--- title: "Module 0 β Brownhat Diagnostic" description: "The entry point for every engagement. A structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised security roadmap, a mapped estate graph, and remediation sized into cuts." eyebrow: "Consulting Module" lead: "Before any module recommendation, we need an honest picture of where you actually stand. The Brownhat Diagnostic is a structured two-day workshop β no tools installed, no scanning β that produces the clearest picture of your security posture and what matters most to fix." actions: - label: "Book a Diagnostic" url: "/about/#contact" primary: true - label: "View All Modules" url: "/consulting/skills/" --- ## What the Diagnostic Produces
An honest scoring of your posture across all six CSF 2.0 functions β GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER β with the gaps that matter most clearly separated from the ones that don't.
Using the Kill Chain Assessment app, we model your environment as an attack graph during the diagnostic. The app computes the cheapest adversary paths from entry points to your crown jewels β and the minimum-cost cut: the smallest priced set of interventions that severs every mapped path. That cut, not a severity list, is what the plan is built on.
Every intervention is sized into a cut class: hour-cut (compensating control now, not the patch), day-cut (one change window), sprint-cut (normal engineering rhythm), or dark (needs discovery first). You leave with a plan ordered by time-to-existential-impact, not by CVSS score.
A recommended sequence of modules derived directly from your gap picture and kill chain. Not a generic framework recommendation β a sequence built on what we actually found in your environment.
Every engagement begins with the Brownhat Diagnostic. It is the only honest way to select a module sequence.