Files
website/content/en/consulting/skills.md
T

172 lines
9.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "Consulting Modules"
description: "14 independent, self-contained security modules. Start where the pain is highest — each module delivers measurable value and creates natural appetite for the next."
eyebrow: "Modular Engagements"
lead: "Every module stands alone. Every module makes the next one easier. Start where the pain is highest — not where the framework says you should."
---
Every engagement begins with the **Brownhat Diagnostic** (Module 0): a structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised module roadmap. The diagnostic is a paid, bounded engagement and delivers value regardless of whether further work follows.
<div class="modules-grid">
<div class="module-card">
<div class="module-num">Module 0</div>
<h3><a href="/consulting/module-0/">Brownhat Diagnostic</a></h3>
<p>Structured two-day NIST CSF 2.0 baseline assessment. Honest picture of your security posture, prioritised gap list, and recommended module sequence. Kill chain synthesis using the Kill Chain Assessment app — maps the unknown estate into an attack graph, computes the shortest path to existential impact, and sizes every finding into a remediation quantum. Entry point for every new client.</p>
<div class="module-meta">
<span class="badge badge-blue">2 days</span>
<span class="badge badge-blue">All clients</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 1</div>
<h3><a href="/consulting/module-1/">Endpoint Management Foundation</a></h3>
<p>Device inventory and enrollment, compliance baseline, shadow IT discovery, basic conditional access integration, ASTRAL deployment for Intune drift detection. Full device visibility in 30–45 days.</p>
<div class="module-meta">
<span class="badge badge-blue">30–45 days</span>
<span class="badge badge-green">M365 E3+</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 2</div>
<h3><a href="/consulting/module-2/">M365 Identity Security</a></h3>
<p>Full identity census, Conditional Access policy register, MFA enforcement, legacy auth blocked, PIM deployment or JIT process, PULSAR for audit log intelligence, guest access audit and governance.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-green">M365 E3+</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 3</div>
<h3><a href="/consulting/module-3/">M365 Security Hardening</a></h3>
<p>Exchange Online Protection tuning, mailbox auditing, Unified Audit Log forwarding, Secure Score baseline and improvement plan, ASR rules, ASTRAL baseline capture. No new licensing required for E3 clients.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-green">No new spend</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 4</div>
<h3><a href="/consulting/module-4/">Data Governance &amp; Compliance</a></h3>
<p>Sensitivity label deployment, retention policies for all M365 workloads, DLP policies, eDiscovery readiness, Teams governance, SharePoint site provisioning. Regulatory evidence produced as a natural output.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 days</span>
<span class="badge badge-orange">NIS2 · DORA · GDPR</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 5</div>
<h3><a href="/consulting/module-5/">AI Sovereignty Bridge</a></h3>
<p>Shadow AI inventory, Azure OpenAI deployment with private endpoints, conditional access for AI tools, first RAG pipeline or fine-tuned model on proprietary data, AI governance policy. Your intelligence stays yours.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-blue">Azure</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 6</div>
<h3><a href="/consulting/module-6/">On-Premise AD &amp; Endpoint Hardening</a></h3>
<p>Full AD identity census with orphan and privilege analysis, password audit of compromised credentials (Elysium), KRBTGT rotation, LAPS, Sysmon, PAW architecture, Azure AD Connect hardening.</p>
<div class="module-meta">
<span class="badge badge-blue">45–60 days</span>
<span class="badge badge-blue">Hybrid identity</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 7</div>
<h3><a href="/consulting/module-7/">Recovery &amp; Resilience</a></h3>
<p>Backup architecture review and remediation, immutable backup deployment, disaster recovery runbooks, tabletop exercise, ASTRAL baseline as rebuild blueprint. Tested recovery, not assumed.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-orange">Ransomware-resilient</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 8</div>
<h3><a href="/consulting/module-8/">Threat &amp; Vulnerability Management</a></h3>
<p>Quantum vulnerability management for the exploitation-first era. Kill-chain position, reachability, and exploit availability replace CVSS as the sort key. The ~90% subtraction removes false urgency — leaving the 10% genuinely exploitable in your environment. Four time-budgeted quanta: Critical (hours — compensating control, not the patch), Severe (days), Standard (sprint), Dark (unsized — routed to discovery). Zero-budget discovery with osquery and scripts. The Kill Chain Assessment app maps the attack graph and sizes every node automatically.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 days</span>
<span class="badge badge-green">Open-source first</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 9</div>
<h3><a href="/consulting/module-9/">Organisational Resilience</a></h3>
<p>Dev/Sec/Ops merger, shift-left security integration, process assurance for teams feeling "not in control", quality management engagement, embedded security review in the delivery pipeline.</p>
<div class="module-meta">
<span class="badge badge-blue">60–90 days</span>
<span class="badge badge-blue">Culture + process</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 10</div>
<h3><a href="/consulting/module-10/">Red Team &amp; Validation</a></h3>
<p>Assumption validation after hardening modules. Targeted adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Measures real security improvement, not compliance scores.</p>
<div class="module-meta">
<span class="badge badge-blue">15–30 days</span>
<span class="badge badge-orange">Post-hardening</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 11</div>
<h3><a href="/consulting/module-11/">Blue/Purple Team Foundation</a></h3>
<p>Building defensive capability from existing tool investments. Detection engineering, alert tuning, SIEM rule development, threat hunting playbooks. Your existing tools, made to actually work.</p>
<div class="module-meta">
<span class="badge badge-blue">45–90 days</span>
<span class="badge badge-blue">Existing tools</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 12</div>
<h3><a href="/consulting/module-12/">T0 Asset Protection</a></h3>
<p>Tier 0 asset classification across identity, infrastructure, and data. Protection architecture for crown-jewel assets. Privileged access design ensuring Tier 0 is never reachable from Tier 1 or 2 compromise.</p>
<div class="module-meta">
<span class="badge badge-blue">30–60 days</span>
<span class="badge badge-orange">Architecture</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 13</div>
<h3><a href="/consulting/module-13/">Privileged Access Architecture</a></h3>
<p>PAM design using Teleport, Tailscale/Headscale, and JIT access. Vendor remote access governance. Ephemeral credentials, session recording, and access reviews. Zero standing access where possible.</p>
<div class="module-meta">
<span class="badge badge-blue">45–60 days</span>
<span class="badge badge-blue">Open-source PAM</span>
</div>
</div>
<div class="module-card">
<div class="module-num">Module 14</div>
<h3><a href="/consulting/module-14/">Sovereign Communications</a></h3>
<p>Delta Chat chatmail relay, Matrix/Element deployment, crisis out-of-band channel design. Communication infrastructure that remains available and private even if your primary collaboration platform is compromised.</p>
<div class="module-meta">
<span class="badge badge-blue">15–30 days</span>
<span class="badge badge-green">Self-hosted</span>
</div>
</div>
</div>
<div class="cta-strip">
<h2>Not sure where to start?</h2>
<p>The Brownhat Diagnostic maps your current posture to a prioritised module sequence. It is a bounded, fixed-price engagement and delivers value regardless of whether further work follows.</p>
<div class="actions">
<a href="/about/#contact" class="btn btn-primary">Book a Diagnostic</a>
<a href="/consulting/" class="btn btn-outline">About Our Approach</a>
</div>
</div>