Files
website/content/en/consulting/_index.md
T

5.7 KiB
Raw Blame History

title, description, eyebrow, lead
title description eyebrow lead
Antifragile Consulting The Brownhat methodology — modular security consulting that starts with what you own, closes the kill chain, and builds capability your team retains. Brownhat Methodology We help organisations close the gap between their security investments and their actual security posture. Every engagement starts with a diagnostic. No recommendations before we understand the environment.

The Antifragile Principle

Most security programmes optimise for robustness — the ability to withstand shocks. Antifragility goes further. An antifragile organisation does not merely survive disruptions. It grows stronger from them.

Every incident produces structural improvement. Every competitor's failure creates market opportunity. Every regulatory demand is met with evidence, not promises.

The Five Pillars

01

Structural Decoupling

Identify and remove hidden dependencies before they become fatal. We do not add complexity that creates new ones.

02

Optionality Preservation

Spend your budget on things that preserve your ability to change direction. Every unnecessary tool purchase reduces your strategic flexibility.

03

Stress-to-Signal Conversion

Every incident, failure, and near-miss is intelligence. Build systems that learn from disruption rather than merely surviving it.

04

Sovereign Intelligence

Your proprietary data should improve your own capability, not a vendor's model. Own the tools and systems you depend on.

05

Asymmetric Payoff Design

Small, targeted investments on existential risks yield disproportionate protection. Concentrate effort where failure is fatal.

How Engagements Work

We do not sell monolithic transformation projects. We sell independent modules that stack. Each module delivers measurable value in 30–90 days and creates natural appetite for the next phase.

Every engagement begins with the Brownhat Diagnostic — a structured two-day NIST CSF 2.0 baseline assessment that produces an honest, prioritised picture of where the organisation stands. We do not make module recommendations before we understand the environment.

What every engagement produces: a defined scope, a defined deliverable, and assets delivered to your own repository. Every script, detection rule, configuration, and runbook we produce belongs to you. When an engagement closes, you are operationally independent.

What Makes Us Different

We start with what you own. Most consultants arrive with a shortlist of products. We arrive with a diagnostic. Before any purchase is discussed, we exhaust the capabilities of existing tools. If your Microsoft E3 tenant can close the gap, we configure it. We earn fees from expertise, not licence margins.

We price by deliverable, not by the hour. Every engagement has a defined scope and defined output before work begins. No open-ended retainers disguised as ongoing support.

We disclose our commercial relationships. We have partnerships with Huntress, Tailscale, Thinkst Canary, and Tenable. When we recommend one of these tools, we say so and explain why the open-source alternative does not meet the specific need.

We tell you what we cannot do. We are a specialist practice. We do not run a 24/7 SOC. We do not sign off on compliance audits. We do not replace your IT team. When a need falls outside our practice, we say so and point you to the right provider.

Standards Alignment

The Brownhat module set maps directly onto major regulatory frameworks:

  • NIS2 (EU 2022/2555) — Article 21 measures: configuration management (ASTRAL), logging and monitoring (PULSAR), access control, incident detection
  • DORA (EU 2022/2554) — ICT change management records (ASTRAL Git trail), incident log retention (PULSAR), ICT third-party risk governance
  • GDPR Article 32 — Continuous configuration governance and audit log retention as "appropriate technical measures"
  • ISO 27001 — A.8.9 configuration management, A.8.15 logging, control evidence produced as a natural output of the engagement
  • CIS Controls v8 — IG1 as a non-negotiable 90-day floor, achieved primarily through existing tool configuration

Brownfield Track

The main engagement model assumes a consultant walking into someone else's enterprise estate. The Brownfield Handbook applies the same methodology to the infrastructure you grew yourself — the self-hosted stack that accreted, the homelab that became production, the one box that quietly turned load-bearing. Discovery by observation, pruning, pets-versus-cattle, rebuildability, and deliberate stress: the antifragile five-part arc applied to the estate nobody designed.

This track is for self-hosters, small platforms, and teams that need to antifragile their own organically-grown infrastructure — and who want to validate the whole methodology by running it against something where the consequences are theirs.

Start with the Brownhat Diagnostic

The entry point for every new client. A structured two-day assessment that produces a prioritised picture of where you stand and what matters most to fix.