfigurační základní linii; inventarizace kritických workloadů |
| **Přirozené navazující** | Modul 11 (Blue/Purple Team) pro budování detekční schopnosti, která napájí smyčku obnovy |
<div class="cta-strip">
<h2>Zjistěte, že umíte obnovit, dřív než to budete potřebovat</h2>
<p>Neotestovaná záloha je současně v pořádku a bezcenná. Modul 7 vám poví, která z možností platí — dříve než to udělá incident.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+76
View File
@@ -0,0 +1,76 @@
---
title: "Modul 8 — Správa hrozeb a zranitelností"
description: "Kvantová správa zranitelností pro éru, kde exploitation vede. Prioritizace na základě kill chainu, subtrakce ~90 %, čtyři časově ohraničená kvanta a aplikace Kill Chain Assessment."
eyebrow: "Konzultační modul"
lead: "Čas do exploitace se zkrátil na přibližně čtyři hodiny. Medián remediace je 43 dní. Žádné množství 'záplatovat rychleji' neuzavře mezeru, která jde špatným směrem o dva řády. Odpověď není záplatovat rychleji — je přestat používat seznam zranitelností jako jednotku práce."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Problém se starým modelem
CVSS hodnotí závažnost abstraktně. Neví nic o tom, zda je zranitelné aktivum dostupné z internetu, zda leží na kill chainu, zda existuje exploit, nebo zda ho kompenzační kontrola již neutralizuje. Seřazení 40 000 nálezů podle CVSS produkuje seznam, který přesně nekoreluje s tím, kam útočník skutečně půjde.
DBIR 2026 od Verizonu potvrzuje, že exploitace zranitelností je nyní vedoucím vektorem počátečního přístupu — zhruba dvakrát více než phishing. Toto není problém vyspělosti, který vyřeší více analytiků. Je to model, který vyčerpal svůj potenciál.
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🗺️</div>
<div class="feature-item-body">
<h4>Hodnocení kill chainu</h4>
<p>Aplikace Kill Chain Assessment mapuje vaše prostředí jako graf útoku a spustí výpočet nejkratší cesty z každého vstupního bodu ke každému korunnímu klenotu. Výsledkem je kill chain — nejlevnější cesta od útočníkovy opory k existenčnímu dopadu. Každý nález je klasifikován jako P0 (na nejkratší cestě), P1 (na nějaké cestě) nebo P2 (mimo cestu).</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">✂️</div>
<div class="feature-item-body">
<h4>Subtrakce ~90 %</h4>
<p>Zhruba 90 % „kritických" zranitelností není v daném prostředí zneužitelných, jakmile jsou zmapovány kompenzační kontroly, dostupnost a segmentace. Tato subtrakce — odebrání falešné urgence před přidáním jakékoli práce — mění „40 000 kritických" na několik stovek skutečných a několik desítek urgentních. Je to nejpákovější krok celého programu a je to čistá delece.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚡</div>
<div class="feature-item-body">
<h4>Čtyři časově ohraničená kvanta</h4>
<p><strong>Kritické (hodiny):</strong> Na kill chainu, dostupné, exploit k dispozici nyní. Odpovědí je kompenzační kontrola — přerušit dostupnost, blokovat na hranici, izolovat — nikoli patch. Čtyřhodinové okno nelze splnit cyklem záplatování vendora.<br><strong>Závažné (dny):</strong> Materiální riziko; dostupné s obtížemi. Jedno change window, ověřit vynucení.<br><strong>Standardní (sprint):</strong> Skutečný, neurgentní ocas. Odvodnit v sprint-dimenzovaných dávkách na normálním change kalendáři.<br><strong>Temné (nedimenzované):</strong> Dostupnost nebo exploitabilita neznámá. Přesměrovat k discovery — nejprve charakterizovat.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Zero-budget discovery zranitelností</h4>
<p>osquery nasazen jako suverénní discovery platforma společně se skriptovanými kontrolami pro nálezy, které skenery přehlédnou — oprávnění service accounts, neopravený firmware, CVE v základních image kontejnerů, exponovaná administrátorská rozhraní. Discovery před pořízením skeneru téměř vždy postačuje k nalezení kill chainu.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📉</div>
<div class="feature-item-body">
<h4>Délka kill chainu jako metrika</h4>
<p>Program neměří MTTR. Měří, zda se kill chain zkrátil. Deset incidentů, které produkují deset záplat, ponechává infrastrukturu stejně křehkou. Deset incidentů, které každý přeruší jednu strukturální cestu, produkuje infrastrukturu, která je při každém testování obtížněji kompromitovatelná. To je jediná poctivá definice zlepšení.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 45–90 dní |
| **Prostředí** | Jakékoli (cloud, on-premises, hybridní) |
| **Předpoklady** | Modul 0 (Diagnostika) pro stanovení počátečního kill chainu; inventarizace aktiv z Modulu 1 nebo 6 |
| **Přirozené navazující** | Modul 10 (Red Team a validace) pro ověření, že přerušené cesty zůstávají přerušeny |
<div class="cta-strip">
<h2>Přestaňte závodit s útočníkem, kterého nemůžete předhonit</h2>
<p>Vítězný tah není záplatovat dlouhý ocas rychleji. Je to zajistit, aby většina z něj nezáležela — a zastavit ty, které záleží, během hodin, ne týdnů.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+63
View File
@@ -0,0 +1,63 @@
---
title: "Modul 9 — Organizační odolnost"
description: "Sloučení Dev/Sec/Ops, integrace bezpečnosti s posunutím doleva, zajištění procesů pro týmy bez pocitu kontroly a vložená bezpečnostní revize do delivery pipeline."
eyebrow: "Konzultační modul"
lead: "Nemáte problém s nástroji. Máte problém s předávkami. Každá hranice mezi vývojem, bezpečností a provozem je hranicí, kde mizí zodpovědnost a akumuluje se křehkost. Tento modul tyto hranice strukturálně odstraňuje."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "Přehled modulů"
url: "/cs/consulting/skills/"
---
## Co přináší
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔗</div>
<div class="feature-item-body">
<h4>Sloučení Dev/Sec/Ops</h4>
<p>Strukturální designová práce pro sloučení vývoje, bezpečnosti a provozu do sdílené zodpovědnosti. Sdílená zodpovědnost znamená, že jeden tým vlastní systém od commitu po vyřazení — což znamená, že ho navrhuje tak, aby neselhával, protože selhání je jejich problém. Alternativou je systém navržený tak, aby vypadal dobře na demo day.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⬅️</div>
<div class="feature-item-body">
<h4>Integrace bezpečnosti s posunutím doleva</h4>
<p>Bezpečnostní kontroly vloženy do vývojové pipeline — SAST, skenování závislostí, skenování image kontejnerů, linting IaC — aby nálezy vypluly při commitu, kdy je vývojář opravit za deset minut, nikoli v produkci, kde organizaci stojí týdny. Bezpečnostní nálezy opravené ve vývoji stojí zhruba 1 % toho, co stojí v produkci.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧭</div>
<div class="feature-item-body">
<h4>Zajištění procesů pro týmy bez pocitu kontroly</h4>
<p>Strukturováno pro týmy, které mají nástroje a lidi, ale cítí, že bezpečnost nefunguje — alarmy, na které nikdo nereaguje, nálezy, které nikdo nevlastní, incidenty, které se opakují. Engagement mapuje selhání předávek, přiřazuje zodpovědnost a zavádí provozní rytmus, který převádí aktivity na výsledky.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔄</div>
<div class="feature-item-body">
<h4>Vložená bezpečnostní revize do delivery pipeline</h4>
<p>Přezkum bezpečnostní architektury vložen jako brána do životního cyklu projektu — nikoli zaškrtávací políčko na konci dodávky, ale strukturovaný kontrolní bod ve fázi návrhu, kdy jsou změny stále levné. Modely hrozeb vznikají jako přirozené artefakty procesu dodávky, nikoli jako oddělené compliance dokumenty.</p>
</div>
</div>
</div>
## Rozsah a předpoklady
| | |
|---|---|
| **Délka** | 60–90 dní |
| **Prostředí** | Jakákoli organizace s funkcí vývoje nebo delivery změn |
| **Předpoklady** | Executive sponzor s pravomocí měnit struktury týmů; ochota poctivě zkoumat organizační design |
| **Přirozené navazující** | Modul 11 (Blue/Purple Team) — po zabezpečení delivery pipeline budujte detekční schopnosti |
<div class="cta-strip">
<h2>Bezpečnost je problém organizačního designu</h2>
<p>Žádný nástroj neopraví předávku. Modul 9 řeší strukturu, na kterou nástroje nestačí.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/skills/" class="btn btn-outline">Přehled modulů</a>
</div>
</div>
+171
View File
@@ -0,0 +1,171 @@
---
title: "Konzultační moduly"
description: "14 nezávislých, samostatných bezpečnostních modulů. Začněte tam, kde bolí nejvíc — každý modul přináší měřitelnou hodnotu a vytváří apetit pro další."
eyebrow: "Modulární angažmá"
lead: "Každý modul stojí samostatně. Každý modul usnadňuje ten následující. Začněte tam, kde bolí nejvíc — ne tam, kde to říká rámec."
---
Každé angažmá začíná **Brownhat Diagnostikou** (Modul 0): strukturovaným dvoudenním hodnocením základní linie NIST CSF 2.0, které přinese prioritizovaný plán modulů. Diagnostika je placené, ohraničené angažmá a přináší hodnotu bez ohledu na to, zda bude následovat další práce.
<div class="modules-grid">
<div class="module-card">
<div class="module-num">Modul 0</div>
<h3><a href="/cs/consulting/module-0/">Brownhat Diagnostika</a></h3>
<p>Strukturované dvoudenní hodnocení základní linie NIST CSF 2.0. Upřímný obraz vaší bezpečnostní pozice, prioritizovaný seznam mezer a doporučené pořadí modulů. Syntéza kill chainu pomocí aplikace Kill Chain Assessment — mapuje neznámé prostředí do grafu útoku, vypočítá nejkratší cestu k existenčnímu dopadu a přiřadí každému nálezu remediační kvantum. Vstupní bod pro každého nového klienta.</p>
<div class="module-meta">
<span class="badge badge-blue">2 dny</span>
<span class="badge badge-blue">Všichni klienti</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 1</div>
<h3><a href="/cs/consulting/module-1/">Správa endpointů</a></h3>
<p>Inventarizace a enrollment zařízení, základní linie dodržování předpisů, discovery shadow IT, základní integrace podmíněného přístupu, nasazení ASTRAL pro detekci drift v Intune. Kompletní přehled zařízení za 30–45 dní.</p>
<div class="module-meta">
<span class="badge badge-blue">30–45 dní</span>
<span class="badge badge-green">M365 E3+</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 2</div>
<h3><a href="/cs/consulting/module-2/">Zabezpečení identity M365</a></h3>
<p>Kompletní census identit, registr CA politik, vynucení MFA, zablokování starší autentizace, nasazení PIM nebo JIT proces, PULSAR pro auditní log intelligence, audit a řízení přístupu hostů.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 dní</span>
<span class="badge badge-green">M365 E3+</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 3</div>
<h3><a href="/cs/consulting/module-3/">Hardening M365</a></h3>
<p>Ladění Exchange Online Protection, auditování poštovních schránek, forwarding Unified Audit Log, základní linie Secure Score a plán zlepšení, ASR pravidla, zachycení základní linie ASTRAL. Bez nového licencování pro E3 klienty.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 dní</span>
<span class="badge badge-green">Bez nových nákladů</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 4</div>
<h3><a href="/cs/consulting/module-4/">Správa dat &amp; compliance</a></h3>
<p>Nasazení štítků citlivosti, zásady uchovávání pro všechny workloady M365, DLP zásady, připravenost na eDiscovery, správa Teams, správa zřizování SharePoint. Regulatorní důkazy jako přirozený výstup.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 dní</span>
<span class="badge badge-orange">NIS2 · DORA · GDPR</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 5</div>
<h3><a href="/cs/consulting/module-5/">Most AI suverenity</a></h3>
<p>Inventura shadow AI, nasazení Azure OpenAI s privátními endpointy, podmíněný přístup pro AI nástroje, první RAG pipeline nebo doladěný model na proprietárních datech, zásada správy AI. Vaše zpravodajství zůstane vaše.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 dní</span>
<span class="badge badge-blue">Azure</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 6</div>
<h3><a href="/cs/consulting/module-6/">Hardening on-prem AD &amp; endpointů</a></h3>
<p>Kompletní census identit AD s analýzou osiřelých účtů a privilegií, audit kompromitovaných hesel (Elysium), rotace KRBTGT, LAPS, Sysmon, architektura PAW, hardening Azure AD Connect.</p>
<div class="module-meta">
<span class="badge badge-blue">45–60 dní</span>
<span class="badge badge-blue">Hybridní identita</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 7</div>
<h3><a href="/cs/consulting/module-7/">Obnova &amp; odolnost</a></h3>
<p>Přezkum a sanace architektury zálohování, nasazení neměnitelných záloh, runbooky pro disaster recovery, tabletop cvičení, ASTRAL základní linie jako plán obnovy. Otestovaná obnova, ne předpokládaná.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 dní</span>
<span class="badge badge-orange">Ransomware-odolné</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 8</div>
<h3><a href="/cs/consulting/module-8/">Správa hrozeb &amp; zranitelností</a></h3>
<p>Kvantová správa zranitelností pro éru, kde exploitation vede. Pozice v kill chainu, dostupnost a přítomnost exploitu nahrazují CVSS jako klíč prioritizace. Subtrakce ~90 % odstraňuje falešnou urgenci — zbyde 10 % skutečně zneužitelných ve vašem prostředí. Čtyři časově ohraničená kvanta: Kritická (hodiny — kompenzační kontrola, nikoli patch), Závažná (dny), Standardní (sprint), Temná (nespecifikovaná — přesměrovaná k discovery). Zero-budget discovery pomocí osquery a skriptů. Aplikace Kill Chain Assessment mapuje graf útoku a automaticky dimenzuje každý uzel.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 dní</span>
<span class="badge badge-green">Open-source první</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 9</div>
<h3><a href="/cs/consulting/module-9/">Organizační odolnost</a></h3>
<p>Sloučení Dev/Sec/Ops, integrace bezpečnosti s posunute doleva, zajišťování procesů pro týmy s pocitem „ztráty kontroly", řízení kvality, integrovaná bezpečnostní revize v delivery pipeline.</p>
<div class="module-meta">
<span class="badge badge-blue">60–90 dní</span>
<span class="badge badge-blue">Kultura + procesy</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 10</div>
<h3><a href="/cs/consulting/module-10/">Red Team &amp; validace</a></h3>
<p>Validace předpokladů po hardeningových modulech. Cílená simulace protivníka proti konkrétnímu útočnému řetězci identifikovanému v Brownhat Diagnostice. Měří skutečné bezpečnostní zlepšení, ne compliance skóre.</p>
<div class="module-meta">
<span class="badge badge-blue">15–30 dní</span>
<span class="badge badge-orange">Po hardeningu</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 11</div>
<h3><a href="/cs/consulting/module-11/">Základ Blue/Purple týmu</a></h3>
<p>Budování obranných schopností z existujících investic do nástrojů. Inženýrství detekcí, ladění alertů, vývoj pravidel SIEM, playbooks pro threat hunting. Vaše existující nástroje, konečně funkční.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 dní</span>
<span class="badge badge-blue">Existující nástroje</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 12</div>
<h3><a href="/cs/consulting/module-12/">Ochrana aktiv T0</a></h3>
<p>Klasifikace aktiv Tier 0 napříč identitou, infrastrukturou a daty. Architektura ochrany pro korunní jewely. Návrh privilegovaného přístupu zajišťující, že Tier 0 není nikdy dosažitelný kompromitací Tier 1 nebo 2.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 dní</span>
<span class="badge badge-orange">Architektura</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 13</div>
<h3><a href="/cs/consulting/module-13/">Architektura privilegovaného přístupu</a></h3>
<p>Návrh PAM pomocí Teleport, Tailscale/Headscale a JIT přístupu. Správa vzdáleného přístupu dodavatelů. Efemérní přihlašovací údaje, nahrávání relací a revize přístupu. Žádný trvalý přístup kde to jde.</p>
<div class="module-meta">
<span class="badge badge-blue">45–60 dní</span>
<span class="badge badge-blue">Open-source PAM</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Modul 14</div>
<h3><a href="/cs/consulting/module-14/">Suverénní komunikace</a></h3>
<p>Delta Chat chatmail relay, nasazení Matrix/Element, návrh krizového out-of-band kanálu. Komunikační infrastruktura, která zůstane dostupná a soukromá i při kompromitaci primární kolaborační platformy.</p>
<div class="module-meta">
<span class="badge badge-blue">15–30 dní</span>
<span class="badge badge-green">Self-hosted</span>
</div>
</div>
</div>
<div class="cta-strip">
<h2>Nevíte, kde začít?</h2>
<p>Brownhat Diagnostika mapuje vaši aktuální pozici na prioritizovanou sekvenci modulů. Jde o ohraničené angažmá s pevnou cenou a přináší hodnotu bez ohledu na to, zda bude následovat další práce.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Objednat diagnostiku</a>
<a href="/cs/consulting/" class="btn btn-outline">Náš přístup</a>
</div>
</div>
+115
View File
@@ -0,0 +1,115 @@
---
title: "Housekeeping jako služba"
description: "Dedikovaný pronajatý tým, který odstraňuje útočný povrch, na který vaše vlastní týmy nikdy nenajdou čas. Dva režimy: pomalý/levný/bezpečný Client-Directed a rychlý/rušivý Kill-Chain. Přepínatelné dle situace."
eyebrow: "Spravovaná služba"
lead: "Každé prostředí se hromadí. Každý projekt, každý zaměstnanec, každý dodavatelský vztah za sebou zanechá účty, oprávnění a konfigurace. Téměř nic je neodstraňuje. Ponecháno svému osudu, útočný povrch roste bez hranic — bez ohledu na to, co jiného opravíte. Tato služba to zastavuje."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
---
## Problém, který nikdo neřeší
Můžete opravit každý server, hardovat každou politiku, dokončit každý modul angažmá — a přesto každé čtvrtletí ztrácet půdu. Protože nikdo objekty *neodstraňuje*.
Účet odchozího dodavatele zůstane. Dočasné ACL se stane trvalým. VM spuštěný pro migraci je zapomenut, ale stále dosažitelný. Service principal s širokým souhlasem pro projekt, na který si nikdo nevzpomíná, ho stále drží. Prostředí objekty nepřetržitě přibírá.
Obvyklá odpověď je „naplánujeme sprint na úklid." Sprint na úklid se nikdy neuskuteční, protože nikdy není naléhavý — dokud není narušení.
## Proč tým poráží aktivitu — přeznamenění
Housekeeping jako *aktivita* je propustnost omezená **pozorností**. Pozornost je nejvolatilnější a nejpřerušitelnější zdroj v každé IT organizaci: v okamžiku, kdy přijde incident, audit nebo projektový termín, stream housekeepingu klesne na nulu.
Housekeeping jako *tým* je propustnost omezená **počtem zaměstnanců**, který je stabilní. Nelze ho tiše odfinancovat přeřazením priorit, protože je to položka rozpočtu a smlouva, nikoli dobrý úmysl.
Tento rozdíl je kategorický, nikoli marginální. Prostředí nepřetržitě přibírá objekty. Pokud úklid odstraňuje pomaleji než přírůstek, útočný povrch roste i když tým „dělá housekeeping." Dedikovaný tým, který odstraňuje *rychleji* než přírůstek, překročí nulovou čistou propustnost a **přeznamenuje**: ohraničený a klesající místo neomezeného růstu.
Dedikovaný tým není rychlejší kbelík. Je to rozdíl mezi kbelíkem a čerpadlem.
| | Housekeeping jako aktivita | Housekeeping jako tým |
|---|---|---|
| Propustnost omezena | Pozorností (volatilní, přerušitelná) | Počtem zaměstnanců (stabilní) |
| Chování při incidentu/termínu | Klesne na nulu | Drží minimum |
| Čistý efekt na útočný povrch | Obvykle záporný (přírůstek > úklid) | Kladný (úklid > přírůstek) |
| Odfinancování | Tiché, přeřazením priorit | Explicitní, vyžaduje zrušení smlouvy |
## Proč je to bezpečnostní funkce stavěná pro outsourcing
Většina bezpečnostních funkcí se outsourcuje špatně, protože vyžadují hluboký, aktuální kontext. Housekeeping je výjimka:
- **Procedurální propustnost, nikoli kontext.** Deaktivace účtu, jehož vlastník odešel před čtrnácti měsíci a od té doby se neautentizoval, nevyžaduje porozumění vašemu businessu. Procedura plus propustnost je definice outsourceovatelné práce.
- **Protichůdný vůči vlastní pozornosti klienta.** Je to práce, kterou nikdo interní nikdy nepriorizuje, protože nikdy není naléhavá — dokud není narušení. Přesně proto by to měl být celý business někoho jiného.
- **SLA-ovatelné na čistých metrikách.** Stáří backlogu, uzavřené položky za cyklus, čas od odhalení po vlastnictví a trend útočného povrchu jsou všechny měřitelné a smluvně ošetřitelné.
- **ASTRAL-gated pro důvěru.** Každá dispozice je vlastněná, prioritizovaná, klientem schválená položka backlogu procházející ASTRAL pull requestem. Vidíte každou akci. **Backlog je řídící povrch** — to je to, co z předání práce externímu týmu dělá snadné ano.
## Dva režimy
Stejný tým, stejný backlog a stejné nástroje dodávají dvě odlišné služby. Liší se v jedné ose — **kdo přiděluje prioritu** — a vše ostatní z toho plyne.
### Režim 1 — Client-Directed (noční úklidová četa)
Noční úklidová četa pracuje kolem vašeho provozu, podle vámi nastaveného rozvrhu, a ráno je kancelář čistá. Vy ukazujete; oni uklízejí. Klient vlastní prioritizaci — tým odstraňuje co klient předloží, v rámci procesů řízení změn, nikdy nevynucuje okno, se kterým klient nesouhlasil.
**Charakter:** levný, pomalý, bezpečný, důkladný, nerušivý.
**Výnos:** lineární a spolehlivý. Útočný povrch přestane růst a pomalu ustoupí.
**Ideální pro:** organizace, které vědí, že nashromáždily dluh, chtějí ho průběžně splácet a dávají přednost provozní stabilitě před rychlostí.
### Režim 2 — Kill-Chain (záchranný tým)
Priority jsou přiděleny bezpečnostní analýzou — kill chainem, nikoli provozní pohodou. Tým uzavírá řetězec zvenčí, záměrně neomezený normálním kalendářem změn, protože jde o odstranění existenčních cest rychleji, než by byrokracie kdy umožnila.
**Charakter:** drahý, rychlý, rušivý, asymetrický výnos.
**Výnos:** asymetrický. Malý počet cílených odstranění na kill chainu přinese nepřiměřené snížení rizika. Trend délky řetězce se neohýbá — klesá.
**Ideální pro:** po incidentu, před auditem, před/po M&A nebo pro jakoukoli organizaci, která přijala, že nese existenční expozici a chce ji odstranit rychleji, než dovolují vlastní procesy.
**Vyžaduje:** executive air cover. Narušení je zde vlastností, nikoli chybou.
### Přepínatelnost je produkt
Klient může měnit režimy podle situace. Výchozí postoj je Režim 1: levný, kontinuální, bezpečný. Když přijde spouštěcí událost — narušení, termín auditu, kill-chain assessment, který odkryje nepřijatelnou nejkratší cestu — stejný tým eskaluje do Režimu 2 na definované okno, uzavře existenční cesty pod executive air cover a pak se vrátí k Režimu 1.
Nekupujete dva týmy. Kupujete jeden tým se škrtičem — levná kontinuita plus možnost přidat plyn, když si to hrozba zaslouží.
## Co tým odstraňuje
Zastaralé uživatelské, dodavatelské a servisní účty bez vlastníka. Osiřelá členství ve skupinách a oprávnění, která přežila svůj projekt. Staré registrace aplikací a service principalů. Zaregistrovaná zařízení, která se již nepoužívají. Politiky podmíněného přístupu bez pojmenovaného vlastníka. Starší protokoly (NTLM, základní auth, SMBv1). DNS záznamy pro dekomisionované služby. Dočasná pravidla firewallu, která se stala trvalými. Staré GPO, admin práva a certifikáty.
## Autorizační lišta
Tým, který deaktivuje účty a odstraňuje ACL, potřebuje strukturu, která zabrání přestřižení čehokoli kritického:
- Každá dispozice je **položka backlogu gated ASTRAL pull requestem, který klient schvaluje**. Nic není odstraněno tiše.
- **Soft-deaktivace s oknem pro vrácení před tvrdým smazáním.** Deaktivovat, počkat, potvrdit, že nic nefunguje, pak odstranit.
- **Freeze / break-glass režim.** Během aktivního incidentu je housekeeping smyčka zmrazitelná, aby tým nikdy nevrátil akci incident response.
- **Explicitní rozsah.** Autorita týmu je ohraničena na pojmenované třídy objektů a pojmenované rozsahy, zdokumentované a schválené.
## Komerční úrovně
| Úroveň | Co to je | Nejlepší pro |
|--------|---------|--------------|
| **Assessment & Backlog Standup** | Kill-chain assessment + ASTRAL/PULSAR feedery, naplněný a prioritizovaný backlog, definovaný rozsah a autorizační lišta | Klienti s nahromaděným dluhem a bez fronty |
| **Retainer Režim 1** | Kontinuální, change-windowed attrition backlogu na smluvní propustnosti | Klienti ve stabilním stavu, kteří chtějí povrch snižovat bez narušení |
| **Angažmá Režim 2** | Časově ohraničená, exec-sponzorovaná kampaň pro uzavření existenčních cest | Po incidentu, před auditem, M&A nebo nepřijatelná kill-chain expozice |
| **Přepínatelný Retainer** | Základ Režimu 1 s předem dohodnutými spouštěči eskalace Režimu 2 | Klienti, kteří chtějí levnou kontinuitu a možnost eskalovat |
SLA metriky jsou stejné napříč všemi úrovněmi: uzavřené položky za cyklus, stáří P0/P1, čas od odhalení po vlastnictví a trend útočného povrchu / délky kill chainu.
## Antifragilní kontext
Housekeeping jako služba je vrstva lidské akce pod CQRE nástroji: ASTRAL a PULSAR povrchují a prioritizují; housekeeping tým *jedná*. Rozšíření identity ownership ASTRAL — signály smrti (účet vlastníka deaktivován), signály ticha (žádná autentizace rok) a signály změny (mutace vlastností) — automaticky generuje prioritizované položky backlogu. Detekovat → přibírat → odstraňovat → reportovat, v jedné smyčce.
Bezpečnost je kontaktní sport. Nástroje práci najdou. Tým ji dokončí.
<div class="cta-strip">
<h2>Připraveni přeznamenat?</h2>
<p>Assessment & Backlog Standup je správný vstupní bod — kill-chain assessment, který naplní a prioritizuje frontu, než ji tým vezme do ruky.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/" class="btn btn-outline">Náš přístup</a>
</div>
</div>
+10
View File
@@ -0,0 +1,10 @@
---
title: "Produkty"
description: "Open-source i komerční nástroje pro správu M365, uchování auditních logů a správu konfigurace."
eyebrow: "Open Source & Komerční"
lead: "Tři nástroje, které dohromady poskytují kompletní přehled o vašem Microsoft 365 tenantovi — co se stalo, jak vypadá vaše konfigurace a co to vše znamená."
---
PULSAR zachycuje signál. ASTRAL uchovává základní linii. AURORA dává oběma smysl.
Všechny tři nástroje jsou samostatně užitečné a v kombinaci postupně silnější.
+70
View File
@@ -0,0 +1,70 @@
---
title: "ASTRAL"
description: "Admin Security: Tenant Review, Automation & Lifecycle. Git-sledované snímky konfigurace M365 s detekcí drift, revizním workflow přes PR a obnovením základní linie."
eyebrow: "Zdarma & Open Source"
lead: "ASTRAL odpovídá na otázku, kterou váš M365 tenant neumí zodpovědět: jak vypadá naše konfigurace teď, jak vypadala dříve, co se změnilo — a kdo tu změnu schválil?"
icon: "🌌"
badge:
text: "Zdarma & Open Source"
color: "green"
actions:
- label: "Zobrazit na GitHub"
url: "https://github.com/cqrenet/astral"
external: true
primary: true
- label: "Přejít na AURORA →"
url: "/cs/products/aurora/"
---
## Co ASTRAL dělá
ASTRAL pořizuje pravidelné snímky konfigurace Microsoft 365 — zásady podmíněného přístupu, profily dodržování předpisů a konfigurace Intune, přiřazení rolí správce, metody ověřování, nastavení přístupu mezi tenanty, privilegované skupiny a další — a ukládá je jako verzované soubory v Git repozitáři.
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📸</div>
<div class="feature-item-body">
<h4>Snímky konfigurace</h4>
<p>Pravidelné, automatizované snímky celé konfigurace M365 uložené jako čitelné JSON soubory v Gitu. Pokrytí zahrnuje podmíněný přístup, Intune, role Entra ID, PIM zásady, metody ověřování, přístup mezi tenanty, ochranu identit a další.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔀</div>
<div class="feature-item-body">
<h4>Detekce drift & Pull Requesty</h4>
<p>Když se konfigurace změní mezi snímky, ASTRAL otevře Pull Request v Azure DevOps zobrazující přesně, co se změnilo, ve čitelném diffu. Pokud je nakonfigurován Azure OpenAI, přidá vysvětlení změny v přirozeném jazyce.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">✅</div>
<div class="feature-item-body">
<h4>Revizní stopa se schválením</h4>
<p>PR lze revidovat, komentovat a schválit nebo zamítnout týmem. Každé rozhodnutí je opatřeno časovým razítkem a připsáno recenzentovi — hotový auditní důkaz bez dalšího nástrojového vybavení.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">↩️</div>
<div class="feature-item-body">
<h4>Obnovení základní linie</h4>
<p>Pokud je PR drift zamítnut, pipeline může automaticky obnovit předchozí konfiguraci. Git základní linie je zdrojem pravdy. „Co obnovit?" se stane deterministickou operací, ne nouzovou rekonstrukcí.</p>
</div>
</div>
</div>
## Soulad s předpisy
ASTRAL přímo mapuje na:
- **NIS2 (čl. 21)** — správa konfigurace a evidence změnového řízení
- **DORA (čl. 11)** — záznamy o správě ICT změn; Git stopa je přímo použitelná jako důkaz pro auditory
- **GDPR (čl. 5 odst. 2)** — zásada odpovědnosti; ASTRAL produkuje konkrétní artefakty prokazující soulad
- **ISO 27001 A.8.9** — správa konfigurace; A.8.15 — protokolování
<div class="cta-strip">
<h2>Připraveni nasadit ASTRAL?</h2>
<p>Kompletní průvodce nasazením, bootstrap skripty a pipeline YAML jsou na GitHub.</p>
<div class="actions">
<a href="https://github.com/cqrenet/astral" class="btn btn-primary" target="_blank" rel="noopener">Zobrazit na GitHub</a>
<a href="/cs/products/aurora/" class="btn btn-outline">Prozkoumat AURORA →</a>
</div>
</div>
+78
View File
@@ -0,0 +1,78 @@
---
title: "AURORA"
description: "Audit, Unified Review, Observability & Remediation for Administrators. Komerční AI vrstva propojující PULSAR a ASTRAL."
eyebrow: "Komerční"
lead: "AURORA sedí před PULSAR a ASTRAL, propojuje je do jediného sjednoceného rozhraní s AI diagnostikou napříč nástroji, orchestrací více scopů a obohaceným SIEM forwarding."
icon: "🌅"
badge:
text: "Komerční"
color: "orange"
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
- label: "← Zpět na produkty"
url: "/cs/products/"
---
## Co AURORA dělá
PULSAR zachycuje signál. ASTRAL uchovává základní linii. AURORA dává oběma smysl.
AURORA je sjednocená operační platforma, která se připojuje k PULSAR a ASTRAL přes jejich MCP servery, vystavuje jediné sjednocené rozhraní vašemu AI nástroji a poskytuje diagnostiku napříč nástroji, kterou ani jeden produkt sám nemůže zodpovědět. **AURORA neukládá žádná data** — všechna data žijí v PULSAR (MongoDB) a ASTRAL (Git). AURORA je čistě vrstva dotazování, orchestrace a intelligence.
## Diagnostické nástroje napříč produkty
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔗</div>
<div class="feature-item-body">
<h4>Korelace drift s auditem</h4>
<p><em>Kdo v portálu spustil tento drift commit?</em> — Získá nedávné Git commity z ASTRAL a auditní události PULSAR ve stejném okně, páruje podle časového razítka a názvu prostředku. Přímo splňuje požadavek DORA čl. 11 prokázat, kdo co změnil a proč.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏥</div>
<div class="feature-item-body">
<h4>Diagnostika chyb zásad</h4>
<p><em>Proč tato compliance zásada hlásí chybu na některých zařízeních?</em> — Načte konfiguraci a přiřazení zásad z ASTRAL, dotáže se PULSAR na auditní události dotýkající se dané zásady, vytvoří narativní odpověď. Dvouhodinové vyšetřování na 2 minuty.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📊</div>
<div class="feature-item-body">
<h4>Souhrnné bezpečnostní hlášení tenanta</h4>
<p><em>Co se v mém tenantovi tento týden stalo a co bych měl vědět?</em> — Kombinuje otevřené drift PR z ASTRAL se souhrnem událostí PULSAR, generuje executive briefing. Týdenní bezpečnostní přehled bez manuální práce.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚖️</div>
<div class="feature-item-body">
<h4>Porovnání scopů</h4>
<p><em>Čím se liší zásady podmíněného přístupu v produkci a vývoji?</em> — Porovnává stav konfigurace napříč nakonfigurovanými pojmenovanými scopy (produkce, staging, testovací tenanty).</p>
</div>
</div>
</div>
## Ceny
AURORA je účtována za tenant, ne za uživatele. Self-hosted zákazníci přinášejí vlastní Azure OpenAI endpoint (BYOAI). Hosted zahrnuje plně spravovanou infrastrukturu a AI.
| Tier | Self-Hosted | Hosted |
|------|-------------|--------|
| Jeden tenant | 259 €/měs. (2 590 €/rok) | 389 €/měs. (3 890 €/rok) |
| Až 5 scopů | 429 €/měs. (4 290 €/rok) | 599 €/měs. (5 990 €/rok) |
| Enterprise | Individuální | Individuální |
Roční fakturace zahrnuje slevu ~15 %.
**Podpora** je zahrnuta ve všech tierech AURORA (e-mail, SLA 2 pracovní dny). Enterprise zahrnuje dedikovaný Slack kanál a odezvu tentýž den.
<div class="cta-strip">
<h2>Máte zájem o AURORA?</h2>
<p>AURORA je v aktivním vývoji. Kontaktujte nás pro diskusi o vašich požadavcích nebo pro zařazení do programu předčasného přístupu.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/products/pulsar/" class="btn btn-outline">Začněte s PULSAR (Zdarma)</a>
</div>
</div>
+80
View File
@@ -0,0 +1,80 @@
---
title: "PULSAR"
description: "Platform for Unified Log Search, Alerting & Review. Bezplatná open-source ingesta auditních logů M365 s neomezeným uchováním a rozhraním pro AI dotazování."
eyebrow: "Zdarma & Open Source"
lead: "PULSAR průběžně ingrestuje administrativní auditní události Microsoft 365 a ukládá je do databáze, kterou vlastníte. Vyhledávejte, upozorňujte, přeposílejte do SIEM a dotazujte přes AI — bez časového omezení uchování."
icon: "📡"
badge:
text: "Zdarma & Open Source"
color: "green"
actions:
- label: "Zobrazit na GitHub"
url: "https://github.com/cqrenet/pulsar"
external: true
primary: true
- label: "Přejít na ASTRAL →"
url: "/cs/products/astral/"
---
## Problém, který PULSAR řeší
Microsoft 365 E3 poskytuje 90 dní uchovávání auditních logů dostupných pouze přes portál Microsoft Purview. Události starší než 90 dní jsou trvale ztraceny. Neexistuje žádné upozorňování na administrativní akce, žádné přeposílání ani žádná integrace mimo Microsoft API.
PULSAR toto řeší celkově. Po nasazení jsou auditní události průběžně stahovány a ukládány do vašeho vlastního MongoDB. Uchování je neomezené. Data jsou vaše.
## Co PULSAR dělá
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📥</div>
<div class="feature-item-body">
<h4>Průběžná ingesta</h4>
<p>Dotazuje Microsoft audit API v konfigurovatelném intervalu a ukládá všechny události inkrementálně. Vodoznaky zajišťují, že mezi spuštěními nic není vynecháno. Zdroje: auditní logy Entra ID, auditní logy Intune, Exchange / SharePoint / Teams přes Office 365 Management Activity API.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Vyhledávací a filtrační rozhraní</h4>
<p>Webové rozhraní pro vyhledávání událostí podle workloadu, typu operace, uživatele, prostředku a časového rozsahu. Navrženo pro typ vyšetřování, který se jinak provádí ručním procházením portálu Purview.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔔</div>
<div class="feature-item-body">
<h4>Upozorňování</h4>
<p>Upozorňování na základě pravidel s doručením přes webhook. Spusťte alert při nových trvalých přiřazeních role Global Admin, změnách CA politiky mimo pracovní dobu, pozvánkách hostů do citlivých skupin a dalších událostech.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📤</div>
<div class="feature-item-body">
<h4>SIEM Forwarding</h4>
<p>Přeposílání auditních událostí do externího SIEM. Události jsou před přeposláním normalizovány a obohaceny — kvalitnější data než přímá integrace Microsoft API.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🤖</div>
<div class="feature-item-body">
<h4>MCP Server</h4>
<p>PULSAR vystavuje <code>search_events</code>, <code>get_event</code> a <code>get_summary</code> přes Model Context Protocol, takže AI asistent (Claude, Copilot nebo jiný MCP klient) může dotazovat auditní log přirozeným jazykem.</p>
</div>
</div>
</div>
## Soulad s předpisy
**NIS2 (čl. 21):** 90denní okno portálu M365 nesplňuje požadavky na průběžné, spolehlivé uchovávání auditních logů. Neomezené uchování v PULSAR, nezávisle ovládané, splňuje očekávání dozorových orgánů.
**GDPR (čl. 33):** Schopnost rychle určit, co se stalo a jaká data byla ovlivněna, přímo závisí na přístupných, prohledavatelných auditních logech pro dodržení 72hodinové lhůty pro hlášení narušení.
**DORA (čl. 10):** Neomezené uchovávání auditních logů ICT událostí je přímým požadavkem pro finanční subjekty.
<div class="cta-strip">
<h2>Připraveni nasadit PULSAR?</h2>
<p>Kompletní dokumentace nasazení a Docker image jsou dostupné na GitHub.</p>
<div class="actions">
<a href="https://github.com/cqrenet/pulsar" class="btn btn-primary" target="_blank" rel="noopener">Zobrazit na GitHub</a>
<a href="/cs/products/astral/" class="btn btn-outline">Prozkoumat ASTRAL →</a>
</div>
</div>
+82
View File
@@ -0,0 +1,82 @@
---
title: "Virtuální CISO & bezpečnostní architekt"
description: "Frakcionální bezpečnostní vedení — strategické směřování, vlastnictví rizik, reporting vedení a řízení programu bez plného pracovního úvazku."
eyebrow: "Retained Capability"
lead: "Virtuální CISO vám dává zkušeného bezpečnostního lídra, který zná vaše prostředí, vlastní váš program řízení rizik a je zodpovědný za výsledky — na retaineru, který odpovídá velikosti a rozpočtu vaší organizace."
actions:
- label: "Kontaktujte nás"
url: "/cs/about/#contact"
primary: true
---
## Problém s outsourcingem bezpečnostní strategie
Outsourcing vašeho SOC nevyvede z vás riziko. Vyvede alert triage. Myšlení — inženýrství detekcí, modelování hrozeb, povědomí o businessovém kontextu — musí zůstat uvnitř vaší organizace. Jinak platíte za generický playbook někoho jiného aplikovaný na vaše specifické prostředí hrozeb.
Totéž platí pro bezpečnostní vedení. Compliance konzultant může psát politiky. MSSP může provozovat vaše nástroje. Ale ani jeden nevlastní váš program rizik, nemluví s vaším vedením v jazyce, kterému rozumí, ani nebuduje bezpečnostní pozici, která odráží váš skutečný business.
## Co virtuální CISO dělá
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Vlastnictví rizik & strategie</h4>
<p>Překládá váš businessový kontext do bezpečnostního programu. Identifikuje a prioritizuje existenční rizika — ne generický checklist rámce — a buduje plán, který odráží váše skutečné prostředí hrozeb, rozpočet a schopnosti týmu.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏛️</div>
<div class="feature-item-body">
<h4>Reporting vedení & představenstva</h4>
<p>Stav bezpečnosti komunikovaný v businessových termínech. Zprávy o rizicích pro vedení, briefingy o incidentech a investiční podklady. Vedoucí pracovníci dostávají informace potřebné pro rozhodování; praktici dostávají směr potřebný pro realizaci.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏗️</div>
<div class="feature-item-body">
<h4>Bezpečnostní architektura</h4>
<p>Autorita pro bezpečnostní rozhodnutí napříč identitou, infrastrukturou, daty a aplikacemi. Architektonická revize nových projektů, hodnocení dodavatelů a technologická rozhodnutí dříve, než vytvoří technický dluh.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🤝</div>
<div class="feature-item-body">
<h4>Správa dodavatelů & MSSP</h4>
<p>Pokud outsourcujete SOC, pentest nebo compliance funkce, stále potřebujete někoho s odbornými znalostmi pro briefing dodavatelů, hodnocení jejich výstupů a jejich odpovědnost. SLA MSSP měří objem tiketů — váš vCISO měří, zda jsou hrozby skutečně detekovány.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📋</div>
<div class="feature-item-body">
<h4>Compliance & regulatorní program</h4>
<p>NIS2, DORA, GDPR, ISO 27001, SOC 2 — tyto rámce vyžadují více než politické dokumenty. vCISO buduje důkazy, mapuje kontroly, řídí vztah s auditory a zajišťuje, že váš compliance program je prokazatelný, ne divadelní.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📈</div>
<div class="feature-item-body">
<h4>Budování interních schopností</h4>
<p>Pracuje po boku vašeho týmu na budování schopností, které ve vaší organizaci zůstanou, když angažmá skončí. Cílem je nezávislost, ne závislost.</p>
</div>
</div>
</div>
## Pro koho je tato služba určena
**Středně velké organizace (50–500 zaměstnanců)**, které se posunuly za hranici „IT řeší bezpečnost", ale nemohou odůvodnit plat, benefity a náklady fulltime CISO. vCISO přináší odbornost za zlomek nákladů.
**Regulovaná odvětví**, kde je prokazatelná bezpečnostní správa regulatorním požadavkem, ne hezkou možností. DORA, NIS2 a odvětvově specifické požadavky potřebují někoho, kdo rozumí jak regulaci, tak technologii.
**Organizace s outsourcovanými bezpečnostními operacemi**, které potřebují někoho, kdo dokáže přesně briefovat MSSP, hodnotit jejich výstupy a investice zpřístupnit vedení.
**Post-incidentní organizace**, které potřebují strukturovaný program obnovy a upřímné hodnocení toho, co selhalo.
<div class="cta-strip">
<h2>Připraveni na rozhovor?</h2>
<p>Angažmá vCISO obvykle začíná Brownhat Diagnostikou — upřímným hodnocením vaší situace před dohodou o rozsahu a struktuře retaineru.</p>
<div class="actions">
<a href="/cs/about/#contact" class="btn btn-primary">Kontaktujte nás</a>
<a href="/cs/consulting/" class="btn btn-outline">Náš konzultační přístup</a>
</div>
</div>
+16
View File
@@ -0,0 +1,16 @@
---
heroTitle: "Antifragile Cybersecurity"
heroSub: "Open-source M365 governance tools. Practical consulting. Security that grows stronger from disruption."
productsTitle: "The M365 Governance Suite"
productsSub: "Three complementary tools — PULSAR, ASTRAL, and AURORA — that together answer every question about what happened and what changed in your Microsoft 365 tenant."
pulsarTagline: "What happened, when, and by whom?"
astralTagline: "What does my config look like, and what changed?"
auroraTagline: "What does it mean and what should I do?"
pulsarDesc: "Continuous M365 audit log ingestion with indefinite retention, search UI, REST API, alerting, SIEM forwarding, and an MCP server for AI-assisted queries."
astralDesc: "Git-tracked snapshots of M365 configuration. Automatic drift detection, PR-based review workflow, baseline restore, and indefinite history."
auroraDesc: "A unified AI-assisted layer connecting PULSAR and ASTRAL. Cross-tool diagnostics, multi-scope support, enriched SIEM forwarding."
servicesTitle: "Security That Grows Stronger"
servicesSub: "Consulting and strategic services built on one principle: every disruption should leave your organisation more capable than before."
consultingDesc: "The Brownhat methodology — start with what you own, close the kill chain, build retained capability. Modular engagements from 30 days upward."
vcisoDesc: "Fractional security leadership for organisations that need strategic direction without a full-time hire. Risk ownership, board reporting, vendor governance."
---
+52
View File
@@ -0,0 +1,52 @@
---
title: "About CQRE"
description: "Specialist cybersecurity consultancy and open-source tool developer. Antifragile security for organisations that have outgrown generic advice."
eyebrow: "About Us"
lead: "CQRE.NET Ltd is a specialist cybersecurity consultancy registered in the United Kingdom, operating primarily from Prague, Czech Republic. We work with organisations across Central Europe and the UK."
---
## Who We Are
We help organisations close the gap between their security investments and their actual security posture. In practice, this means auditing what exists honestly — not what the policies say should exist — maximising value from tools already paid for, and building retained capability inside client organisations rather than dependencies on us.
We operate under the **Brownhat** brand when engaging with clients — a name that reflects our core philosophy: we work in brownfield environments (built up, lived in, carrying the weight of past decisions) and our job is to recultivate what exists before recommending anything new.
We also build open-source tools — **PULSAR** and **ASTRAL** — used by M365 administrators and security teams who need continuous audit log retention and configuration governance without vendor lock-in. **AURORA**, our commercial intelligence layer, sits above both.
## How We Think
Five principles shape every recommendation we make:
| Principle | What it means in practice |
|-----------|--------------------------|
| **Structural Decoupling** | Identify and remove hidden dependencies before they become fatal. Do not add complexity that creates new ones. |
| **Optionality Preservation** | Spend your budget on things that preserve your ability to change direction. Every unnecessary tool purchase reduces strategic flexibility. |
| **Stress-to-Signal Conversion** | Every incident, failure, and near-miss is intelligence. Build systems that learn from disruption rather than merely surviving it. |
| **Sovereign Intelligence** | Your proprietary data should improve your own capability, not a vendor's model. Own the tools and systems you depend on. |
| **Asymmetric Payoff Design** | Small, targeted investments on existential risks yield disproportionate protection. Concentrate effort where failure is fatal. |
## What We Do Not Do
**We do not run a 24/7 SOC.** We deploy, configure, and commission monitoring tools. For continuous managed response, we work with commercial partners or help clients build internal capability.
**We do not sign off on compliance audits.** We prepare clients for audits — mapping controls, building evidence packages, closing gaps. The audit opinion belongs to a qualified auditor.
**We do not replace your IT team.** We work alongside your people, transfer knowledge as a matter of course, and leave when the engagement closes. When we leave, your team can operate what we built.
**We disclose our commercial relationships.** We have partnerships with Huntress, Tailscale, Thinkst Canary, and Tenable. If we recommend one of these tools, we say so and explain why the open-source alternative does not meet your specific need.
## Contact {#contact}
The best way to start is to send us a message describing your situation. We will respond with an honest assessment of whether and how we can help.
| | |
|-|-|
| **Email** | hello@cqre.net |
| **Web** | cqre.net |
| **Languages** | English, Czech |
| **Geography** | Czech Republic, Slovakia, UK; remote engagements across the EU |
| **Response time** | Initial reply within 1 business day |
For open-source tool questions, issues, and contributions, please use the GitHub repositories directly:
- [github.com/cqrenet/pulsar](https://github.com/cqrenet/pulsar)
- [github.com/cqrenet/astral](https://github.com/cqrenet/astral)
+85
View File
@@ -0,0 +1,85 @@
---
title: "Antifragile Consulting"
description: "The Brownhat methodology — modular security consulting that starts with what you own, closes the kill chain, and builds capability your team retains."
eyebrow: "Brownhat Methodology"
lead: "We help organisations close the gap between their security investments and their actual security posture. Every engagement starts with a diagnostic. No recommendations before we understand the environment."
---
## The Antifragile Principle
Most security programmes optimise for robustness — the ability to withstand shocks. Antifragility goes further. An antifragile organisation does not merely survive disruptions. It grows stronger from them.
Every incident produces structural improvement. Every competitor's failure creates market opportunity. Every regulatory demand is met with evidence, not promises.
## The Five Pillars
<div class="pillars">
<div class="pillar">
<div class="pillar-num">01</div>
<h4>Structural Decoupling</h4>
<p>Identify and remove hidden dependencies before they become fatal. We do not add complexity that creates new ones.</p>
</div>
<div class="pillar">
<div class="pillar-num">02</div>
<h4>Optionality Preservation</h4>
<p>Spend your budget on things that preserve your ability to change direction. Every unnecessary tool purchase reduces your strategic flexibility.</p>
</div>
<div class="pillar">
<div class="pillar-num">03</div>
<h4>Stress-to-Signal Conversion</h4>
<p>Every incident, failure, and near-miss is intelligence. Build systems that learn from disruption rather than merely surviving it.</p>
</div>
<div class="pillar">
<div class="pillar-num">04</div>
<h4>Sovereign Intelligence</h4>
<p>Your proprietary data should improve your own capability, not a vendor's model. Own the tools and systems you depend on.</p>
</div>
<div class="pillar">
<div class="pillar-num">05</div>
<h4>Asymmetric Payoff Design</h4>
<p>Small, targeted investments on existential risks yield disproportionate protection. Concentrate effort where failure is fatal.</p>
</div>
</div>
## How Engagements Work
We do not sell monolithic transformation projects. We sell **independent modules that stack**. Each module delivers measurable value in 30–90 days and creates natural appetite for the next phase.
Every engagement begins with the **Brownhat Diagnostic** — a structured two-day NIST CSF 2.0 baseline assessment that produces an honest, prioritised picture of where the organisation stands. We do not make module recommendations before we understand the environment.
**What every engagement produces:** a defined scope, a defined deliverable, and assets delivered to your own repository. Every script, detection rule, configuration, and runbook we produce belongs to you. When an engagement closes, you are operationally independent.
## What Makes Us Different
**We start with what you own.** Most consultants arrive with a shortlist of products. We arrive with a diagnostic. Before any purchase is discussed, we exhaust the capabilities of existing tools. If your Microsoft E3 tenant can close the gap, we configure it. We earn fees from expertise, not licence margins.
**We price by deliverable, not by the hour.** Every engagement has a defined scope and defined output before work begins. No open-ended retainers disguised as ongoing support.
**We disclose our commercial relationships.** We have partnerships with Huntress, Tailscale, Thinkst Canary, and Tenable. When we recommend one of these tools, we say so and explain why the open-source alternative does not meet the specific need.
**We tell you what we cannot do.** We are a specialist practice. We do not run a 24/7 SOC. We do not sign off on compliance audits. We do not replace your IT team. When a need falls outside our practice, we say so and point you to the right provider.
## Standards Alignment
The Brownhat module set maps directly onto major regulatory frameworks:
- **NIS2 (EU 2022/2555)** — Article 21 measures: configuration management (ASTRAL), logging and monitoring (PULSAR), access control, incident detection
- **DORA (EU 2022/2554)** — ICT change management records (ASTRAL Git trail), incident log retention (PULSAR), ICT third-party risk governance
- **GDPR Article 32** — Continuous configuration governance and audit log retention as "appropriate technical measures"
- **ISO 27001** — A.8.9 configuration management, A.8.15 logging, control evidence produced as a natural output of the engagement
- **CIS Controls v8** — IG1 as a non-negotiable 90-day floor, achieved primarily through existing tool configuration
## Brownfield Track
The main engagement model assumes a consultant walking into someone else's enterprise estate. The Brownfield Handbook applies the same methodology to the infrastructure you grew yourself — the self-hosted stack that accreted, the homelab that became production, the one box that quietly turned load-bearing. Discovery by observation, pruning, pets-versus-cattle, rebuildability, and deliberate stress: the antifragile five-part arc applied to the estate nobody designed.
This track is for self-hosters, small platforms, and teams that need to antifragile their own organically-grown infrastructure — and who want to validate the whole methodology by running it against something where the consequences are theirs.
<div class="cta-strip">
<h2>Start with the Brownhat Diagnostic</h2>
<p>The entry point for every new client. A structured two-day assessment that produces a prioritised picture of where you stand and what matters most to fix.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+86
View File
@@ -0,0 +1,86 @@
---
title: "Module 0 — Brownhat Diagnostic"
description: "The entry point for every engagement. A structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised security roadmap, a mapped kill chain, and sized remediation quanta."
eyebrow: "Consulting Module"
lead: "Before any module recommendation, we need an honest picture of where you actually stand. The Brownhat Diagnostic is a structured two-day workshop — no tools installed, no scanning — that produces the clearest picture of your security posture and what matters most to fix."
actions:
- label: "Book a Diagnostic"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What the Diagnostic Produces
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📋</div>
<div class="feature-item-body">
<h4>NIST CSF 2.0 Gap Report</h4>
<p>An honest scoring of your posture across all six CSF 2.0 functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — with the gaps that matter most clearly separated from the ones that don't.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🗺️</div>
<div class="feature-item-body">
<h4>Kill Chain Map</h4>
<p>Using the Kill Chain Assessment app, we model your environment as an attack graph during the diagnostic. The app computes the shortest path from an attacker's entry point to your crown jewels — the kill chain — and identifies exactly which links need breaking first.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚡</div>
<div class="feature-item-body">
<h4>Quantum-Sized Remediation Plan</h4>
<p>Every finding on the kill chain is sized into a remediation quantum: Critical (hours), Severe (days), Standard (sprint), or Dark (needs discovery first). You leave with a plan ordered by time-to-existential-impact, not by CVSS score.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📦</div>
<div class="feature-item-body">
<h4>Prioritised Module Roadmap</h4>
<p>A recommended sequence of modules derived directly from your gap picture and kill chain. Not a generic framework recommendation — a sequence built on what we actually found in your environment.</p>
</div>
</div>
</div>
## How It Works
The Diagnostic is a two half-day structured workshop with your IT lead, a business process owner, and whoever is accountable for security decisions. No homework before. No questionnaire to fill in. Pre-filled questionnaires produce aspirational answers; the workshop produces honest ones.
**Session 1 — Context and Foundation:** GOVERN and IDENTIFY domains. Who is accountable for security, how decisions are made, what assets exist, and how risk is assessed. This is where the governance gaps surface — usually faster than clients expect.
**Session 2 — Controls, Detection, and Recovery:** PROTECT, DETECT, RESPOND, and RECOVER. What controls are actually in place and enforced (not just configured), how alerts are handled, how incidents are managed, and whether recovery has ever been tested. Kill chain synthesis runs in parallel as findings accumulate.
**What we do not do:** install tools, collect data from systems, or make recommendations before the picture is complete. We earn the right to recommend by understanding the environment first.
## Deliverables
Everything goes to your repository. At the end of the two days you receive:
- NIST CSF 2.0 gap report (strengths, gaps, severity ratings)
- Kill chain diagram and shortest-path analysis
- Quantum-bucketed remediation priorities (P0 / P1 / P2 with time budgets)
- Module roadmap with recommended sequencing and rationale
- Findings backlog seeded and ready for the housekeeping stream
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 2 half-days (4 hours each) |
| **Format** | In-person strongly preferred; remote with camera-on acceptable |
| **Who attends** | IT lead, executive sponsor (mandatory); business process owner (recommended) |
| **Prerequisites** | None — this is the starting point |
| **Follow-on** | Delivers a module roadmap; further modules are optional |
The Diagnostic is a bounded, fixed-price engagement. It delivers value regardless of whether further work follows. We have never run a diagnostic that did not surface something the client did not know.
<div class="cta-strip">
<h2>Start here</h2>
<p>Every engagement begins with the Brownhat Diagnostic. It is the only honest way to select a module sequence.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Book a Diagnostic</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+76
View File
@@ -0,0 +1,76 @@
---
title: "Module 1 — Endpoint Management Foundation"
description: "Device inventory, Intune enrollment, compliance baseline, shadow IT discovery, and ASTRAL deployment for drift detection. Full device visibility in 30–45 days."
eyebrow: "Consulting Module"
lead: "You cannot govern what you cannot see. Endpoint management is almost always the right first module after the Diagnostic — it produces immediate visibility across every device and creates the foundation every other security control depends on."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📱</div>
<div class="feature-item-body">
<h4>Complete Device Inventory</h4>
<p>Every managed device enrolled in Intune: OS version, patch level, encryption status, compliance state. Shadow IT devices flagged. You leave with a real picture of your fleet — not what should be there, but what is.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">✅</div>
<div class="feature-item-body">
<h4>Compliance Baseline</h4>
<p>Encryption enforced, OS minimum versions set, antivirus required, screen lock configured. Devices that fail compliance are flagged in red and blocked from data access via Conditional Access integration.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔀</div>
<div class="feature-item-body">
<h4>ASTRAL Deployment for Intune Drift</h4>
<p>ASTRAL captures your Intune configuration as versioned snapshots in Git. Any policy change opens a pull request with a human-readable diff. Unauthorised changes are detected before they become incidents.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Shadow IT Discovery</h4>
<p>Application inventory across all enrolled devices surfaces sanctioned and unsanctioned software — including consumer AI tools running on corporate devices. Every unsanctioned application is a potential data exfiltration or malware entry path.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔐</div>
<div class="feature-item-body">
<h4>Conditional Access Integration</h4>
<p>Device compliance state wired into Conditional Access so non-compliant devices cannot reach email, SharePoint, or Teams. The device check becomes a real enforcement signal, not just a dashboard metric.</p>
</div>
</div>
</div>
## Why Endpoint Management First
Endpoint management is the entry vector that reveals everything else. Once enrollment runs, the consultant can see orphaned AD accounts (devices with no owner), unencrypted disks (the compliance gap nobody admitted), and consumer AI apps installed on devices that access regulated data. Every one of these becomes a natural conversation about what comes next.
**The Trojan horse:** the client asks to manage their laptops. You deliver that in 30 days. You also hand them a map of what you found — accounts that should not exist, devices that are not encrypted, applications leaking data. The device problem is solved. The picture that follows it is what turns a bounded engagement into a programme.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 30–45 days |
| **Environment** | M365 E3+ (Intune included) |
| **Prerequisites** | Global Administrator access; device enrollment feasibility confirmed |
| **Natural follow-on** | Module 2 (Identity Security) — identity gaps surface during enrollment |
<div class="cta-strip">
<h2>Ready to see your fleet?</h2>
<p>Full device visibility in 30 days. The foundation every other security control depends on.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+67
View File
@@ -0,0 +1,67 @@
---
title: "Module 10 — Red Team & Adversarial Validation"
description: "Adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Validates whether hardening modules produced real security improvement or compliance dashboard improvement."
eyebrow: "Consulting Module"
lead: "The client has MFA. They have Conditional Access. They have Intune. The dashboard is green. This is the most dangerous estate to walk into — not because it is badly configured, but because everyone believes it works. Module 10 finds out which controls are real and which are representations."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Targeted Kill Chain Validation</h4>
<p>Adversary simulation runs specifically against the kill chain identified in the Brownhat Diagnostic and modified by previous hardening modules. Not a broad-scope red team — a focused test of whether the paths we said we closed are actually closed. The attack surface is the attack surface your organisation faces, not a generic penetration test scope.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔐</div>
<div class="feature-item-body">
<h4>Identity and Privilege Assumption Testing</h4>
<p>Kerberoasting, DCSync simulation, PIM bypass attempts, and OAuth consent abuse — the techniques that succeed on hardened estates because the hardening is present but not tested. A control that has never been exercised is a hypothesis. This engagement converts hypotheses to evidence.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧪</div>
<div class="feature-item-body">
<h4>Detection Validation</h4>
<p>Security alerts deliberately triggered to test whether detection rules fire, whether alerts reach a human, and whether that human knows what to do. Many estates generate the right alert into a queue nobody reads. Detection validation distinguishes between "we detect this" and "we detect this and respond to it."</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏗️</div>
<div class="feature-item-body">
<h4>Structural Finding, Not a CVE List</h4>
<p>Every gap found produces a structural recommendation — not "patch this CVE" but "this path exists because of this architectural condition; severing it requires this change." The output is a shorter kill chain, not a longer remediation backlog. We do not add controls. We find why the existing ones do not work.</p>
</div>
</div>
</div>
## When to Run This Module
Module 10 is a **post-hardening engagement**. It is the evidence check after the work — the test that distinguishes security improvement from compliance improvement. Run it after Modules 2, 3, 6, and 12 have had time to bed in. Running it before hardening is simply a penetration test; running it after hardening is adversarial validation.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 15–30 days |
| **Environment** | Any |
| **Prerequisites** | Written authorisation covering all test activities; at least two hardening modules completed; initial kill chain from Module 0 documented |
| **Natural follow-on** | Update kill chain map with validated findings; feed structural gaps back into the module roadmap |
<div class="cta-strip">
<h2>Find out which controls are real</h2>
<p>Green dashboards and untested reality are the most dangerous combination in security. Module 10 converts one to the other.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Module 11 — Blue/Purple Team Foundation"
description: "Detection engineering, alert tuning, SIEM rule development, and threat hunting playbooks. Your existing tools, made to actually work."
eyebrow: "Consulting Module"
lead: "Most organisations own a Ferrari-grade security stack and drive it like a rental car. The tools are not the problem. This module builds the operating rhythm, detection rules, and hunting playbooks that turn security telemetry into security outcomes."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">⚙️</div>
<div class="feature-item-body">
<h4>Capability Audit</h4>
<p>The engagement begins by assessing not the tools, but the team's ability to use them. Defender for Endpoint alert coverage, Sentinel analytic rule quality, Defender for Office 365 review process, identity protection response time — each assessed against what the tool is capable of versus what is actually happening. The gap is almost always process, not technology.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔔</div>
<div class="feature-item-body">
<h4>Alert Tuning and Tiered Triage</h4>
<p>High-fidelity alerts separated from noise. A tiered triage model deployed so analysts know which alerts require immediate response, which require investigation, and which are informational. The "200 alerts per day with no triage process" configuration — which produces analyst burnout and missed detections equally — replaced with something workable.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📐</div>
<div class="feature-item-body">
<h4>Detection Engineering</h4>
<p>Custom detection rules built against the specific attack techniques relevant to your environment — not the vendor's default rules covering all industries, but rules tuned to your crown jewels, your identity topology, and the kill chain your Diagnostic identified. Rules are tested against real activity before deployment to verify they fire without drowning the queue.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Threat Hunting Playbooks</h4>
<p>Structured hunt hypotheses and execution playbooks for the techniques most likely to succeed against your environment. Analysts stop waiting for alerts and start looking for evidence of compromise that has not yet triggered one. The hunt is repeatable and scheduled, not ad-hoc and occasional.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔄</div>
<div class="feature-item-body">
<h4>Continuous Improvement Loop</h4>
<p>Every alert, every hunt, and every incident feeds a tuning cycle. Detection misses produce new rules. False positives are suppressed with scope, not silence. The SIEM improves over time rather than drifting toward irrelevance as the environment changes around it.</p>
</div>
</div>
</div>
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 45–90 days |
| **Environment** | Microsoft Defender stack and/or Sentinel |
| **Prerequisites** | PULSAR deployed for audit log intelligence; initial kill chain from Module 0 to anchor detection scope |
| **Natural follow-on** | Module 10 (Red Team & Validation) to test whether detection catches simulated attacks |
<div class="cta-strip">
<h2>Make your existing tools work</h2>
<p>The tooling you already own can detect the attacks you actually face. Module 11 builds the capability to use it.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+67
View File
@@ -0,0 +1,67 @@
---
title: "Module 12 — T0 Asset Protection"
description: "Tier 0 asset classification across identity, infrastructure, and data. Protection architecture ensuring crown jewels are never reachable from a Tier 1 or Tier 2 compromise."
eyebrow: "Consulting Module"
lead: "A T0 asset is not merely important. It is existential — its compromise does not cause downtime, it causes dissolution. Most organisations have never explicitly classified which assets belong here, which means they have never specifically protected them."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🏆</div>
<div class="feature-item-body">
<h4>T0 Asset Classification</h4>
<p>Every asset classified into tiers: T0 (existential — compromise destroys the operation), T1 (critical — material harm), T2 (important — significant disruption), T3 (standard). Classification is not a spreadsheet exercise — it is a conversation about what the organisation genuinely cannot operate without. Domain controllers, ADCS, the Entra Connect sync server, cryptographic key material, and the systems that hold sovereign intelligence all belong at T0.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🛡️</div>
<div class="feature-item-body">
<h4>Crown Jewel Protection Architecture</h4>
<p>A protection design for each T0 asset: access controls, network segmentation, monitoring requirements, and privilege boundaries. The architecture's primary constraint is that T0 must never be reachable from the compromise of a T1 or T2 system. If an attacker owns a member server, they should not be able to reach a domain controller. If they compromise an admin laptop, they should not reach the ADCS root.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔒</div>
<div class="feature-item-body">
<h4>Privilege Tier Enforcement</h4>
<p>Administrative access enforced per tier — T0 administrators use dedicated, hardened workstations and dedicated accounts that do not log in to T1 or T2 systems. Service accounts that currently span tiers identified and decomposed. Entra Connect sync server permissions tightened so the bridge between on-premises T0 and the cloud tenant cannot be weaponised.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📡</div>
<div class="feature-item-body">
<h4>T0 Monitoring and Alert Design</h4>
<p>Custom detection rules scoped specifically to T0 assets — any authentication attempt, any privilege escalation, any configuration change on a T0 system generates a high-fidelity alert that reaches a human immediately. Noise from T1 and T2 does not bury T0 signals.</p>
</div>
</div>
</div>
## The Kill Chain Connection
The Kill Chain Assessment app from Module 0 identifies which assets are crown jewels — the end of the kill chain. Module 12 builds the architecture that ensures an attacker cannot reach them even after compromising entry-level systems. Together, Module 0 finds the path and Module 12 removes it at the structural level.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 30–60 days |
| **Environment** | Any |
| **Prerequisites** | Module 0 (Diagnostic) to identify crown jewels; Module 6 if on-premises AD is in scope |
| **Natural follow-on** | Module 13 (Privileged Access Architecture) for the PAM layer that enforces the tier boundaries in practice |
<div class="cta-strip">
<h2>Protect what the organisation cannot lose</h2>
<p>Everything else can be rebuilt. T0 assets cannot. Module 12 ensures the architecture reflects that distinction.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+70
View File
@@ -0,0 +1,70 @@
---
title: "Module 13 — Privileged Access Architecture"
description: "PAM design using Teleport, Tailscale/Headscale, and JIT access. Vendor remote access governance, ephemeral credentials, session recording, and zero standing access."
eyebrow: "Consulting Module"
lead: "Your VPN authenticates people to your network. PAM authenticates people to specific resources inside it. Most organisations solve the first problem badly and ignore the second entirely. The result: a compromised VPN credential reaches everything. This module closes that gap with a two-layer architecture."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🌐</div>
<div class="feature-item-body">
<h4>Network Access Layer — Tailscale or Headscale</h4>
<p>Tailscale (or Headscale for sovereign deployments) replaces legacy VPN for T1 workloads — cloud resources, Kubernetes clusters, multi-cloud management planes. Per-node ACLs, Entra OIDC integration, and per-session MFA via key expiry. An attacker with a stolen credential reaches only the specific resources that credential is scoped to, not the entire network.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔐</div>
<div class="feature-item-body">
<h4>Privileged Access Layer — Teleport</h4>
<p>Teleport deployed as the protocol-aware access layer for SSH, RDP, Kubernetes, and database access. Every privileged session is proxied, recorded, and auditable. Ephemeral certificates replace long-lived credentials — there are no SSH keys to steal, no saved RDP passwords, no standing database credentials. Access is approved, time-bounded, and logged by default.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⏱️</div>
<div class="feature-item-body">
<h4>JIT Access and Zero Standing Privilege</h4>
<p>Just-in-time access workflows so privileged access to critical systems requires an approval request, grants time-bounded access, and expires automatically. No standing admin sessions, no persistent elevated accounts with broad reach. The attacker who compromises an admin account at 3am finds it has no current access to anything significant.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏢</div>
<div class="feature-item-body">
<h4>Vendor Remote Access Governance</h4>
<p>Third-party vendors — managed service providers, hardware suppliers, software vendors with remote support access — brought under the same PAM architecture. Every vendor session scoped to the specific resources they need, recorded, and revokable instantly. Vendor access is a significant and frequently overlooked attack surface.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏔️</div>
<div class="feature-item-body">
<h4>T0 Overlay — Nebula (Optional)</h4>
<p>For T0 systems (domain controllers, ADCS, Entra Connect sync server), an optional Nebula overlay provides a management network with no external coordinator dependency — once certificates are distributed, the overlay functions with zero cloud service availability dependency. The Nebula CA is the only T0 component and can be kept offline.</p>
</div>
</div>
</div>
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 45–60 days |
| **Environment** | Any (cloud, on-premises, hybrid, multi-cloud) |
| **Prerequisites** | Module 12 (T0 Asset Protection) to establish the tier boundaries the PAM architecture enforces; inventory of privileged access requirements |
| **Natural follow-on** | Module 11 (Blue/Purple Team) to build detection for privileged access anomalies |
<div class="cta-strip">
<h2>No standing access. No standing risk.</h2>
<p>Every privileged session scoped, recorded, and time-bounded. An attacker who steals a credential finds it grants nothing by default.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+67
View File
@@ -0,0 +1,67 @@
---
title: "Module 14 — Sovereign Communications"
description: "Delta Chat chatmail relay, Matrix/Element deployment, and crisis out-of-band channel design. Communication infrastructure that stays available and private when your primary platform is compromised."
eyebrow: "Consulting Module"
lead: "Your incident response plan assumes your communication platform is available. Your incident response plan is wrong. When ransomware takes down corporate IT, Teams goes down too. When Active Directory is compromised, the attacker can monitor your response in real time. This module builds the alternative."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">💬</div>
<div class="feature-item-body">
<h4>Delta Chat — Crisis Out-of-Band Channel</h4>
<p>Delta Chat deployed on independent chatmail relay infrastructure in under 10 minutes per user. Encrypted, works on mobile, requires no corporate account or corporate network to operate. When the corporate identity provider is down or compromised, your incident response team still has a secure, verified channel. Used as the crisis fallback that is always independent from whatever is failing.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏠</div>
<div class="feature-item-body">
<h4>Matrix/Element — Sovereign Primary Platform (Optional)</h4>
<p>For organisations that want to own their primary communications entirely: a self-hosted Matrix homeserver with Element client. No vendor dependency, no Microsoft or Google account required for access, fully federated if needed. Your communication infrastructure becomes sovereign in the same way your authentication infrastructure should be.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📋</div>
<div class="feature-item-body">
<h4>Crisis Communication Runbook</h4>
<p>A documented, tested out-of-band communication protocol — who contacts whom, on which channel, in which sequence, for which incident types. The runbook exists on paper and on every responder's personal device, independent of corporate infrastructure. Tested in the tabletop exercise so the first time it is used under pressure is not the first time it is used at all.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔑</div>
<div class="feature-item-body">
<h4>Key Verification and Trust Establishment</h4>
<p>Encryption keys verified out-of-band before the incident, so responders know they are talking to each other and not to an attacker who has compromised the corporate directory. Trust established in advance is the only trust that holds under incident pressure.</p>
</div>
</div>
</div>
## Why Communications Infrastructure Is a Security Control
An incident response that depends on the infrastructure the incident might destroy is not a response capability — it is a hope. For OT environments and critical infrastructure, the dependency is even more direct: control room operators cannot rely on a communication tool that depends on corporate IT when the incident is in the corporate IT.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 15–30 days |
| **Environment** | Any |
| **Prerequisites** | None — this module can be delivered standalone as crisis preparedness |
| **Natural follow-on** | Module 7 (Recovery & Resilience) — sovereign communications integrates with the full incident response capability |
<div class="cta-strip">
<h2>Keep talking when everything else is down</h2>
<p>The crisis communication channel must be independent from the infrastructure that might fail during the crisis. Module 14 builds it.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+81
View File
@@ -0,0 +1,81 @@
---
title: "Module 2 — M365 Identity Security"
description: "Full identity census, Conditional Access architecture, MFA enforcement, legacy auth elimination, PIM deployment, and PULSAR audit log intelligence for your M365 tenant."
eyebrow: "Consulting Module"
lead: "Identity is the perimeter. Every other control you deploy is downstream of whether the right people — and only the right people — can authenticate. This module makes your identity architecture explicit, enforced, and auditable."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">👥</div>
<div class="feature-item-body">
<h4>Full Identity Census</h4>
<p>Every user account, admin account, service principal, app registration, and guest identity enumerated and assessed. Orphaned accounts, over-privileged roles, and never-used service principals flagged and queued for remediation.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏗️</div>
<div class="feature-item-body">
<h4>Conditional Access Architecture</h4>
<p>A complete, documented CA policy set covering MFA enforcement, legacy auth blocking, device compliance signals, named locations, and phishing-resistant authentication for admins. Staged deployment with report-only period before enforcement to prevent lockout.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔒</div>
<div class="feature-item-body">
<h4>MFA Enforcement and Legacy Auth Elimination</h4>
<p>MFA enforced via Conditional Access (not per-user MFA). Legacy authentication protocols — IMAP, POP, SMTP AUTH, basic auth — blocked at the tenant level. These protocols bypass MFA entirely and are the entry point for the majority of credential-based attacks.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⏱️</div>
<div class="feature-item-body">
<h4>PIM Deployment or JIT Process</h4>
<p>Privileged Identity Management deployed so admin roles are activated on-demand with approval workflow and time-bounded access, rather than permanently assigned. Zero standing Global Admin access where feasible. Break-glass accounts established and documented.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📡</div>
<div class="feature-item-body">
<h4>PULSAR Audit Log Intelligence</h4>
<p>PULSAR deployed for continuous M365 audit log ingestion with indefinite retention. Search UI, alerting on high-risk events, and MCP server for AI-assisted queries. You gain the ability to answer "what happened, when, and by whom" — retrospectively and in real time.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧹</div>
<div class="feature-item-body">
<h4>Guest Access Audit and Governance</h4>
<p>All guest identities enumerated. Stale guests (inactive, unknown owner, no project association) flagged and removed. External collaboration settings tightened. Guest access policy documented and a review cadence established.</p>
</div>
</div>
</div>
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 30–60 days |
| **Environment** | M365 E3+ |
| **Prerequisites** | Global Administrator access; existing CA policies inventoried |
| **Natural follow-on** | Module 3 (M365 Security Hardening) builds on the identity baseline |
## Standards Alignment
Conditional Access and audit log retention map directly onto NIS2 Article 21 (access control, monitoring), DORA Article 9 (ICT security — identity and access management), GDPR Article 32 (appropriate technical measures), and ISO 27001 A.5.15–A.5.18 (access control).
<div class="cta-strip">
<h2>Close the identity gaps</h2>
<p>The most common kill chain starts with a compromised credential. Module 2 ensures that credential alone is not enough.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+74
View File
@@ -0,0 +1,74 @@
---
title: "Module 3 — M365 Security Hardening"
description: "Exchange Online Protection tuning, mailbox auditing, Unified Audit Log forwarding, Secure Score baseline, ASR rules, and ASTRAL configuration capture — no new licensing required for E3 clients."
eyebrow: "Consulting Module"
lead: "Most M365 E3 tenants are running at a fraction of the security their licence already includes. This module extracts that value systematically — tightening the controls that exist, enabling the logging that should be on, and capturing the baseline so drift is detectable from day one."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📧</div>
<div class="feature-item-body">
<h4>Exchange Online Protection Tuning</h4>
<p>Anti-phishing, anti-malware, and anti-spam policies reviewed and tightened. DKIM, DMARC, and SPF validated. External sender tagging enabled. Auto-forwarding to external addresses blocked — one of the most reliable business email compromise persistence mechanisms.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📒</div>
<div class="feature-item-body">
<h4>Mailbox Auditing and UAL Forwarding</h4>
<p>Mailbox auditing enabled tenant-wide for all user and admin actions. Unified Audit Log configured for forwarding to SIEM or PULSAR. Every mailbox access, calendar sharing change, and permission modification becomes a searchable, retained event.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📊</div>
<div class="feature-item-body">
<h4>Secure Score Baseline and Improvement Plan</h4>
<p>Current Secure Score documented with every open recommendation classified: accept, remediate, or mitigate. A realistic 90-day improvement plan targets the highest-impact items within the existing E3 licence — no new spend required to close most gaps.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🛡️</div>
<div class="feature-item-body">
<h4>Attack Surface Reduction Rules</h4>
<p>ASR rules deployed via Intune in audit mode first, then staged to enforcement. Rules targeting Office macro abuse, credential theft from LSASS, and suspicious process creation — covering the most common malware execution paths without blocking legitimate business workflows.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📸</div>
<div class="feature-item-body">
<h4>ASTRAL Baseline Capture</h4>
<p>ASTRAL deployed to take a Git-tracked snapshot of the post-hardening configuration. Every subsequent change opens a pull request with a diff and an AI-generated narrative. The hardened state becomes the recoverable baseline — if anything drifts, you know immediately and can restore deterministically.</p>
</div>
</div>
</div>
## No New Licensing Required
The full scope of this module is deliverable on Microsoft 365 E3. We do not recommend upgrading to E5 as a condition of delivery. If E5 features would materially improve a specific control, we say so and explain the trade-off — but we do not use the engagement as a licence upsell.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 30–60 days |
| **Environment** | M365 E3+ |
| **Prerequisites** | Global Administrator access; Module 2 (Identity Security) completed or in parallel |
| **Natural follow-on** | Module 4 (Data Governance) for sensitivity labels and DLP |
<div class="cta-strip">
<h2>Extract the security your licence already includes</h2>
<p>Most E3 tenants leave the majority of their security value unconfigured. This module closes that gap systematically.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+74
View File
@@ -0,0 +1,74 @@
---
title: "Module 4 — Data Governance & Compliance"
description: "Sensitivity label deployment, retention policies, DLP, eDiscovery readiness, Teams governance, and SharePoint external sharing controls. Regulatory evidence produced as a natural output."
eyebrow: "Consulting Module"
lead: "Data does not stay where you put it. It is copied, forwarded, synced, and shared — and in most tenants, nobody can enumerate where it went or pull it back. This module makes data flows visible, governable, and auditable."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🏷️</div>
<div class="feature-item-body">
<h4>Sensitivity Label Deployment</h4>
<p>A practical label taxonomy deployed across M365 — not the six-tier compliance architecture that nobody uses, but a scheme your organisation will actually apply. Labels flow through email, Teams, SharePoint, and Office applications. Classification becomes a signal every downstream control can act on.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📅</div>
<div class="feature-item-body">
<h4>Retention Policies for All M365 Workloads</h4>
<p>Retention configured for Exchange, SharePoint, OneDrive, Teams messages, and Teams meeting recordings. Regulatory minimums met. Over-retained data that creates unnecessary eDiscovery scope identified and scheduled for deletion. Retention gaps that expose you to "we don't have it" responses closed.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🚫</div>
<div class="feature-item-body">
<h4>DLP Policies</h4>
<p>Data Loss Prevention policies targeting your actual regulated data — payment card numbers, national IDs, health data, or proprietary classifications — with alert-before-block staged deployment. Auto-forward to external addresses blocked. "Anyone with the link" sharing scoped or removed.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚖️</div>
<div class="feature-item-body">
<h4>eDiscovery Readiness</h4>
<p>Content search scope validated, custodian identification process documented, legal hold workflow tested. If you receive a regulatory request or litigation hold tomorrow, you can respond without improvising under pressure.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">👥</div>
<div class="feature-item-body">
<h4>Teams Governance and Guest Access Controls</h4>
<p>Teams lifecycle policy deployed so abandoned Teams do not accumulate as forgotten data stores. Guest access permissions tightened. External sharing settings reconciled across tenant, site, and Teams channel levels — the three layers that routinely disagree and produce unexpected exposure.</p>
</div>
</div>
</div>
## Standards Alignment
This module produces direct compliance evidence for NIS2 Article 21 (data security, access control), DORA Article 9 (ICT security policies — data classification and handling), GDPR Articles 5 and 25 (data minimisation, privacy by design), and ISO 27001 A.5.12–A.5.13 (classification, labelling). External auditors receive the retention logs, sensitivity label reports, and DLP policy documentation as artefacts — not manual screenshots.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 45–90 days |
| **Environment** | M365 E3+ |
| **Prerequisites** | Module 2 (Identity) completed — guest access and external sharing controls depend on a clean identity baseline |
| **Natural follow-on** | Module 7 (Recovery) to ensure retained data is backed up independently of Microsoft's native retention |
<div class="cta-strip">
<h2>Make your data flows visible</h2>
<p>Every share is a copy of your blast radius handed to a party you do not fully control. Module 4 makes that visible and governable.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+74
View File
@@ -0,0 +1,74 @@
---
title: "Module 5 — AI Sovereignty Bridge"
description: "Shadow AI inventory, Azure OpenAI deployment with private endpoints, Conditional Access for AI tools, first RAG pipeline on proprietary data, and AI governance policy."
eyebrow: "Consulting Module"
lead: "Most organisations already have employees using cloud AI. The question is not whether it happens — it is whether the data flowing through those tools is yours to audit, yours to withdraw, and yours to keep sovereign. This module closes that gap."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Shadow AI Inventory</h4>
<p>Endpoint and proxy data used to enumerate AI tools actually in use — not what the acceptable-use policy permits, but what employees are running. Consumer AI assistants, code completion tools, browser extensions, and embedded SaaS AI features all leave traces. You cannot govern a tool you do not know exists.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔒</div>
<div class="feature-item-body">
<h4>Azure OpenAI on Private Endpoints</h4>
<p>Azure OpenAI deployed within your tenant boundary with private endpoint networking — inference traffic stays inside your Azure virtual network, never traverses the public internet. Your data residency requirements are met structurally, not by contractual assurance alone.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🚦</div>
<div class="feature-item-body">
<h4>Conditional Access for AI Tools</h4>
<p>CA policies that restrict sanctioned AI tool access to compliant, managed devices and approved users. Consumer AI tool access from corporate devices blocked or scoped via proxy policy. The boundary between sanctioned and unsanctioned AI becomes enforceable.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧠</div>
<div class="feature-item-body">
<h4>First RAG Pipeline or Fine-Tuned Model</h4>
<p>A working retrieval-augmented generation pipeline — or a fine-tuned model — built on your proprietary data. A general cloud model improves at everyone's tasks. A model trained on your data improves at your tasks alone. That gap compounds and is not recoverable by a vendor.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📜</div>
<div class="feature-item-body">
<h4>AI Governance Policy</h4>
<p>A documented, practical AI governance policy covering sanctioned tools, acceptable data classifications for AI input, human-review requirements for AI-assisted decisions, and a vendor assessment process for new AI procurement. Designed to be enforced, not filed.</p>
</div>
</div>
</div>
## The Economic Case
At meaningful usage scale, cloud AI inference is priced to grow with usage. Fixed-cost sovereign infrastructure — local models, private Azure endpoints, or auditable sovereign cloud — produces predictable economics. Organisations spending €5,000–€15,000 monthly on cloud AI APIs typically reach break-even within 12–18 months. Module 5 creates the infrastructure that makes that transition feasible.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 30–60 days |
| **Environment** | Azure subscription; M365 E3+ for CA integration |
| **Prerequisites** | Module 2 (Identity) for CA enforcement; Module 1 (Endpoint Management) for shadow AI discovery from device telemetry |
| **Natural follow-on** | AURORA for cross-tool AI operations once PULSAR and ASTRAL are deployed |
<div class="cta-strip">
<h2>Your intelligence should stay yours</h2>
<p>Proprietary data run through a cloud model trains that model — not yours. Module 5 builds the alternative.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+74
View File
@@ -0,0 +1,74 @@
---
title: "Module 6 — On-Premises AD & Endpoint Hardening"
description: "Full AD identity census, password audit of compromised credentials, KRBTGT rotation, LAPS, Sysmon, PAW architecture, and Entra Connect hardening for hybrid environments."
eyebrow: "Consulting Module"
lead: "The cloud gets the headlines. Active Directory gets compromised. Most AD forests carry a decade of accumulated privilege, service accounts with passwords that predate the organisation's current security team, and group policies nobody dares to touch. This module fixes the kill chain in the on-premises layer."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🗂️</div>
<div class="feature-item-body">
<h4>Full AD Identity Census</h4>
<p>Every user, computer, service account, and admin group enumerated and assessed. Stale accounts (no logon in 90+ days), orphaned objects (owner departed), and service accounts with non-expiring passwords flagged. The privilege map you didn't know you had.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔑</div>
<div class="feature-item-body">
<h4>Compromised Credential Audit</h4>
<p>AD password hashes compared against known-breached credential databases (Elysium / Have I Been Pwned corpus). Accounts using passwords that appear in breach databases identified and forced to reset — before an attacker uses them. This consistently surfaces accounts that have been silently compromised for months.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔄</div>
<div class="feature-item-body">
<h4>KRBTGT Rotation and Golden Ticket Invalidation</h4>
<p>KRBTGT account rotated twice in sequence (required to invalidate any existing Kerberos tickets, including forged golden tickets). Procedure documented for future rotations. A non-rotated KRBTGT is a persistent attacker foothold that survives every other remediation you run.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">💻</div>
<div class="feature-item-body">
<h4>LAPS and Privileged Access Workstations</h4>
<p>Local Administrator Password Solution deployed so every machine has a unique, rotating local admin password — eliminating the lateral movement path of a shared local admin credential. PAW architecture designed for admin tasks to prevent credential theft from the workstations used to manage Tier 0 systems.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📡</div>
<div class="feature-item-body">
<h4>Sysmon Deployment and Entra Connect Hardening</h4>
<p>Sysmon deployed to endpoints for detailed process creation, network connection, and registry change logging — the telemetry source that turns a security incident from "we don't know what happened" to "we have the full timeline." Entra Connect sync account permissions tightened and sync server isolated: the bridge between on-premises and cloud is a Tier 0 asset and must be protected as one.</p>
</div>
</div>
</div>
## The Hybrid Identity Risk
In a hybrid environment, the on-premises AD and the cloud tenant are linked. Compromise of the Entra Connect sync account — a common, often overlooked target — gives an attacker the ability to manipulate cloud identities from on-premises. The on-premises security posture is a cloud security question. This module treats it as one.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 45–60 days |
| **Environment** | On-premises AD with or without hybrid M365 |
| **Prerequisites** | Domain Admin access; Module 2 (Identity) for cloud-side alignment if hybrid |
| **Natural follow-on** | Module 12 (T0 Asset Protection) for crown-jewel isolation; Module 13 (Privileged Access Architecture) for PAM |
<div class="cta-strip">
<h2>The cloud is only as secure as the AD behind it</h2>
<p>Most kill chains pass through on-premises AD even when the target is cloud resources. Module 6 closes the path.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+74
View File
@@ -0,0 +1,74 @@
---
title: "Module 7 — Recovery & Resilience"
description: "Backup architecture review, immutable backup deployment, disaster recovery runbooks, tabletop exercise, and ASTRAL baseline as rebuild blueprint. Tested recovery, not assumed."
eyebrow: "Consulting Module"
lead: "The most common recovery lie in the industry: 'we have backups.' Having a backup is not the same as being able to recover. This module replaces the assumption with a tested, documented, and rehearsed capability — so when the incident happens, recovery is a procedure, not an improvisation."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Backup Architecture Review</h4>
<p>Current backup coverage assessed for every workload: M365 data, on-premises systems, cloud VMs, and critical databases. The gaps that consistently appear — M365 data that employees believe Microsoft backs up but that has no independent point-in-time backup, backup systems reachable from the same network as production, backup credentials stored in the same password manager as everything else — are found and documented before an attacker finds them first.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧱</div>
<div class="feature-item-body">
<h4>Immutable Backup Deployment</h4>
<p>Immutable, off-network backup deployed for critical workloads. Ransomware operators delete or encrypt backups before they hit production — a backup reachable from the compromised estate is not a backup. Immutability ensures the backup cannot be modified or deleted even by a fully compromised admin account.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📖</div>
<div class="feature-item-body">
<h4>Disaster Recovery Runbooks</h4>
<p>Step-by-step recovery procedures written for every critical workload — including the scenarios nobody documents: AD forest recovery, M365 tenant configuration restore, and cloud infrastructure rebuild from ASTRAL baseline. Each runbook is tested, not just written. A runbook that has never been executed is a hypothesis.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Tabletop Exercise</h4>
<p>A structured scenario walkthrough — typically a ransomware incident or identity compromise — run with the actual response team. Gaps in communication, decision authority, and technical procedure surface in a tabletop, not in a live incident. Every gap found in the exercise is a gap not found under pressure.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔀</div>
<div class="feature-item-body">
<h4>ASTRAL Baseline as Rebuild Blueprint</h4>
<p>The ASTRAL Git repository — capturing your M365 and Intune configuration — becomes your authoritative rebuild baseline. After a catastrophic configuration failure or tenant compromise, "what do we restore to?" has a deterministic answer. The restore pipeline applies the known-good state without manual reconstruction from memory.</p>
</div>
</div>
</div>
## The Antifragile Recovery Principle
A robust organisation survives an incident and comes back the same. An antifragile one comes back different — with a shorter kill chain, a tested runbook it now knows works, and one more scenario it has rehearsed. Every incident that runs through this module's feedback loop makes the next one cheaper. The tabletop is not a compliance checkbox; it is the cheapest incident you will ever have.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 30–60 days |
| **Environment** | M365 and/or on-premises |
| **Prerequisites** | ASTRAL deployed (Module 1 or 3) for the configuration baseline; inventory of critical workloads |
| **Natural follow-on** | Module 11 (Blue/Purple Team) to build the detection capability that feeds the recovery loop |
<div class="cta-strip">
<h2>Know you can recover before you need to</h2>
<p>An untested backup is simultaneously fine and worthless. Module 7 tells you which one yours is — before the incident does.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+80
View File
@@ -0,0 +1,80 @@
---
title: "Module 8 — Threat & Vulnerability Management"
description: "Quantum vulnerability management for the exploitation-first era. Kill-chain-based prioritisation, the ~90% subtraction, four time-budgeted quanta, and the Kill Chain Assessment app."
eyebrow: "Consulting Module"
lead: "Time-to-exploit has collapsed to roughly four hours. Median remediation sits at 43 days. No amount of 'patch faster' closes a gap that runs the wrong way by two orders of magnitude. The answer is not to patch faster — it is to stop using the vulnerability list as the unit of work."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## The Problem with the Old Model
CVSS scores severity in the abstract. It knows nothing about whether the vulnerable asset is internet-reachable, whether it sits on the kill chain, whether an exploit exists in the wild, or whether a compensating control already neutralises it. Sorting 40,000 findings by CVSS produces a list precisely uncorrelated with where an attacker will actually go.
The 2026 Verizon DBIR confirms vulnerability exploitation is now the leading initial-access vector — roughly twice phishing. This is not a maturity problem solved with more analysts. It is a model that has run out of road.
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🗺️</div>
<div class="feature-item-body">
<h4>Kill Chain Assessment</h4>
<p>The Kill Chain Assessment app maps your environment as an attack graph and runs a shortest-path computation across every entry point to every crown jewel. The result is the kill chain — the cheapest route from attacker foothold to existential impact. Every finding is classified P0 (on the shortest chain), P1 (on some path), or P2 (off-chain entirely).</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">✂️</div>
<div class="feature-item-body">
<h4>The ~90% Subtraction</h4>
<p>Roughly 90% of "critical" vulnerabilities are not exploitable in a given environment once compensating controls, reachability, and segmentation are mapped. This subtraction — removing false urgency before adding any work — turns "40,000 criticals" into the few hundred that are real and the few dozen that are on fire. It is the highest-leverage move in the programme and it is pure deletion.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚡</div>
<div class="feature-item-body">
<h4>Four Time-Budgeted Quanta</h4>
<p><strong>Critical (hours):</strong> On the kill chain, reachable, exploit available now. Response is a compensating control — sever reachability, block at the edge, isolate — not the patch. You cannot meet a four-hour window with a vendor patch cycle.<br><strong>Severe (days):</strong> Material risk; reachable with friction. One change window, verify enforcement.<br><strong>Standard (sprint):</strong> The real, non-urgent tail. Drain in sprint-sized batches on the normal change calendar.<br><strong>Dark (unsized):</strong> Reachability or exploitability unknown. Route to discovery — characterise before remediating.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Zero-Budget Vulnerability Discovery</h4>
<p>osquery deployed as a sovereign discovery platform alongside scripted checks for the findings scanners miss — service account privileges, unpatched firmware, container base image CVEs, exposed management interfaces. Discovery before scanner procurement is almost always sufficient to find the kill chain.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📉</div>
<div class="feature-item-body">
<h4>Kill Chain Length as the Metric</h4>
<p>The programme does not measure MTTR. It measures whether the kill chain got shorter. Ten incidents that produce ten patches leave the estate equally fragile. Ten incidents that each sever one structural path leave an estate that is genuinely harder to compromise every time it is tested. That is the only honest definition of improvement.</p>
</div>
</div>
</div>
## The Barbell
The antifragile TVM programme has two ends and a middle to avoid. **Fast end:** hours-lane compensating controls — edge blocks, isolation, reachability cuts — that win the time race a patch cannot. **Structural end:** segmentation, least privilege, and T0 protection that make most vulnerabilities irrelevant before they are disclosed. **The fragile middle to avoid:** the aging critical-patch backlog that carries hours-lane urgency while moving at sprint-lane speed. Maximum anxiety, minimum protection.
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 45–90 days |
| **Environment** | Any (cloud, on-premises, hybrid) |
| **Prerequisites** | Module 0 (Diagnostic) to establish the initial kill chain; asset inventory from Modules 1 or 6 |
| **Natural follow-on** | Module 10 (Red Team & Validation) to validate that severed paths stay severed |
<div class="cta-strip">
<h2>Stop racing an attacker you cannot outrun</h2>
<p>The winning move is not to patch the long tail faster. It is to make most of it not matter — and contain the few that do in hours, not weeks.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+63
View File
@@ -0,0 +1,63 @@
---
title: "Module 9 — Organisational Resilience"
description: "Dev/Sec/Ops merger, shift-left security integration, process assurance for teams feeling out of control, and embedded security review in the delivery pipeline."
eyebrow: "Consulting Module"
lead: "You do not have a tools problem. You have a handoff problem. Every boundary between development, security, and operations is a boundary where accountability disappears and fragility accumulates. This module removes those boundaries structurally."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
- label: "View All Modules"
url: "/consulting/skills/"
---
## What It Delivers
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔗</div>
<div class="feature-item-body">
<h4>Dev/Sec/Ops Merger</h4>
<p>The structural design work to merge development, security, and operations into shared ownership. Shared accountability means one team owns a system from commit to retirement — which means they design it not to fail, because failure is their problem. The alternative is a system designed to pass demo day.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⬅️</div>
<div class="feature-item-body">
<h4>Shift-Left Security Integration</h4>
<p>Security checks embedded in the development pipeline — SAST, dependency scanning, container image scanning, IaC linting — so findings surface at commit time, when they cost a developer ten minutes to fix, rather than in production, where they cost the organisation weeks and significant reputational damage. Security findings fixed in development cost roughly 1% of what they cost in production.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🧭</div>
<div class="feature-item-body">
<h4>Process Assurance for Teams Feeling Out of Control</h4>
<p>Structured for teams who have the tools and the people but feel like security is not working — alerts nobody acts on, findings nobody owns, incidents that keep recurring. The engagement maps the handoff failures, assigns ownership, and establishes the operating rhythm that converts activity into outcomes.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔄</div>
<div class="feature-item-body">
<h4>Embedded Security Review in the Delivery Pipeline</h4>
<p>Security architecture review embedded as a gate in the project lifecycle — not a checkbox at the end of delivery, but a structured checkpoint at design phase when changes are still cheap. Threat models produced as natural artefacts of the delivery process, not as separate compliance documents written by someone who did not build the system.</p>
</div>
</div>
</div>
## Scope and Prerequisites
| | |
|---|---|
| **Duration** | 60–90 days |
| **Environment** | Any organisation with a development or change delivery function |
| **Prerequisites** | Executive sponsor with authority to change team structures; willingness to examine the organisational design honestly |
| **Natural follow-on** | Module 11 (Blue/Purple Team) — once the delivery pipeline is secure, build the detection capability that catches what gets through |
<div class="cta-strip">
<h2>Security is an organisational design problem</h2>
<p>No tool fixes a handoff. Module 9 addresses the structure that tools cannot reach.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/skills/" class="btn btn-outline">View All Modules</a>
</div>
</div>
+171
View File
@@ -0,0 +1,171 @@
---
title: "Consulting Modules"
description: "14 independent, self-contained security modules. Start where the pain is highest — each module delivers measurable value and creates natural appetite for the next."
eyebrow: "Modular Engagements"
lead: "Every module stands alone. Every module makes the next one easier. Start where the pain is highest — not where the framework says you should."
---
Every engagement begins with the **Brownhat Diagnostic** (Module 0): a structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised module roadmap. The diagnostic is a paid, bounded engagement and delivers value regardless of whether further work follows.
<div class="modules-grid">
<div class="module-card">
<div class="module-num">Module 0</div>
<h3><a href="/consulting/module-0/">Brownhat Diagnostic</a></h3>
<p>Structured two-day NIST CSF 2.0 baseline assessment. Honest picture of your security posture, prioritised gap list, and recommended module sequence. Kill chain synthesis using the Kill Chain Assessment app — maps the unknown estate into an attack graph, computes the shortest path to existential impact, and sizes every finding into a remediation quantum. Entry point for every new client.</p>
<div class="module-meta">
<span class="badge badge-blue">2 days</span>
<span class="badge badge-blue">All clients</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 1</div>
<h3><a href="/consulting/module-1/">Endpoint Management Foundation</a></h3>
<p>Device inventory and enrollment, compliance baseline, shadow IT discovery, basic conditional access integration, ASTRAL deployment for Intune drift detection. Full device visibility in 30–45 days.</p>
<div class="module-meta">
<span class="badge badge-blue">30–45 days</span>
<span class="badge badge-green">M365 E3+</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 2</div>
<h3><a href="/consulting/module-2/">M365 Identity Security</a></h3>
<p>Full identity census, Conditional Access policy register, MFA enforcement, legacy auth blocked, PIM deployment or JIT process, PULSAR for audit log intelligence, guest access audit and governance.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-green">M365 E3+</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 3</div>
<h3><a href="/consulting/module-3/">M365 Security Hardening</a></h3>
<p>Exchange Online Protection tuning, mailbox auditing, Unified Audit Log forwarding, Secure Score baseline and improvement plan, ASR rules, ASTRAL baseline capture. No new licensing required for E3 clients.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-green">No new spend</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 4</div>
<h3><a href="/consulting/module-4/">Data Governance &amp; Compliance</a></h3>
<p>Sensitivity label deployment, retention policies for all M365 workloads, DLP policies, eDiscovery readiness, Teams governance, SharePoint site provisioning. Regulatory evidence produced as a natural output.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 days</span>
<span class="badge badge-orange">NIS2 · DORA · GDPR</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 5</div>
<h3><a href="/consulting/module-5/">AI Sovereignty Bridge</a></h3>
<p>Shadow AI inventory, Azure OpenAI deployment with private endpoints, conditional access for AI tools, first RAG pipeline or fine-tuned model on proprietary data, AI governance policy. Your intelligence stays yours.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-blue">Azure</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 6</div>
<h3><a href="/consulting/module-6/">On-Premise AD &amp; Endpoint Hardening</a></h3>
<p>Full AD identity census with orphan and privilege analysis, password audit of compromised credentials (Elysium), KRBTGT rotation, LAPS, Sysmon, PAW architecture, Azure AD Connect hardening.</p>
<div class="module-meta">
<span class="badge badge-blue">45–60 days</span>
<span class="badge badge-blue">Hybrid identity</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 7</div>
<h3><a href="/consulting/module-7/">Recovery &amp; Resilience</a></h3>
<p>Backup architecture review and remediation, immutable backup deployment, disaster recovery runbooks, tabletop exercise, ASTRAL baseline as rebuild blueprint. Tested recovery, not assumed.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-orange">Ransomware-resilient</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 8</div>
<h3><a href="/consulting/module-8/">Threat &amp; Vulnerability Management</a></h3>
<p>Quantum vulnerability management for the exploitation-first era. Kill-chain position, reachability, and exploit availability replace CVSS as the sort key. The ~90% subtraction removes false urgency — leaving the 10% genuinely exploitable in your environment. Four time-budgeted quanta: Critical (hours — compensating control, not the patch), Severe (days), Standard (sprint), Dark (unsized — routed to discovery). Zero-budget discovery with osquery and scripts. The Kill Chain Assessment app maps the attack graph and sizes every node automatically.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 days</span>
<span class="badge badge-green">Open-source first</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 9</div>
<h3><a href="/consulting/module-9/">Organisational Resilience</a></h3>
<p>Dev/Sec/Ops merger, shift-left security integration, process assurance for teams feeling "not in control", quality management engagement, embedded security review in the delivery pipeline.</p>
<div class="module-meta">
<span class="badge badge-blue">60–90 days</span>
<span class="badge badge-blue">Culture + process</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 10</div>
<h3><a href="/consulting/module-10/">Red Team &amp; Validation</a></h3>
<p>Assumption validation after hardening modules. Targeted adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Measures real security improvement, not compliance scores.</p>
<div class="module-meta">
<span class="badge badge-blue">15–30 days</span>
<span class="badge badge-orange">Post-hardening</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 11</div>
<h3><a href="/consulting/module-11/">Blue/Purple Team Foundation</a></h3>
<p>Building defensive capability from existing tool investments. Detection engineering, alert tuning, SIEM rule development, threat hunting playbooks. Your existing tools, made to actually work.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 days</span>
<span class="badge badge-blue">Existing tools</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 12</div>
<h3><a href="/consulting/module-12/">T0 Asset Protection</a></h3>
<p>Tier 0 asset classification across identity, infrastructure, and data. Protection architecture for crown-jewel assets. Privileged access design ensuring Tier 0 is never reachable from Tier 1 or 2 compromise.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-orange">Architecture</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 13</div>
<h3><a href="/consulting/module-13/">Privileged Access Architecture</a></h3>
<p>PAM design using Teleport, Tailscale/Headscale, and JIT access. Vendor remote access governance. Ephemeral credentials, session recording, and access reviews. Zero standing access where possible.</p>
<div class="module-meta">
<span class="badge badge-blue">45–60 days</span>
<span class="badge badge-blue">Open-source PAM</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 14</div>
<h3><a href="/consulting/module-14/">Sovereign Communications</a></h3>
<p>Delta Chat chatmail relay, Matrix/Element deployment, crisis out-of-band channel design. Communication infrastructure that remains available and private even if your primary collaboration platform is compromised.</p>
<div class="module-meta">
<span class="badge badge-blue">15–30 days</span>
<span class="badge badge-green">Self-hosted</span>
</div>
</div>
</div>
<div class="cta-strip">
<h2>Not sure where to start?</h2>
<p>The Brownhat Diagnostic maps your current posture to a prioritised module sequence. It is a bounded, fixed-price engagement and delivers value regardless of whether further work follows.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Book a Diagnostic</a>
<a href="/consulting/" class="btn btn-outline">About Our Approach</a>
</div>
</div>
+115
View File
@@ -0,0 +1,115 @@
---
title: "Housekeeping as a Service"
description: "A dedicated rented team that drains the attack surface your own teams will never find time to clean. Two modes: slow/cheap/safe Client-Directed, and fast/disruptive Kill-Chain. Switchable as conditions change."
eyebrow: "Managed Service"
lead: "Every environment accumulates. Every project, every employee, every vendor relationship leaves accounts, permissions, and configurations behind. Almost nothing removes them. Left alone, the attack surface grows without bound — regardless of what else you fix. This is the service that stops it."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
---
## The Problem Nobody Solves
You can patch every server, harden every policy, complete every module engagement — and still lose ground every quarter. Because nobody is taking objects *away*.
A departed contractor's account lingers. A temporary ACL becomes permanent. A VM spun up for a migration is forgotten but still reachable. A service principal granted broad consent for a project nobody remembers still holds it. The estate accretes objects continuously.
The usual answer is "we'll schedule a cleanup sprint." The cleanup sprint never happens, because it is never urgent — until it is the breach.
## Why a Team Beats an Activity — The Sign Flip
A housekeeping *activity* is throughput gated by **attention**. Attention is the most volatile and preemptible resource in any IT organisation: the moment there is an incident, an audit, or a project deadline, the housekeeping stream drops to zero.
A housekeeping *team* is throughput gated by **headcount**, which is stable. It cannot be quietly defunded by reprioritisation, because it is a line item and a contract, not a good intention.
That difference is categorical, not marginal. The estate accretes objects continuously. If cleanup drains slower than accretion, the attack surface grows even while the team is "doing housekeeping." A dedicated team that drains *faster* than accretion crosses zero net-throughput and **flips the sign**: bounded and shrinking instead of unbounded growth.
The dedicated team is not a faster bailer. It is the difference between a bucket and a pump.
| | Housekeeping as activity | Housekeeping as team |
|---|---|---|
| Throughput gated by | Attention (volatile, preemptible) | Headcount (stable) |
| Behaviour under incident/deadline | Drops to zero | Holds a floor |
| Net effect on attack surface | Usually negative (accretion > drain) | Positive (drain > accretion) |
| Defunding | Silent, by reprioritisation | Explicit, requires cancelling a contract |
## Why This Is the Security Function Built to Be Outsourced
Most security functions outsource badly because they need deep, current context. Housekeeping is the exception:
- **Procedural throughput, not context.** Disabling an account whose owner left fourteen months ago and which has not authenticated since does not require understanding your business. Procedure plus throughput is the definition of outsourceable work.
- **Counter-cyclical to your own attention.** It is the work nobody internal will ever prioritise because it is never urgent until the breach — which is exactly why it should be somebody else's entire business.
- **SLA-able on clean metrics.** Backlog aging, items closed per cycle, time-from-uncovered-to-owned, and the attack-surface trend line are all measurable and contractible.
- **ASTRAL-gated for trust.** Every disposition is an owned, prioritised, client-approved backlog item gated through an ASTRAL pull request. You see every action. **The backlog is the control surface** — that is what makes handing the work to an outside team an easy yes.
## The Two Modes
The same team, the same backlog, and the same tooling deliver two distinct services. They differ on one axis — **who assigns priority** — and everything else follows from it.
### Mode 1 — Client-Directed (The Night-Shift Crew)
The night-shift cleaning crew works around your operations, to the rota you set, and the office is clean in the morning. You point; they clean. The client owns prioritisation — the team drains whatever the client puts in front of it, within change-management constraints, never forcing a window the client has not agreed.
**Character:** cheap, slow, safe, thorough, non-disruptive.
**Payoff:** linear and reliable. The attack surface stops growing and slowly recedes.
**Ideal for:** organisations that know they have accumulated debt, want it worked down continuously, and prize operational stability over speed.
### Mode 2 — Kill-Chain (The Strike Team)
Priority is assigned by security analysis — the kill chain, not operational comfort. The team closes the chain from the outside, deliberately unconstrained by the normal change calendar, because the point is to remove existential paths faster than bureaucracy would ever allow.
**Character:** expensive, fast, disruptive, asymmetric payoff.
**Payoff:** asymmetric. A small number of targeted removals on the kill chain yields disproportionate risk reduction. The chain-length trend does not bend — it drops.
**Ideal for:** post-incident, pre-audit, pre/post-M&A, or any organisation that has accepted it is carrying existential exposure and wants it gone faster than its own processes permit.
**Requires:** executive air cover. Disruption is a feature here, not a bug.
### Switchability Is the Product
A client can move between modes as conditions change. The default posture is Mode 1: cheap, continuous, safe. When a triggering event arrives — a breach, an audit deadline, a kill-chain assessment that surfaces an unacceptable shortest path — the same team escalates into Mode 2 for a defined window, closes the existential paths under executive air cover, then drops back to Mode 1 maintenance.
You are not buying two teams. You are buying one team with a throttle — cheap continuity plus the option to surge when the threat justifies it.
## What the Team Drains
Stale user, contractor, and service accounts with no owner. Orphaned group memberships and permissions that outlasted their project. Old app registrations and service principals. Enrolled devices no longer in use. Conditional Access policies with no named owner. Legacy protocols (NTLM, basic auth, SMBv1). DNS records for decommissioned services. Temporary firewall rules gone permanent. Old GPOs, admin rights, and certificates.
## The Authorisation Rail
A team that disables accounts and removes ACLs needs one bad disposition away from severing something load-bearing. The safety is not trust — it is structure:
- Every disposition is a **backlog item gated by an ASTRAL pull request the client approves**. Nothing is removed silently.
- **Soft-disable with a reversal window before hard delete.** Disable, wait, confirm nothing broke, then remove.
- **Freeze / break-glass mode.** During an active incident, the housekeeping loop is freezable so the team never reverts an incident-response action.
- **Explicit scoping.** The team's authority is bounded to named object classes and named scopes, documented and approved.
## Commercial Tiers
| Tier | What it is | Best for |
|------|-----------|---------|
| **Assessment & Backlog Standup** | Kill-chain assessment + ASTRAL/PULSAR feeders, backlog populated and prioritised, scope and authorisation rail defined | Clients with accumulated debt and no queue yet |
| **Mode 1 Retainer** | Continuous, change-windowed backlog attrition at contracted throughput | Stable-state clients wanting the surface worked down without disruption |
| **Mode 2 Engagement** | Time-boxed, exec-sponsored campaign to collapse existential paths | Post-incident, pre-audit, M&A, or unacceptable kill-chain exposure |
| **Switchable Retainer** | Mode 1 baseline with pre-agreed Mode 2 escalation triggers and rates | Clients who want cheap continuity and the option to surge |
SLA metrics are the same across all tiers: items closed per cycle, P0/P1 aging, time-from-uncovered-to-owned, and the attack-surface / kill-chain-length trend.
## The Antifragile Connection
Housekeeping as a Service is the human action layer beneath the CQRE tooling: ASTRAL and PULSAR surface and prioritise; the housekeeping team *acts* on it. The ASTRAL identity-ownership extension — death signals (owner account disabled), silence signals (no authentication in a year), and change signals (property mutations) — manufactures prioritised backlog items automatically. Detect → accrete → drain → report, in one loop.
Security is a contact sport. The tools find the work. The team finishes it.
<div class="cta-strip">
<h2>Ready to flip the sign?</h2>
<p>The Assessment & Backlog Standup is the right entry point — a kill-chain assessment that populates and prioritises the queue before the team picks it up.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/" class="btn btn-outline">Our Consulting Approach</a>
</div>
</div>
+10
View File
@@ -0,0 +1,10 @@
---
title: "Products"
description: "Open-source and commercial tools for M365 governance, audit log retention, and configuration management."
eyebrow: "Open Source & Commercial"
lead: "Three tools that together give you complete visibility over your Microsoft 365 tenant — what happened, what your configuration looks like, and what it all means."
---
PULSAR captures the signal. ASTRAL holds the baseline. AURORA makes sense of both.
All three tools are independently useful and progressively more powerful in combination.
+104
View File
@@ -0,0 +1,104 @@
---
title: "ASTRAL"
description: "Admin Security: Tenant Review, Automation & Lifecycle. Git-tracked M365 configuration snapshots with drift detection, PR-based review, and baseline restore."
eyebrow: "Free & Open Source"
lead: "ASTRAL answers the question your M365 tenant cannot: what does our configuration look like right now, what did it look like before, and what changed — and who approved that change?"
icon: "🌌"
badge:
text: "Free & Open Source"
color: "green"
actions:
- label: "View on GitHub"
url: "https://github.com/cqrenet/astral"
external: true
primary: true
- label: "Learn about AURORA →"
url: "/products/aurora/"
---
## What ASTRAL Does
ASTRAL takes regular snapshots of your Microsoft 365 configuration — Conditional Access policies, Intune compliance and configuration profiles, admin role assignments, authentication methods, cross-tenant access settings, privileged groups, and more — and stores them as versioned files in a Git repository.
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📸</div>
<div class="feature-item-body">
<h4>Configuration Snapshots</h4>
<p>Regular, automated snapshots of your entire M365 configuration stored as human-readable JSON files in Git. Coverage includes Conditional Access, Intune, Entra ID roles, PIM policies, authentication methods, cross-tenant access, identity protection policies, and more.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔀</div>
<div class="feature-item-body">
<h4>Drift Detection & Pull Requests</h4>
<p>When configuration changes between snapshots, ASTRAL opens a Pull Request in Azure DevOps showing exactly what changed in a human-readable diff. If Azure OpenAI is configured, it adds a plain-English narrative explaining the change and its implications.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">✅</div>
<div class="feature-item-body">
<h4>Reviewable Approval Trail</h4>
<p>PRs can be reviewed, commented on, and approved or rejected by the team. This is lightweight change management built on infrastructure you already use. Every decision is timestamped and reviewer-attributed — audit evidence ready without extra tooling.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">↩️</div>
<div class="feature-item-body">
<h4>Baseline Restore</h4>
<p>If a drift PR is rejected, a pipeline can automatically restore the previous configuration. The Git baseline is the source of truth. "What do we restore to?" becomes a deterministic operation, not an emergency reconstruction exercise.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🤖</div>
<div class="feature-item-body">
<h4>MCP Server</h4>
<p>ASTRAL exposes its snapshot data via the Model Context Protocol, enabling AI assistants to query configuration history, compare policy states, and surface drift in natural language. AURORA uses this interface for cross-tool diagnostics.</p>
</div>
</div>
</div>
## Coverage
ASTRAL currently covers the following M365 workloads:
- **Entra ID** — Conditional Access policies, authentication methods, authorization policy, security defaults, cross-tenant access, external collaboration settings
- **Entra Roles** — Permanent and PIM-eligible role assignments, PIM governance policies, privileged group membership with delta tracking
- **Intune** — Compliance policies, device configuration profiles, enrollment restrictions
- **Identity Protection** — Sign-in risk policy, user risk policy, MFA registration policy
- **Reports** — Nightly generated Intune and Entra documentation, committed to the repository automatically
Phase 2 (planned): UTCM API integration covering Exchange Online, Teams, Defender, and Purview — 249 additional resource types via a single API surface.
## Bring Your Own AI
AI PR narratives use any OpenAI-compatible endpoint — Azure OpenAI, Ollama (local), Groq, or others. ASTRAL is fully functional without AI. The narratives are an enhancement, not a dependency.
## What This Gives You Strategically
**Configuration decoupled from Microsoft's control plane.** Once M365 configuration lives in Git, it is data you own. The history, the review workflow, the approval trail — none of it depends on Microsoft's tools. Gitea, GitHub, GitLab, or a self-hosted instance are all valid targets.
**Disaster recovery baseline.** The Git history is not just evidence — it is a rebuild blueprint. If a CA policy is catastrophically misconfigured or bulk changes are made by a compromised account, the previous known-good state is in Git and the restore pipeline applies it deterministically.
**Compliance evidence.** ASTRAL's Git trail maps directly onto NIS2 Article 21 (configuration management), DORA Article 11 (ICT change management), GDPR Article 5(2) (accountability principle), and ISO 27001 A.8.9 (configuration management). External auditors receive timestamped, reviewer-attributed evidence — not manual screenshots.
**Institutional knowledge capture.** Every PR comment, AI narrative, and approval decision is a searchable, permanent record of why a configuration choice was made. Teams without this lose institutional knowledge every time personnel changes.
## Deployment Model
ASTRAL runs entirely within your Azure DevOps organisation and Microsoft tenant:
- One ADO project
- Three pipelines (backup, review sync, restore)
- One Entra app registration (read-only Graph permissions + targeted Intune read)
- One variable group
No data leaves your environment. No CQRE infrastructure is involved. No ongoing licensing.
<div class="cta-strip">
<h2>Ready to deploy ASTRAL?</h2>
<p>Full deployment guide, bootstrap scripts, and pipeline YAML are on GitHub.</p>
<div class="actions">
<a href="https://github.com/cqrenet/astral" class="btn btn-primary" target="_blank" rel="noopener">View on GitHub</a>
<a href="/products/aurora/" class="btn btn-outline">Explore AURORA →</a>
</div>
</div>
+105
View File
@@ -0,0 +1,105 @@
---
title: "AURORA"
description: "Audit, Unified Review, Observability & Remediation for Administrators. The paid AI-assisted operations layer that connects PULSAR and ASTRAL."
eyebrow: "Commercial"
lead: "AURORA sits in front of PULSAR and ASTRAL, connecting them into a single unified interface with AI-assisted cross-tool diagnostics, multi-scope orchestration, and enriched SIEM forwarding."
icon: "🌅"
badge:
text: "Commercial"
color: "orange"
actions:
- label: "Contact Us"
url: "/about/#contact"
primary: true
- label: "← Back to Products"
url: "/products/"
---
## What AURORA Does
PULSAR captures the signal. ASTRAL holds the baseline. AURORA makes sense of both.
AURORA is a unified operations platform that connects to PULSAR and ASTRAL via their MCP servers, exposes a single unified interface to your AI tool, and provides cross-tool diagnostics that neither product can answer alone. **AURORA stores no data** — all data lives in PULSAR (MongoDB) and ASTRAL (Git). AURORA is purely a query, orchestration, and intelligence layer.
## Cross-Tool Diagnostic Tools
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🔗</div>
<div class="feature-item-body">
<h4>Correlate Drift with Audit</h4>
<p><em>Who in the portal triggered this drift commit?</em> — Gets recent Git commits from ASTRAL and PULSAR audit events in the same window, matches by timestamp and resource name. Directly satisfies DORA Article 11's requirement to demonstrate who changed what and why.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏥</div>
<div class="feature-item-body">
<h4>Diagnose Policy Errors</h4>
<p><em>Why is this compliance policy erroring on some devices?</em> — Fetches policy config and assignments from ASTRAL, queries PULSAR for audit events touching that policy, synthesises a narrative answer. Turns a 2-hour investigation into 2 minutes.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📱</div>
<div class="feature-item-body">
<h4>Explain Device Compliance</h4>
<p><em>Why did this device suddenly become non-compliant?</em> — Pulls assigned policies from ASTRAL, fetches all PULSAR audit events for the device, synthesises a compliance timeline with AI-generated narrative.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📊</div>
<div class="feature-item-body">
<h4>Tenant Security Summary</h4>
<p><em>What happened in my tenant this week that I should know about?</em> — Combines ASTRAL open drift PRs with PULSAR event summary, generates an executive briefing. Weekly security digest without manual work.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">⚖️</div>
<div class="feature-item-body">
<h4>Compare Scopes</h4>
<p><em>What's different between my production and development Conditional Access policies?</em> — Compares configuration state across AURORA's configured named scopes (production, staging, test tenants).</p>
</div>
</div>
</div>
## Multi-Scope Orchestration
AURORA connects to multiple named ASTRAL instances within one organisation — production read-only alongside development read-write, with direct configuration comparison between scopes. This is a distinct capability from what ASTRAL or PULSAR can deliver independently.
## Enriched SIEM Forwarding
PULSAR forwards raw audit events to a SIEM. AURORA forwards *enriched* events — audit events correlated with ASTRAL configuration state at the time of the event. Each forwarded event carries:
- The current ASTRAL snapshot state of the affected resource
- Whether a matching Git commit exists in ASTRAL within the same time window
- Risk signals: whether the affected policy is tagged high-sensitivity, whether the actor holds a privileged role
This produces qualitatively higher-quality SIEM data than any direct Microsoft integration delivers.
## Pricing
AURORA is priced per-tenant, not per-user. Self-hosted customers bring their own Azure OpenAI endpoint (BYOAI). Hosted includes fully managed infrastructure and AI.
| Tier | Self-Hosted | Hosted |
|------|-------------|--------|
| Single tenant | €259/mo (€2,590/yr) | €389/mo (€3,890/yr) |
| Up to 5 scopes | €429/mo (€4,290/yr) | €599/mo (€5,990/yr) |
| Enterprise | Custom | Custom |
Annual billing includes ~15% discount.
**Support** is included with all AURORA tiers (email, 2-business-day SLA). Enterprise includes a dedicated Slack channel and same-day response.
## EU Compliance Notes
- **Self-hosted**: runs entirely on your Azure infrastructure, EU data residency preserved, no data processing agreement required with CQRE for the core product.
- **Hosted**: CQRE manages the stack. EU data is stored and processed within the EU/EEA. A GDPR data processing agreement (DPA) is required before onboarding.
- **BYOAI self-hosted**: pointing `LLM_BASE_URL` at your own Azure OpenAI EU endpoint ensures no tenant data leaves your region.
<div class="cta-strip">
<h2>Interested in AURORA?</h2>
<p>AURORA is in active development. Contact us to discuss your requirements, join the early access program, or get help sizing the right tier.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/products/pulsar/" class="btn btn-outline">Start with PULSAR (Free)</a>
</div>
</div>
+97
View File
@@ -0,0 +1,97 @@
---
title: "PULSAR"
description: "Platform for Unified Log Search, Alerting & Review. Free, open-source M365 audit log ingestion with indefinite retention and AI-ready query interface."
eyebrow: "Free & Open Source"
lead: "PULSAR continuously ingests Microsoft 365 admin audit events and stores them in a database you own. Search, alert, forward to your SIEM, and query via AI — with no retention expiry."
icon: "📡"
badge:
text: "Free & Open Source"
color: "green"
actions:
- label: "View on GitHub"
url: "https://github.com/cqrenet/pulsar"
external: true
primary: true
- label: "Learn about ASTRAL →"
url: "/products/astral/"
---
## The Problem PULSAR Solves
Microsoft 365 E3 provides 90 days of audit log retention, accessible only through the Microsoft Purview portal. Events older than 90 days are permanently gone. There is no alerting on admin actions, no forwarding, and no integration surface beyond Microsoft's API.
PULSAR solves this entirely. Once deployed, audit events are continuously pulled and stored in your own MongoDB instance. Retention is indefinite. The data is yours.
## What PULSAR Does
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">📥</div>
<div class="feature-item-body">
<h4>Continuous Ingestion</h4>
<p>Polls Microsoft audit APIs on a configurable interval and stores all events incrementally. Watermarks ensure nothing is missed. Sources: Entra directory audit logs, Intune audit logs, Exchange / SharePoint / Teams via Office 365 Management Activity API.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔍</div>
<div class="feature-item-body">
<h4>Search & Filter UI</h4>
<p>A web interface for searching events by workload, operation type, user, resource, and time range. Designed for the kind of investigation that is otherwise done by manually clicking through the Purview portal.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🔔</div>
<div class="feature-item-body">
<h4>Alerting</h4>
<p>Rules-based alerting with webhook delivery. Trigger on new permanent Global Admin assignments, CA policy changes outside business hours, guest invitations in sensitive groups, and more.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📤</div>
<div class="feature-item-body">
<h4>SIEM Forwarding</h4>
<p>Forward audit events to an external SIEM. Events are normalised and enriched before forwarding — higher-quality data than a direct Microsoft API integration delivers.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🤖</div>
<div class="feature-item-body">
<h4>MCP Server</h4>
<p>PULSAR exposes <code>search_events</code>, <code>get_event</code>, and <code>get_summary</code> via the Model Context Protocol, so an AI assistant (Claude, Copilot, or any MCP-compatible client) can query your audit log in natural language.</p>
</div>
</div>
</div>
## Why This Matters
**For compliance (NIS2 / GDPR Article 33):** The 90-day M365 portal window does not satisfy requirements for ongoing, reliable audit log retention. PULSAR's indefinite retention, independently controlled, satisfies supervisory authority expectations and enables the 72-hour breach notification window under GDPR.
**For incident investigation:** Without PULSAR, a breach investigation depends on whatever events are still within the portal window. With PULSAR, the full history is always available — even if detection was slow.
**For governance evidence:** Every admin action, searchable and permanent. Useful for internal reporting, audit preparation, and the team's own situational awareness.
## Architecture
PULSAR runs as a container on Azure Container Apps alongside ASTRAL. The recommended database backend for production is **Azure Cosmos DB for MongoDB (vCore)** — fully managed, wire-compatible, and available within your Azure region (EU data residency preserved).
Secrets are stored in Azure Key Vault and surfaced via managed identity — no credentials in environment variables.
## PULSAR + ASTRAL Together
| | PULSAR | ASTRAL |
|---|---|---|
| **Question answered** | What happened? | What does the config look like, and what changed? |
| **Data stored** | Audit events | Configuration snapshots |
| **Storage** | MongoDB | Git repository |
| **History** | From deployment date | From deployment date |
Deployed together, they give the complete picture: every admin action in the audit log, and every configuration state at any point in time.
<div class="cta-strip">
<h2>Ready to deploy PULSAR?</h2>
<p>Full deployment documentation and Docker images are available on GitHub.</p>
<div class="actions">
<a href="https://github.com/cqrenet/pulsar" class="btn btn-primary" target="_blank" rel="noopener">View on GitHub</a>
<a href="/products/astral/" class="btn btn-outline">Explore ASTRAL →</a>
</div>
</div>
+97
View File
@@ -0,0 +1,97 @@
---
title: "Virtual CISO & Security Architect"
description: "Fractional security leadership — strategic direction, risk ownership, board reporting, and program management without a full-time hire."
eyebrow: "Retained Capability"
lead: "A virtual CISO gives you a senior security leader who knows your environment, owns your risk programme, and is accountable for results — on a retainer that fits your organisation's size and budget."
actions:
- label: "Get in Touch"
url: "/about/#contact"
primary: true
---
## The Problem with Outsourcing Security Strategy
Outsourcing your SOC does not outsource your risk. It outsources your alert triage. The thinking — detection engineering, threat modelling, business-context awareness — must stay inside your organisation. Otherwise you are paying for someone else's generic playbook applied to your specific threat landscape.
The same applies to security leadership. A compliance consultant can write policies. An MSSP can operate your tools. But neither owns your risk programme, speaks to your board in terms they understand, or builds a security posture that reflects your actual business.
## What a Virtual CISO Does
<div class="feature-list">
<div class="feature-item">
<div class="feature-item-icon">🎯</div>
<div class="feature-item-body">
<h4>Risk Ownership & Strategy</h4>
<p>Translates your business context into a security programme. Identifies and prioritises existential risks — not a generic framework checklist — and builds a roadmap that reflects your actual threat landscape, budget, and team capability.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏛️</div>
<div class="feature-item-body">
<h4>Board & Executive Reporting</h4>
<p>Security status communicated in business terms. Board-ready risk reports, incident briefings, and investment cases. Executives get the information they need to make decisions; practitioners get the direction they need to execute.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🏗️</div>
<div class="feature-item-body">
<h4>Security Architecture</h4>
<p>Design authority for security decisions across identity, infrastructure, data, and applications. Architecture review for new projects, vendor evaluations, and technology decisions before they create technical debt you will spend years unwinding.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">🤝</div>
<div class="feature-item-body">
<h4>Vendor & MSSP Governance</h4>
<p>If you outsource SOC, pentest, or compliance functions, you still need someone with the expertise to brief vendors accurately, evaluate their output, and hold them accountable. An MSSP's SLA measures ticket volume — your vCISO measures whether threats are actually detected.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📋</div>
<div class="feature-item-body">
<h4>Compliance & Regulatory Programme</h4>
<p>NIS2, DORA, GDPR, ISO 27001, SOC 2 — these require more than policy documents. A vCISO builds the evidence, maps the controls, manages the audit relationship, and ensures your compliance programme is demonstrable rather than theatrical.</p>
</div>
</div>
<div class="feature-item">
<div class="feature-item-icon">📈</div>
<div class="feature-item-body">
<h4>Capability Building</h4>
<p>Works alongside your team to build retained capability — security skills that stay in your organisation when the engagement ends. The goal is independence, not dependency.</p>
</div>
</div>
</div>
## Who This Is For
**Mid-market organisations (50–500 employees)** that have moved beyond "IT handles security" but cannot justify a full-time CISO salary, benefits, and overhead. A vCISO delivers the expertise at a fraction of the cost.
**Regulated industries** where demonstrable security governance is a regulatory requirement, not a nice-to-have. DORA, NIS2, and sector-specific requirements need someone who understands both the regulation and the technology.
**Organisations with outsourced security operations** who need someone who can brief the MSSP accurately, evaluate their output, and make the investment intelligible to leadership.
**Post-incident** organisations that need a structured recovery programme and honest assessment of what failed.
## What a vCISO Is Not
We do not run a 24/7 SOC. We do not provide managed detection and response. We do not sign off on compliance audits as an independent auditor. We do not replace your internal IT team.
What we provide is security *leadership* and *architecture* — the strategic and technical direction that makes your other investments coherent and accountable.
## The Antifragile Difference
A vCISO engagement from CQRE is built on the same principles as every other engagement:
- **Starts with what you own** — before any new tools are proposed, we exhaust existing capabilities
- **Prices by deliverable** — retainer scope and deliverables are defined before work begins
- **Builds retained capability** — every engagement increases your internal competence, not your dependency on us
- **Discloses commercial relationships** — if we recommend a tool, we disclose any commercial relationship and explain why the alternative does not meet your specific need
<div class="cta-strip">
<h2>Ready for a conversation?</h2>
<p>A vCISO engagement typically begins with the Brownhat Diagnostic — an honest assessment of where you stand before we agree on scope and retainer structure.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Get in Touch</a>
<a href="/consulting/" class="btn btn-outline">Our Consulting Approach</a>
</div>
</div>
+40
View File
@@ -0,0 +1,40 @@
baseURL: 'https://cqre.net'
title: 'CQRE.NET'
defaultContentLanguage: 'en'
defaultContentLanguageInSubdir: false
languages:
en:
weight: 1
title: 'CQRE.NET'
contentDir: 'content/en'
params:
label: 'English'
locale: 'en-US'
description: "Antifragile cybersecurity consulting and open-source M365 governance tools."
cs:
weight: 2
title: 'CQRE.NET'
contentDir: 'content/cs'
params:
label: 'Čeština'
locale: 'cs-CZ'
description: "Antifragilní poradenství v oblasti kybernetické bezpečnosti a open-source nástroje pro správu M365."
params:
githubOrg: 'https://github.com/cqrenet'
contactEmail: 'hello@cqre.net'
gitea: 'https://git.cqre.net'
markup:
goldmark:
renderer:
unsafe: true
outputs:
home:
- HTML
page:
- HTML
section:
- HTML
+34
View File
@@ -0,0 +1,34 @@
nav_products: Produkty
nav_consulting: Poradenství
nav_vciso: Virtuální CISO
nav_housekeeping: Housekeeping
nav_about: O nás
nav_contact: Kontakt
nav_open_source: Open Source
home_hero_subtitle: "Zabezpečme vaši síť."
home_cta_products: Naše produkty
home_cta_consulting: Náš přístup
home_section_products: Open-Source nástroje
home_section_services: Služby
home_section_tools: Nástroje & produkty
product_free_open_source: "Zdarma & Open Source"
product_paid: "Komerční"
product_github: Zobrazit na GitHub
product_docs: Dokumentace
product_learn_more: Zjistit více
consulting_title: Antifragilní poradenství
vciso_title: Virtuální CISO & bezpečnostní architekt
housekeeping_title: Housekeeping jako služba
footer_tagline: "Zabezpečme vaši síť."
footer_rights: "Všechna práva vyhrazena."
footer_github: GitHub
footer_contact: Kontakt
lang_switch: English
skills_title: "Konzultační moduly"
skills_subtitle: "Nezávislé, samostatné moduly — začněte tam, kde bolí nejvíc."
+34
View File
@@ -0,0 +1,34 @@
nav_products: Products
nav_consulting: Consulting
nav_vciso: vCISO
nav_housekeeping: Housekeeping
nav_about: About
nav_contact: Contact
nav_open_source: Open Source
home_hero_subtitle: "Let's secure your net."
home_cta_products: Explore Products
home_cta_consulting: Our Approach
home_section_products: Open-Source Products
home_section_services: Services
home_section_tools: Tools & Products
product_free_open_source: "Free & Open Source"
product_paid: "Commercial"
product_github: View on GitHub
product_docs: Documentation
product_learn_more: Learn More
consulting_title: Antifragile Consulting
vciso_title: Virtual CISO & Security Architect
housekeeping_title: Housekeeping as a Service
footer_tagline: "Let's secure your net."
footer_rights: "All rights reserved."
footer_github: GitHub
footer_contact: Contact
lang_switch: Čeština
skills_title: "Consulting Modules"
skills_subtitle: "Independent, self-contained modules — start where the pain is highest."
+13
View File
@@ -0,0 +1,13 @@
<!DOCTYPE html>
<html lang="{{ .Language.Lang }}">
<head>
{{ partial "head.html" . }}
</head>
<body>
{{ partial "header.html" . }}
<main>
{{ block "main" . }}{{ end }}
</main>
{{ partial "footer.html" . }}
</body>
</html>
+27
View File
@@ -0,0 +1,27 @@
{{ define "main" }}
<section class="product-hero">
<div class="container">
{{ with .Params.eyebrow }}<div class="hero-eyebrow eyebrow">{{ . }}</div>{{ end }}
<h1>{{ .Title }}</h1>
{{ with .Params.lead }}<p class="lead">{{ . }}</p>{{ end }}
</div>
</section>
<div class="page-content">
<div class="container" style="max-width: var(--max-width);">
{{ .Content }}
<div class="card-grid mt-4">
{{ range .Pages }}
<a class="card" href="{{ .RelPermalink }}" style="text-decoration:none; color:inherit;">
{{ with .Params.icon }}<div class="card-icon">{{ . }}</div>{{ end }}
<h3>{{ .Title }}</h3>
<p>{{ .Description }}</p>
<div class="card-footer">
{{ with .Params.badge }}<span class="badge badge-{{ .color }}">{{ .text }}</span>{{ end }}
</div>
</a>
{{ end }}
</div>
</div>
</div>
{{ end }}
+34
View File
@@ -0,0 +1,34 @@
{{ define "main" }}
<div class="breadcrumb">
<div class="breadcrumb-inner">
<a href="{{ "/" | relLangURL }}">CQRE.NET</a>
{{ with .Parent }}
<span class="sep">/</span>
<a href="{{ .RelPermalink }}">{{ .Title }}</a>
{{ end }}
<span class="sep">/</span>
<span>{{ .Title }}</span>
</div>
</div>
<section class="product-hero">
<div class="container">
{{ with .Params.eyebrow }}<div class="hero-eyebrow eyebrow">{{ . }}</div>{{ end }}
<h1>{{ .Title }}</h1>
{{ with .Params.lead }}<p class="lead">{{ . }}</p>{{ end }}
{{ with .Params.actions }}
<div class="actions">
{{ range . }}
<a href="{{ .url }}" class="btn {{ if .primary }}btn-primary{{ else }}btn-outline{{ end }}" {{ if .external }}target="_blank" rel="noopener"{{ end }}>{{ .label }}</a>
{{ end }}
</div>
{{ end }}
</div>
</section>
<div class="page-content">
<div class="container">
{{ .Content }}
</div>
</div>
{{ end }}
+124
View File
@@ -0,0 +1,124 @@
{{ define "main" }}
<!-- Hero -->
<section class="hero">
<div class="container">
<div class="hero-eyebrow">Cybersecurity · M365 Governance · Open Source</div>
<h1>{{ .Params.heroTitle | default .Site.Title }}</h1>
<p class="hero-sub">{{ .Params.heroSub | default (i18n "home_hero_subtitle") }}</p>
<div class="hero-actions">
<a href="{{ "/products/" | relLangURL }}" class="btn btn-primary">{{ i18n "home_cta_products" }}</a>
<a href="{{ "/consulting/" | relLangURL }}" class="btn btn-outline">{{ i18n "home_cta_consulting" }}</a>
</div>
</div>
</section>
<!-- Products: PULSAR, ASTRAL, AURORA -->
<section class="section section-alt">
<div class="container">
<div class="section-header">
<span class="section-label">{{ i18n "home_section_products" }}</span>
<h2>{{ .Params.productsTitle | default "The M365 Governance Suite" }}</h2>
<p>{{ .Params.productsSub | default "Three complementary open-source tools for complete visibility and control over your Microsoft 365 tenant." }}</p>
</div>
<div style="overflow-x:auto; margin-bottom: 2.5rem;">
<table class="stack-table">
<thead>
<tr>
<th>Product</th>
<th>What it answers</th>
<th>Model</th>
</tr>
</thead>
<tbody>
<tr>
<td class="product-name"><a href="{{ "/products/pulsar/" | relLangURL }}">PULSAR</a></td>
<td>{{ .Params.pulsarTagline | default "What happened, when, and by whom?" }}</td>
<td><span class="badge badge-green">{{ i18n "product_free_open_source" }}</span></td>
</tr>
<tr>
<td class="product-name"><a href="{{ "/products/astral/" | relLangURL }}">ASTRAL</a></td>
<td>{{ .Params.astralTagline | default "What does my config look like and what changed?" }}</td>
<td><span class="badge badge-green">{{ i18n "product_free_open_source" }}</span></td>
</tr>
<tr>
<td class="product-name"><a href="{{ "/products/aurora/" | relLangURL }}">AURORA</a></td>
<td>{{ .Params.auroraTagline | default "What does it mean and what should I do?" }}</td>
<td><span class="badge badge-orange">{{ i18n "product_paid" }}</span></td>
</tr>
</tbody>
</table>
</div>
<div class="card-grid">
<a class="card" href="{{ "/products/pulsar/" | relLangURL }}" style="text-decoration:none;color:inherit;">
<div class="card-icon">📡</div>
<h3>PULSAR</h3>
<p>{{ .Params.pulsarDesc | default "Continuous M365 audit log ingestion with search, alerting, SIEM forwarding, and an MCP server for AI-assisted querying. Indefinite retention. Your data, your infrastructure." }}</p>
<div class="card-footer"><span class="badge badge-green">Free & Open Source</span></div>
</a>
<a class="card" href="{{ "/products/astral/" | relLangURL }}" style="text-decoration:none;color:inherit;">
<div class="card-icon">🌌</div>
<h3>ASTRAL</h3>
<p>{{ .Params.astralDesc | default "Git-tracked snapshots of M365 configuration with drift detection, PR-based review and approval, and baseline restore. Every config change, forever." }}</p>
<div class="card-footer"><span class="badge badge-green">Free & Open Source</span></div>
</a>
<a class="card" href="{{ "/products/aurora/" | relLangURL }}" style="text-decoration:none;color:inherit;">
<div class="card-icon">🌅</div>
<h3>AURORA</h3>
<p>{{ .Params.auroraDesc | default "A unified AI-assisted operations layer connecting PULSAR and ASTRAL. Cross-tool diagnostics, multi-scope orchestration, and enriched SIEM forwarding." }}</p>
<div class="card-footer"><span class="badge badge-orange">Commercial</span></div>
</a>
</div>
</div>
</section>
<!-- Services -->
<section class="section">
<div class="container">
<div class="section-header">
<span class="section-label">{{ i18n "home_section_services" }}</span>
<h2>{{ .Params.servicesTitle | default "Security That Grows Stronger" }}</h2>
<p>{{ .Params.servicesSub | default "Consulting and strategic services built around one principle: your organization should emerge from every disruption more capable than before." }}</p>
</div>
<div class="card-grid">
<a class="card" href="{{ "/consulting/" | relLangURL }}" style="text-decoration:none;color:inherit;">
<div class="card-icon">🛡️</div>
<h3>{{ i18n "consulting_title" }}</h3>
<p>{{ .Params.consultingDesc | default "The Brownhat methodology: start with what you own, close the kill chain, build retained capability. Modular engagements from 30 days upward — no monolithic programs." }}</p>
<div class="card-footer">
<span class="badge badge-blue">14 Modules</span>
<span class="badge badge-blue">NIS2 · DORA · ISO 27001</span>
</div>
</a>
<a class="card" href="{{ "/vciso/" | relLangURL }}" style="text-decoration:none;color:inherit;">
<div class="card-icon">🧭</div>
<h3>{{ i18n "vciso_title" }}</h3>
<p>{{ .Params.vcisoDesc | default "Fractional security leadership for organisations that need strategic direction without a full-time hire. Risk ownership, board reporting, vendor governance, and program management." }}</p>
<div class="card-footer">
<span class="badge badge-blue">Strategic</span>
<span class="badge badge-blue">Retainer</span>
</div>
</a>
<a class="card" href="{{ "/housekeeping/" | relLangURL }}" style="text-decoration:none;color:inherit;">
<div class="card-icon">🧹</div>
<h3>{{ i18n "housekeeping_title" }}</h3>
<p>{{ .Params.housekeepingDesc | default "A dedicated rented team that drains your attack surface continuously. Client-Directed for steady attrition, Kill-Chain for collapsing existential paths fast. The sign flip from growth to decay." }}</p>
<div class="card-footer">
<span class="badge badge-blue">Two Modes</span>
<span class="badge badge-blue">Managed Service</span>
</div>
</a>
</div>
</div>
</section>
{{ with .Content }}
<section class="section-sm">
<div class="container">{{ . }}</div>
</section>
{{ end }}
{{ end }}
+24
View File
@@ -0,0 +1,24 @@
<footer class="site-footer">
<div class="footer-inner">
<div class="footer-brand">
<a class="site-logo" href="{{ "/" | relLangURL }}">
<img src="{{ "images/logo.svg" | relURL }}" alt="CQRE.NET" width="28" height="28">
CQRE<span style="color:var(--accent)">.NET</span>
</a>
<p>{{ i18n "footer_tagline" }}</p>
</div>
<ul class="footer-links">
<li><a href="{{ "/products/" | relLangURL }}">{{ i18n "nav_products" }}</a></li>
<li><a href="{{ "/consulting/" | relLangURL }}">{{ i18n "nav_consulting" }}</a></li>
<li><a href="{{ "/vciso/" | relLangURL }}">{{ i18n "nav_vciso" }}</a></li>
<li><a href="{{ "/housekeeping/" | relLangURL }}">{{ i18n "nav_housekeeping" }}</a></li>
<li><a href="{{ "/about/" | relLangURL }}">{{ i18n "nav_about" }}</a></li>
<li><a href="https://github.com/cqrenet" target="_blank" rel="noopener">{{ i18n "footer_github" }}</a></li>
</ul>
</div>
<div class="footer-copy container">
© {{ now.Year }} CQRE.NET Ltd. {{ i18n "footer_rights" }}
&nbsp;·&nbsp;
{{ range .Translations }}<a href="{{ .Permalink }}">{{ .Language.Params.label }}</a>{{ end }}
</div>
</footer>
+9
View File
@@ -0,0 +1,9 @@
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>{{ if .IsHome }}{{ .Site.Title }} — {{ .Site.Params.description }}{{ else }}{{ .Title }} | {{ .Site.Title }}{{ end }}</title>
<meta name="description" content="{{ with .Description }}{{ . }}{{ else }}{{ .Site.Params.description }}{{ end }}">
<link rel="stylesheet" href="{{ "css/main.css" | relURL }}">
<link rel="icon" type="image/svg+xml" href="{{ "images/logo.svg" | relURL }}">
{{ range .AlternativeOutputFormats -}}
{{ printf `<link rel="%s" type="%s" href="%s" title="%s" />` .Rel .MediaType.Type .Permalink $.Site.Title | safeHTML }}
{{ end -}}
+27
View File
@@ -0,0 +1,27 @@
<header class="site-header">
<nav class="nav-inner">
<a class="site-logo" href="{{ "/" | relLangURL }}">
<img src="{{ "images/logo.svg" | relURL }}" alt="CQRE.NET" width="36" height="36">
CQRE<span>.NET</span>
</a>
<button class="nav-mobile-toggle" aria-label="Toggle menu" onclick="document.querySelector('.nav-links').classList.toggle('open')">
<svg viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round">
<line x1="3" y1="6" x2="21" y2="6"></line>
<line x1="3" y1="12" x2="21" y2="12"></line>
<line x1="3" y1="18" x2="21" y2="18"></line>
</svg>
</button>
<ul class="nav-links">
<li><a href="{{ "/products/" | relLangURL }}"{{ if hasPrefix .RelPermalink "/products" }} class="active"{{ end }}>{{ i18n "nav_products" }}</a></li>
<li><a href="{{ "/consulting/" | relLangURL }}"{{ if hasPrefix .RelPermalink "/consulting" }} class="active"{{ end }}>{{ i18n "nav_consulting" }}</a></li>
<li><a href="{{ "/vciso/" | relLangURL }}"{{ if eq .RelPermalink "/vciso/" }} class="active"{{ end }}>{{ i18n "nav_vciso" }}</a></li>
<li><a href="{{ "/housekeeping/" | relLangURL }}"{{ if eq .RelPermalink "/housekeeping/" }} class="active"{{ end }}>{{ i18n "nav_housekeeping" }}</a></li>
<li><a href="{{ "/about/" | relLangURL }}"{{ if eq .RelPermalink "/about/" }} class="active"{{ end }}>{{ i18n "nav_about" }}</a></li>
{{ range .Translations }}
<li><a class="nav-lang" href="{{ .Permalink }}">{{ i18n "lang_switch" }}</a></li>
{{ end }}
</ul>
</nav>
</header>
+725
View File
@@ -0,0 +1,725 @@
/* CQRE.NET — Main Stylesheet v2.0 */
/* Modern cybersecurity aesthetic */
:root {
--bg-deep: #03070f;
--bg-primary: #050a14;
--bg-secondary: #0a1628;
--bg-tertiary: #0d1f38;
--bg-elevated: #122440;
--accent: #fbbf24;
--accent-dim: #8b5cf6;
--accent-glow: rgba(251, 191, 36, 0.15);
--accent-glow-strong: rgba(251, 191, 36, 0.35);
--orange: #f97316;
--green: #22c55e;
--text: #e2e8f0;
--text-muted: #94a3b8;
--text-dim: #64748b;
--border: rgba(148, 163, 184, 0.08);
--border-hover: rgba(251, 191, 36, 0.25);
--card-bg: rgba(10, 22, 40, 0.6);
--card-hover: rgba(13, 31, 56, 0.8);
--radius: 10px;
--radius-lg: 16px;
--transition: 0.25s cubic-bezier(0.4, 0, 0.2, 1);
--max-width: 1200px;
--font-sans: -apple-system, BlinkMacSystemFont, 'Segoe UI', system-ui, sans-serif;
--font-mono: 'SF Mono', 'Fira Code', 'Cascadia Code', monospace;
}
*, *::before, *::after { box-sizing: border-box; margin: 0; padding: 0; }
html { font-size: 16px; scroll-behavior: smooth; }
body {
background: var(--bg-primary);
color: var(--text);
font-family: var(--font-sans);
line-height: 1.7;
min-height: 100vh;
display: flex;
flex-direction: column;
position: relative;
}
/* Subtle grid background */
body::before {
content: '';
position: fixed;
inset: 0;
background-image:
linear-gradient(rgba(139, 92, 246, 0.04) 1px, transparent 1px),
linear-gradient(90deg, rgba(139, 92, 246, 0.04) 1px, transparent 1px);
background-size: 60px 60px;
mask-image: radial-gradient(ellipse 80% 60% at 50% 0%, rgba(0,0,0,0.4) 0%, transparent 70%);
-webkit-mask-image: radial-gradient(ellipse 80% 60% at 50% 0%, rgba(0,0,0,0.4) 0%, transparent 70%);
pointer-events: none;
z-index: 0;
}
main { position: relative; z-index: 1; }
a { color: var(--accent); text-decoration: none; transition: color var(--transition), filter var(--transition); }
a:hover { color: #fde68a; filter: brightness(1.15); }
/* ── Typography ── */
h1, h2, h3, h4 { line-height: 1.2; font-weight: 700; letter-spacing: -0.02em; }
h1 { font-size: clamp(2.2rem, 5.5vw, 3.6rem); }
h2 { font-size: clamp(1.6rem, 3.5vw, 2.4rem); }
h3 { font-size: 1.3rem; }
h4 { font-size: 1.1rem; }
p { margin-bottom: 1rem; }
p:last-child { margin-bottom: 0; }
strong { color: #f8fafc; font-weight: 600; }
.container { max-width: var(--max-width); margin: 0 auto; padding: 0 1.5rem; }
/* ── Header / Nav ── */
.site-header {
position: sticky;
top: 0;
z-index: 100;
background: rgba(5, 10, 20, 0.85);
backdrop-filter: blur(16px) saturate(1.2);
-webkit-backdrop-filter: blur(16px) saturate(1.2);
border-bottom: 1px solid var(--border);
}
.site-header::after {
content: '';
position: absolute;
bottom: -1px;
left: 0;
right: 0;
height: 1px;
background: linear-gradient(90deg, transparent 0%, var(--accent) 50%, transparent 100%);
opacity: 0.4;
}
.nav-inner {
display: flex;
align-items: center;
justify-content: space-between;
padding: 0.9rem 1.5rem;
max-width: var(--max-width);
margin: 0 auto;
gap: 2rem;
}
.site-logo {
display: inline-flex;
align-items: center;
gap: 0.6rem;
font-size: 1.25rem;
font-weight: 800;
letter-spacing: -0.02em;
color: #f8fafc;
text-decoration: none;
}
.site-logo img {
height: 36px;
width: auto;
filter: drop-shadow(0 0 8px rgba(251, 191, 36, 0.3));
}
.site-logo span { color: var(--accent); }
.nav-links {
display: flex;
align-items: center;
gap: 0.25rem;
list-style: none;
flex-wrap: wrap;
}
.nav-links a {
color: var(--text-muted);
font-size: 0.9rem;
font-weight: 500;
padding: 0.45rem 0.85rem;
border-radius: var(--radius);
transition: color var(--transition), background var(--transition), box-shadow var(--transition);
}
.nav-links a:hover,
.nav-links a.active {
color: var(--text);
background: rgba(0, 212, 255, 0.08);
box-shadow: 0 0 16px rgba(251, 191, 36, 0.08);
}
.nav-lang {
font-size: 0.85rem;
padding: 0.4rem 0.75rem;
border: 1px solid var(--border);
border-radius: var(--radius);
color: var(--text-muted);
margin-left: 0.5rem;
transition: all var(--transition);
font-family: var(--font-mono);
font-size: 0.8rem;
}
.nav-lang:hover {
border-color: var(--accent);
color: var(--accent);
box-shadow: 0 0 12px rgba(251, 191, 36, 0.15);
}
/* Mobile toggle */
.nav-mobile-toggle {
display: none;
background: none;
border: none;
color: var(--text);
cursor: pointer;
padding: 0.4rem;
}
.nav-mobile-toggle svg { width: 24px; height: 24px; }
/* ── Hero ── */
.hero {
padding: 8rem 1.5rem 6rem;
text-align: center;
position: relative;
overflow: hidden;
}
.hero::before {
content: '';
position: absolute;
inset: 0;
background:
radial-gradient(ellipse 70% 50% at 50% 0%, rgba(0, 212, 255, 0.1) 0%, transparent 60%),
radial-gradient(ellipse 50% 40% at 80% 20%, rgba(14, 165, 233, 0.06) 0%, transparent 50%);
pointer-events: none;
}
.hero .container { position: relative; z-index: 1; }
.hero-eyebrow {
display: inline-flex;
align-items: center;
gap: 0.5rem;
font-family: var(--font-mono);
font-size: 0.78rem;
font-weight: 600;
letter-spacing: 0.12em;
text-transform: uppercase;
color: var(--accent);
background: rgba(251, 191, 36, 0.08);
border: 1px solid rgba(251, 191, 36, 0.2);
padding: 0.4rem 1rem;
border-radius: 100px;
margin-bottom: 1.75rem;
box-shadow: 0 0 20px rgba(251, 191, 36, 0.08);
}
.hero h1 {
color: #f8fafc;
margin-bottom: 1.5rem;
text-shadow: 0 0 40px rgba(251, 191, 36, 0.1);
}
.hero h1 em { font-style: normal; color: var(--accent); }
.hero-sub {
font-size: 1.2rem;
color: var(--text-muted);
max-width: 640px;
margin: 0 auto 2.75rem;
line-height: 1.7;
}
.hero-actions { display: flex; gap: 1rem; justify-content: center; flex-wrap: wrap; }
/* ── Buttons ── */
.btn {
display: inline-flex;
align-items: center;
gap: 0.5rem;
padding: 0.8rem 1.6rem;
border-radius: var(--radius);
font-size: 0.95rem;
font-weight: 600;
cursor: pointer;
transition: all var(--transition);
border: none;
text-decoration: none;
position: relative;
overflow: hidden;
}
.btn-primary {
background: linear-gradient(135deg, var(--accent) 0%, #d97706 100%);
color: #03070f;
box-shadow: 0 0 24px rgba(251, 191, 36, 0.25), 0 4px 12px rgba(0, 0, 0, 0.3);
}
.btn-primary:hover {
background: linear-gradient(135deg, #fcd34d 0%, #f59e0b 100%);
color: #03070f;
box-shadow: 0 0 32px rgba(251, 191, 36, 0.4), 0 6px 16px rgba(0, 0, 0, 0.4);
transform: translateY(-1px);
}
.btn-outline {
background: transparent;
color: var(--text);
border: 1px solid var(--border);
box-shadow: inset 0 1px 0 rgba(255,255,255,0.03);
}
.btn-outline:hover {
border-color: var(--accent);
color: var(--accent);
box-shadow: 0 0 20px rgba(251, 191, 36, 0.1), inset 0 1px 0 rgba(255,255,255,0.06);
transform: translateY(-1px);
}
.btn-sm { padding: 0.5rem 1rem; font-size: 0.85rem; }
/* ── Sections ── */
.section { padding: 5.5rem 1.5rem; position: relative; }
.section-sm { padding: 3rem 1.5rem; }
.section-alt { background: linear-gradient(180deg, var(--bg-secondary) 0%, var(--bg-primary) 100%); }
.section-header { text-align: center; margin-bottom: 3.5rem; }
.section-header h2 { margin-bottom: 1rem; }
.section-header p { color: var(--text-muted); font-size: 1.1rem; max-width: 600px; margin: 0 auto; line-height: 1.7; }
.section-label {
display: inline-block;
font-family: var(--font-mono);
font-size: 0.75rem;
font-weight: 600;
letter-spacing: 0.12em;
text-transform: uppercase;
color: var(--accent);
margin-bottom: 0.75rem;
padding: 0.25rem 0.6rem;
border-radius: 4px;
background: rgba(251, 191, 36, 0.06);
border: 1px solid rgba(251, 191, 36, 0.12);
}
/* ── Cards ── */
.card-grid {
display: grid;
grid-template-columns: repeat(auto-fill, minmax(320px, 1fr));
gap: 1.5rem;
}
.card-grid-2 { grid-template-columns: repeat(auto-fill, minmax(420px, 1fr)); }
.card {
background: var(--card-bg);
border: 1px solid var(--border);
border-radius: var(--radius-lg);
padding: 2rem;
transition: all var(--transition);
display: flex;
flex-direction: column;
position: relative;
overflow: hidden;
}
.card::before {
content: '';
position: absolute;
inset: 0;
border-radius: var(--radius-lg);
padding: 1px;
background: linear-gradient(135deg, rgba(251, 191, 36, 0.15) 0%, transparent 40%, transparent 60%, rgba(139, 92, 246, 0.1) 100%);
-webkit-mask: linear-gradient(#fff 0 0) content-box, linear-gradient(#fff 0 0);
mask: linear-gradient(#fff 0 0) content-box, linear-gradient(#fff 0 0);
-webkit-mask-composite: xor;
mask-composite: exclude;
pointer-events: none;
opacity: 0;
transition: opacity var(--transition);
}
.card:hover {
background: var(--card-hover);
border-color: var(--border-hover);
transform: translateY(-3px);
box-shadow: 0 12px 40px rgba(0, 0, 0, 0.4), 0 0 30px rgba(251, 191, 36, 0.06);
}
.card:hover::before { opacity: 1; }
.card-icon {
width: 48px;
height: 48px;
border-radius: 12px;
display: flex;
align-items: center;
justify-content: center;
font-size: 1.5rem;
margin-bottom: 1.25rem;
background: rgba(251, 191, 36, 0.08);
border: 1px solid rgba(251, 191, 36, 0.15);
box-shadow: 0 0 16px rgba(251, 191, 36, 0.08);
}
.card h3 { margin-bottom: 0.6rem; color: #f8fafc; }
.card p { color: var(--text-muted); font-size: 0.95rem; flex: 1; line-height: 1.7; }
.card-footer { margin-top: 1.5rem; display: flex; gap: 0.5rem; flex-wrap: wrap; }
.badge {
font-family: var(--font-mono);
font-size: 0.7rem;
font-weight: 600;
padding: 0.3rem 0.7rem;
border-radius: 100px;
letter-spacing: 0.06em;
text-transform: uppercase;
}
.badge-green { background: rgba(34, 197, 94, 0.1); color: #4ade80; border: 1px solid rgba(34, 197, 94, 0.2); }
.badge-blue { background: rgba(0, 212, 255, 0.08); color: var(--accent); border: 1px solid rgba(0, 212, 255, 0.18); }
.badge-orange { background: rgba(249, 115, 22, 0.1); color: #fb923c; border: 1px solid rgba(249, 115, 22, 0.2); }
/* ── Product page ── */
.product-hero {
padding: 5.5rem 1.5rem 3.5rem;
border-bottom: 1px solid var(--border);
position: relative;
}
.product-hero::before {
content: '';
position: absolute;
inset: 0;
background: radial-gradient(ellipse 60% 50% at 50% 0%, rgba(139, 92, 246, 0.08) 0%, transparent 60%);
pointer-events: none;
}
.product-hero .container { position: relative; z-index: 1; }
.product-hero .eyebrow { margin-bottom: 1.25rem; }
.product-hero h1 { margin-bottom: 1.25rem; }
.product-hero .lead {
font-size: 1.15rem;
color: var(--text-muted);
max-width: 700px;
margin-bottom: 2rem;
line-height: 1.7;
}
.product-hero .actions { display: flex; gap: 0.875rem; flex-wrap: wrap; }
.page-content { padding: 4rem 1.5rem; }
.page-content .container { max-width: 800px; }
.page-content h2 {
margin-top: 3rem;
margin-bottom: 1rem;
color: #f8fafc;
padding-bottom: 0.5rem;
border-bottom: 1px solid var(--border);
}
.page-content h3 { margin-top: 2rem; margin-bottom: 0.6rem; color: #cbd5e1; }
.page-content ul, .page-content ol { padding-left: 1.5rem; margin-bottom: 1.25rem; }
.page-content li { margin-bottom: 0.4rem; color: var(--text-muted); }
.page-content li strong { color: #f8fafc; }
.page-content blockquote {
border-left: 3px solid var(--accent);
padding: 1rem 1.5rem;
margin: 2rem 0;
background: rgba(139, 92, 246, 0.04);
border-radius: 0 var(--radius) var(--radius) 0;
color: var(--text-muted);
font-style: italic;
box-shadow: 4px 0 20px rgba(139, 92, 246, 0.04);
}
/* ── Feature list ── */
.feature-list { display: flex; flex-direction: column; gap: 1.75rem; margin: 2.5rem 0; }
.feature-item { display: flex; gap: 1.25rem; }
.feature-item-icon {
flex-shrink: 0;
width: 40px;
height: 40px;
border-radius: 10px;
background: rgba(0, 212, 255, 0.08);
border: 1px solid rgba(0, 212, 255, 0.15);
display: flex;
align-items: center;
justify-content: center;
font-size: 1.2rem;
margin-top: 2px;
box-shadow: 0 0 12px rgba(0, 212, 255, 0.06);
}
.feature-item-body h4 { margin-bottom: 0.35rem; color: #f8fafc; }
.feature-item-body p { color: var(--text-muted); font-size: 0.95rem; line-height: 1.7; }
/* ── Pillars ── */
.pillars { display: grid; grid-template-columns: repeat(auto-fill, minmax(200px, 1fr)); gap: 1.5rem; margin: 2.5rem 0; }
.pillar {
background: var(--card-bg);
border: 1px solid var(--border);
border-radius: var(--radius-lg);
padding: 1.75rem;
transition: all var(--transition);
}
.pillar:hover {
border-color: var(--border-hover);
transform: translateY(-2px);
box-shadow: 0 8px 24px rgba(0, 0, 0, 0.3);
}
.pillar-num {
font-family: var(--font-mono);
font-size: 2.2rem;
font-weight: 800;
color: var(--accent);
opacity: 0.35;
line-height: 1;
margin-bottom: 0.6rem;
}
.pillar h4 { color: #f8fafc; margin-bottom: 0.5rem; }
.pillar p { font-size: 0.9rem; color: var(--text-muted); line-height: 1.7; }
/* ── Skills / Modules grid ── */
.modules-grid {
display: grid;
grid-template-columns: repeat(auto-fill, minmax(320px, 1fr));
gap: 1.25rem;
margin-top: 2rem;
}
.module-card {
background: var(--card-bg);
border: 1px solid var(--border);
border-radius: var(--radius-lg);
padding: 1.5rem 1.75rem;
transition: all var(--transition);
}
.module-card:hover {
border-color: var(--border-hover);
background: var(--card-hover);
transform: translateY(-2px);
box-shadow: 0 8px 24px rgba(0, 0, 0, 0.3);
}
.module-num {
font-family: var(--font-mono);
font-size: 0.75rem;
font-weight: 700;
color: var(--accent);
text-transform: uppercase;
letter-spacing: 0.08em;
margin-bottom: 0.4rem;
}
.module-card h3 { font-size: 1.1rem; color: #f8fafc; margin-bottom: 0.5rem; }
.module-card p { font-size: 0.9rem; color: var(--text-muted); margin: 0; line-height: 1.7; }
.module-meta { display: flex; gap: 0.5rem; flex-wrap: wrap; margin-top: 1rem; }
/* ── Stack comparison table ── */
.stack-table {
width: 100%;
border-collapse: separate;
border-spacing: 0;
margin: 2.5rem 0;
font-size: 0.95rem;
border-radius: var(--radius-lg);
overflow: hidden;
border: 1px solid var(--border);
}
.stack-table th, .stack-table td { padding: 0.9rem 1.25rem; text-align: left; }
.stack-table th {
color: var(--text-muted);
font-weight: 600;
font-size: 0.8rem;
text-transform: uppercase;
letter-spacing: 0.06em;
background: var(--bg-tertiary);
font-family: var(--font-mono);
border-bottom: 1px solid var(--border);
}
.stack-table td { color: var(--text); border-bottom: 1px solid var(--border); }
.stack-table tr:last-child td { border-bottom: none; }
.stack-table tr:hover td { background: rgba(251, 191, 36, 0.03); }
.stack-table .product-name { color: #f8fafc; font-weight: 600; }
/* ── CTA strip ── */
.cta-strip {
background: linear-gradient(135deg, var(--bg-tertiary) 0%, var(--bg-secondary) 100%);
border: 1px solid var(--border);
border-radius: var(--radius-lg);
padding: 3.5rem 2.5rem;
text-align: center;
margin: 4rem 0 0;
position: relative;
overflow: hidden;
}
.cta-strip::before {
content: '';
position: absolute;
inset: 0;
background: radial-gradient(ellipse 60% 50% at 50% 0%, rgba(139, 92, 246, 0.1) 0%, transparent 60%);
pointer-events: none;
}
.cta-strip h2 { margin-bottom: 1rem; position: relative; }
.cta-strip p { color: var(--text-muted); margin-bottom: 2rem; max-width: 500px; margin-left: auto; margin-right: auto; position: relative; }
.cta-strip .actions { display: flex; gap: 1rem; justify-content: center; flex-wrap: wrap; position: relative; }
/* ── Footer ── */
.site-footer {
margin-top: auto;
border-top: 1px solid var(--border);
padding: 3.5rem 1.5rem 2rem;
background: linear-gradient(180deg, var(--bg-secondary) 0%, var(--bg-deep) 100%);
position: relative;
}
.site-footer::before {
content: '';
position: absolute;
top: -1px;
left: 0;
right: 0;
height: 1px;
background: linear-gradient(90deg, transparent 0%, var(--accent) 50%, transparent 100%);
opacity: 0.3;
}
.footer-inner {
max-width: var(--max-width);
margin: 0 auto;
display: grid;
grid-template-columns: 1fr auto;
gap: 2rem;
align-items: start;
}
.footer-brand .site-logo { font-size: 1.1rem; display: block; margin-bottom: 0.5rem; }
.footer-brand p { font-size: 0.88rem; color: var(--text-dim); max-width: 320px; line-height: 1.7; }
.footer-links { display: flex; gap: 1.75rem; list-style: none; }
.footer-links a { font-size: 0.88rem; color: var(--text-dim); transition: all var(--transition); }
.footer-links a:hover { color: var(--accent); }
.footer-copy {
margin-top: 2.5rem;
padding-top: 1.5rem;
border-top: 1px solid var(--border);
text-align: center;
font-size: 0.8rem;
color: var(--text-dim);
font-family: var(--font-mono);
}
.footer-copy a { color: var(--text-dim); }
.footer-copy a:hover { color: var(--accent); }
/* ── Breadcrumb ── */
.breadcrumb { padding: 1.25rem 1.5rem; }
.breadcrumb-inner {
max-width: var(--max-width);
margin: 0 auto;
display: flex;
gap: 0.6rem;
align-items: center;
font-size: 0.85rem;
color: var(--text-dim);
font-family: var(--font-mono);
}
.breadcrumb-inner a { color: var(--text-dim); }
.breadcrumb-inner a:hover { color: var(--accent); }
.breadcrumb-inner span.sep { opacity: 0.4; }
/* ── About page ── */
.about-intro { display: grid; grid-template-columns: 1fr 1fr; gap: 3rem; align-items: start; margin-bottom: 4rem; }
/* ── Logo in footer brand ── */
.footer-brand .site-logo img {
height: 28px;
width: auto;
filter: drop-shadow(0 0 6px rgba(251, 191, 36, 0.2));
}
/* ── Animations ── */
@keyframes fadeInUp {
from { opacity: 0; transform: translateY(20px); }
to { opacity: 1; transform: translateY(0); }
}
.hero .container > * {
animation: fadeInUp 0.6s ease forwards;
}
.hero .container > *:nth-child(1) { animation-delay: 0.1s; opacity: 0; }
.hero .container > *:nth-child(2) { animation-delay: 0.2s; opacity: 0; }
.hero .container > *:nth-child(3) { animation-delay: 0.3s; opacity: 0; }
.hero .container > *:nth-child(4) { animation-delay: 0.4s; opacity: 0; }
/* ── Responsive ── */
@media (max-width: 768px) {
.hero { padding: 5rem 1rem 4rem; }
.card-grid-2 { grid-template-columns: 1fr; }
.footer-inner { grid-template-columns: 1fr; gap: 1.5rem; }
.footer-links { flex-wrap: wrap; gap: 1rem; }
.pillars { grid-template-columns: 1fr 1fr; }
.about-intro { grid-template-columns: 1fr; }
.nav-links {
display: none;
position: absolute;
top: 100%;
left: 0;
right: 0;
background: rgba(5, 10, 20, 0.98);
backdrop-filter: blur(16px);
border-bottom: 1px solid var(--border);
flex-direction: column;
padding: 1rem 1.5rem;
gap: 0.25rem;
}
.nav-links.open { display: flex; }
.nav-links a { width: 100%; padding: 0.6rem 0.75rem; }
.nav-mobile-toggle { display: flex; margin-left: auto; }
.nav-lang { margin-left: 0; margin-top: 0.5rem; width: fit-content; }
}
@media (max-width: 480px) {
.pillars { grid-template-columns: 1fr; }
.modules-grid { grid-template-columns: 1fr; }
.card-grid { grid-template-columns: 1fr; }
.cta-strip { padding: 2.5rem 1.5rem; }
.section { padding: 4rem 1rem; }
}
/* ── Utilities ── */
.text-center { text-align: center; }
.text-muted { color: var(--text-muted); }
.mt-1 { margin-top: 0.5rem; }
.mt-2 { margin-top: 1rem; }
.mt-3 { margin-top: 1.5rem; }
.mt-4 { margin-top: 2rem; }
.mb-2 { margin-bottom: 1rem; }
.mb-3 { margin-bottom: 1.5rem; }
.gap-1 { gap: 0.5rem; }
.flex { display: flex; }
.flex-wrap { flex-wrap: wrap; }
.items-center { align-items: center; }
+57
View File
@@ -0,0 +1,57 @@
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 512 512" fill="none">
<defs>
<linearGradient id="shieldGrad" x1="0" y1="0" x2="512" y2="512">
<stop offset="0%" stop-color="#1a103c"/>
<stop offset="100%" stop-color="#0f0820"/>
</linearGradient>
<linearGradient id="wingGrad" x1="0" y1="0" x2="512" y2="256">
<stop offset="0%" stop-color="#e2e8f0"/>
<stop offset="50%" stop-color="#c4b5fd"/>
<stop offset="100%" stop-color="#fbbf24"/>
</linearGradient>
<linearGradient id="circuitGrad" x1="0" y1="256" x2="512" y2="512">
<stop offset="0%" stop-color="#8b5cf6"/>
<stop offset="100%" stop-color="#fbbf24"/>
</linearGradient>
</defs>
<!-- Shield outline -->
<path d="M256 20 L472 80 L472 240 C472 380 370 460 256 492 C142 460 40 380 40 240 L40 80 Z"
fill="url(#shieldGrad)" stroke="#2e1065" stroke-width="3"/>
<!-- Inner shield highlight -->
<path d="M256 35 L455 90 L455 235 C455 365 362 440 256 470 C150 440 57 365 57 235 L57 90 Z"
fill="none" stroke="rgba(255,255,255,0.06)" stroke-width="2"/>
<!-- Swan neck & head -->
<path d="M140 180 C140 120 180 80 230 80 C260 80 280 100 280 130 C280 160 250 180 220 200 C190 220 170 250 170 290 C170 340 200 380 240 400"
stroke="url(#wingGrad)" stroke-width="12" fill="none" stroke-linecap="round"/>
<!-- Swan head detail -->
<circle cx="230" cy="85" r="8" fill="#fbbf24"/>
<circle cx="230" cy="85" r="4" fill="#ffffff"/>
<!-- Wing / Circuit traces -->
<path d="M200 240 L320 180 L380 200" stroke="url(#wingGrad)" stroke-width="6" fill="none" stroke-linecap="round" stroke-linejoin="round"/>
<path d="M220 280 L340 220 L400 240" stroke="url(#wingGrad)" stroke-width="5" fill="none" stroke-linecap="round" stroke-linejoin="round" opacity="0.7"/>
<path d="M240 320 L360 260 L420 280" stroke="url(#circuitGrad)" stroke-width="4" fill="none" stroke-linecap="round" stroke-linejoin="round" opacity="0.5"/>
<!-- Circuit nodes -->
<circle cx="320" cy="180" r="5" fill="#e2e8f0"/>
<circle cx="380" cy="200" r="5" fill="#e2e8f0"/>
<circle cx="340" cy="220" r="4" fill="#c4b5fd"/>
<circle cx="400" cy="240" r="4" fill="#c4b5fd"/>
<circle cx="360" cy="260" r="3" fill="#fbbf24"/>
<circle cx="420" cy="280" r="3" fill="#fbbf24"/>
<!-- Binary digits -->
<text x="320" y="340" font-family="monospace" font-size="28" font-weight="700" fill="#fbbf24" opacity="0.9">0101</text>
<text x="300" y="375" font-family="monospace" font-size="24" font-weight="700" fill="#8b5cf6" opacity="0.7">0110</text>
<!-- Bottom circuit line -->
<path d="M120 380 L180 380 L200 360 L240 360 L260 380 L320 380"
stroke="url(#circuitGrad)" stroke-width="3" fill="none" stroke-linecap="round"/>
<circle cx="180" cy="380" r="3" fill="#fbbf24"/>
<circle cx="240" cy="360" r="3" fill="#fbbf24"/>
<circle cx="320" cy="380" r="3" fill="#fbbf24"/>
</svg>

After

Width:  |  Height:  |  Size: 2.8 KiB