172 lines
9.1 KiB
Markdown
172 lines
9.1 KiB
Markdown
---
|
||
title: "Consulting Modules"
|
||
description: "14 independent, self-contained security modules. Start where the pain is highest — each module delivers measurable value and creates natural appetite for the next."
|
||
eyebrow: "Modular Engagements"
|
||
lead: "Every module stands alone. Every module makes the next one easier. Start where the pain is highest — not where the framework says you should."
|
||
---
|
||
|
||
Every engagement begins with the **Brownhat Diagnostic** (Module 0): a structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised module roadmap. The diagnostic is a paid, bounded engagement and delivers value regardless of whether further work follows.
|
||
|
||
<div class="modules-grid">
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 0</div>
|
||
<h3><a href="/consulting/module-0/">Brownhat Diagnostic</a></h3>
|
||
<p>Structured two-day NIST CSF 2.0 baseline assessment. Honest picture of your security posture, prioritised gap list, and recommended module sequence. Kill chain synthesis using the Kill Chain Assessment app — maps the unknown estate into an attack graph, computes the shortest path to existential impact, and sizes every finding into a remediation quantum. Entry point for every new client.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">2 days</span>
|
||
<span class="badge badge-blue">All clients</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 1</div>
|
||
<h3><a href="/consulting/module-1/">Endpoint Management Foundation</a></h3>
|
||
<p>Device inventory and enrollment, compliance baseline, shadow IT discovery, basic conditional access integration, ASTRAL deployment for Intune drift detection. Full device visibility in 30–45 days.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">30–45 days</span>
|
||
<span class="badge badge-green">M365 E3+</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 2</div>
|
||
<h3><a href="/consulting/module-2/">M365 Identity Security</a></h3>
|
||
<p>Full identity census, Conditional Access policy register, MFA enforcement, legacy auth blocked, PIM deployment or JIT process, PULSAR for audit log intelligence, guest access audit and governance.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">30–60 days</span>
|
||
<span class="badge badge-green">M365 E3+</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 3</div>
|
||
<h3><a href="/consulting/module-3/">M365 Security Hardening</a></h3>
|
||
<p>Exchange Online Protection tuning, mailbox auditing, Unified Audit Log forwarding, Secure Score baseline and improvement plan, ASR rules, ASTRAL baseline capture. No new licensing required for E3 clients.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">30–60 days</span>
|
||
<span class="badge badge-green">No new spend</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 4</div>
|
||
<h3><a href="/consulting/module-4/">Data Governance & Compliance</a></h3>
|
||
<p>Sensitivity label deployment, retention policies for all M365 workloads, DLP policies, eDiscovery readiness, Teams governance, SharePoint site provisioning. Regulatory evidence produced as a natural output.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">45–90 days</span>
|
||
<span class="badge badge-orange">NIS2 · DORA · GDPR</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 5</div>
|
||
<h3><a href="/consulting/module-5/">AI Sovereignty Bridge</a></h3>
|
||
<p>Shadow AI inventory, Azure OpenAI deployment with private endpoints, conditional access for AI tools, first RAG pipeline or fine-tuned model on proprietary data, AI governance policy. Your intelligence stays yours.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">30–60 days</span>
|
||
<span class="badge badge-blue">Azure</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 6</div>
|
||
<h3><a href="/consulting/module-6/">On-Premise AD & Endpoint Hardening</a></h3>
|
||
<p>Full AD identity census with orphan and privilege analysis, password audit of compromised credentials (Elysium), KRBTGT rotation, LAPS, Sysmon, PAW architecture, Azure AD Connect hardening.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">45–60 days</span>
|
||
<span class="badge badge-blue">Hybrid identity</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 7</div>
|
||
<h3><a href="/consulting/module-7/">Recovery & Resilience</a></h3>
|
||
<p>Backup architecture review and remediation, immutable backup deployment, disaster recovery runbooks, tabletop exercise, ASTRAL baseline as rebuild blueprint. Tested recovery, not assumed.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">30–60 days</span>
|
||
<span class="badge badge-orange">Ransomware-resilient</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 8</div>
|
||
<h3><a href="/consulting/module-8/">Threat & Vulnerability Management</a></h3>
|
||
<p>Quantum vulnerability management for the exploitation-first era. Kill-chain position, reachability, and exploit availability replace CVSS as the sort key. The ~90% subtraction removes false urgency — leaving the 10% genuinely exploitable in your environment. Four time-budgeted quanta: Critical (hours — compensating control, not the patch), Severe (days), Standard (sprint), Dark (unsized — routed to discovery). Zero-budget discovery with osquery and scripts. The Kill Chain Assessment app maps the attack graph and sizes every node automatically.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">45–90 days</span>
|
||
<span class="badge badge-green">Open-source first</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 9</div>
|
||
<h3><a href="/consulting/module-9/">Organisational Resilience</a></h3>
|
||
<p>Dev/Sec/Ops merger, shift-left security integration, process assurance for teams feeling "not in control", quality management engagement, embedded security review in the delivery pipeline.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">60–90 days</span>
|
||
<span class="badge badge-blue">Culture + process</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 10</div>
|
||
<h3><a href="/consulting/module-10/">Red Team & Validation</a></h3>
|
||
<p>Assumption validation after hardening modules. Targeted adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Measures real security improvement, not compliance scores.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">15–30 days</span>
|
||
<span class="badge badge-orange">Post-hardening</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 11</div>
|
||
<h3><a href="/consulting/module-11/">Blue/Purple Team Foundation</a></h3>
|
||
<p>Building defensive capability from existing tool investments. Detection engineering, alert tuning, SIEM rule development, threat hunting playbooks. Your existing tools, made to actually work.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">45–90 days</span>
|
||
<span class="badge badge-blue">Existing tools</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 12</div>
|
||
<h3><a href="/consulting/module-12/">T0 Asset Protection</a></h3>
|
||
<p>Tier 0 asset classification across identity, infrastructure, and data. Protection architecture for crown-jewel assets. Privileged access design ensuring Tier 0 is never reachable from Tier 1 or 2 compromise.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">30–60 days</span>
|
||
<span class="badge badge-orange">Architecture</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 13</div>
|
||
<h3><a href="/consulting/module-13/">Privileged Access Architecture</a></h3>
|
||
<p>PAM design using Teleport, Tailscale/Headscale, and JIT access. Vendor remote access governance. Ephemeral credentials, session recording, and access reviews. Zero standing access where possible.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">45–60 days</span>
|
||
<span class="badge badge-blue">Open-source PAM</span>
|
||
</div>
|
||
</div>
|
||
|
||
<div class="module-card">
|
||
<div class="module-num">Module 14</div>
|
||
<h3><a href="/consulting/module-14/">Sovereign Communications</a></h3>
|
||
<p>Delta Chat chatmail relay, Matrix/Element deployment, crisis out-of-band channel design. Communication infrastructure that remains available and private even if your primary collaboration platform is compromised.</p>
|
||
<div class="module-meta">
|
||
<span class="badge badge-blue">15–30 days</span>
|
||
<span class="badge badge-green">Self-hosted</span>
|
||
</div>
|
||
</div>
|
||
|
||
</div>
|
||
|
||
<div class="cta-strip">
|
||
<h2>Not sure where to start?</h2>
|
||
<p>The Brownhat Diagnostic maps your current posture to a prioritised module sequence. It is a bounded, fixed-price engagement and delivers value regardless of whether further work follows.</p>
|
||
<div class="actions">
|
||
<a href="/about/#contact" class="btn btn-primary">Book a Diagnostic</a>
|
||
<a href="/consulting/" class="btn btn-outline">About Our Approach</a>
|
||
</div>
|
||
</div>
|