The Antifragile Principle
Most security programmes optimise for robustness — the ability to withstand shocks. Antifragility goes further. An antifragile organisation does not merely survive disruptions. It grows stronger from them.
Every incident produces structural improvement. Every competitor’s failure creates market opportunity. Every regulatory demand is met with evidence, not promises.
The Five Pillars
Structural Decoupling
Identify and remove hidden dependencies before they become fatal. We do not add complexity that creates new ones.
Optionality Preservation
Spend your budget on things that preserve your ability to change direction. Every unnecessary tool purchase reduces your strategic flexibility.
Stress-to-Signal Conversion
Every incident, failure, and near-miss is intelligence. Build systems that learn from disruption rather than merely surviving it.
Sovereign Intelligence
Your proprietary data should improve your own capability, not a vendor's model. Own the tools and systems you depend on.
Asymmetric Payoff Design
Small, targeted investments on existential risks yield disproportionate protection. Concentrate effort where failure is fatal.
How Engagements Work
We do not sell monolithic transformation projects. We sell independent modules that stack. Each module delivers measurable value in 30–90 days and creates natural appetite for the next phase.
Every engagement begins with the Brownhat Diagnostic — a structured two-day NIST CSF 2.0 baseline assessment that produces an honest, prioritised picture of where the organisation stands. We do not make module recommendations before we understand the environment.
What every engagement produces: a defined scope, a defined deliverable, and assets delivered to your own repository. Every script, detection rule, configuration, and runbook we produce belongs to you. When an engagement closes, you are operationally independent.
What Makes Us Different
We start with what you own. Most consultants arrive with a shortlist of products. We arrive with a diagnostic. Before any purchase is discussed, we exhaust the capabilities of existing tools. If your Microsoft E3 tenant can close the gap, we configure it. We earn fees from expertise, not licence margins.
We price by deliverable, not by the hour. Every engagement has a defined scope and defined output before work begins. No open-ended retainers disguised as ongoing support.
We disclose our commercial relationships. We have partnerships with Huntress, Tailscale, Thinkst Canary, and Tenable. When we recommend one of these tools, we say so and explain why the open-source alternative does not meet the specific need.
We tell you what we cannot do. We are a specialist practice. We do not run a 24/7 SOC. We do not sign off on compliance audits. We do not replace your IT team. When a need falls outside our practice, we say so and point you to the right provider.
Standards Alignment
The Brownhat module set maps directly onto major regulatory frameworks:
- NIS2 (EU 2022/2555) — Article 21 measures: configuration management (ASTRAL), logging and monitoring (PULSAR), access control, incident detection
- DORA (EU 2022/2554) — ICT change management records (ASTRAL Git trail), incident log retention (PULSAR), ICT third-party risk governance
- GDPR Article 32 — Continuous configuration governance and audit log retention as “appropriate technical measures”
- ISO 27001 — A.8.9 configuration management, A.8.15 logging, control evidence produced as a natural output of the engagement
- CIS Controls v8 — IG1 as a non-negotiable 90-day floor, achieved primarily through existing tool configuration
Brownfield Track
Some infrastructure was never designed — it grew. The internal stack that accreted over years, the one box that quietly turned load-bearing, the estate nobody ever drew a diagram of. The Brownfield track applies the same five-part arc to exactly that: discovery by observation, pruning, pets-versus-cattle, rebuildability, and deliberate stress.
We run this discipline on infrastructure we own and operate ourselves. For teams who’d rather start exactly there — where the consequences are entirely theirs — the Brownfield Handbook is the self-guided entry point.
Start with the Brownhat Diagnostic
The entry point for every new client. A structured two-day assessment that produces a prioritised picture of where you stand and what matters most to fix.
Consulting Modules
14 independent, self-contained security modules. Start where the pain is highest — each module delivers measurable value and creates natural appetite for the next.
Module 0 — Brownhat Diagnostic
The entry point for every engagement. A structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised security roadmap, a mapped estate graph, and remediation sized into cuts.
Module 1 — Endpoint Management Foundation
Device inventory, Intune enrollment, compliance baseline, shadow IT discovery, and ASTRAL deployment for drift detection. Full device visibility in 30–45 days.
Module 10 — Red Team & Adversarial Validation
Adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Validates whether hardening modules produced real security improvement or compliance dashboard improvement.
Module 11 — Blue/Purple Team Foundation
Detection engineering, alert tuning, SIEM rule development, and threat hunting playbooks. Your existing tools, made to actually work.
Module 12 — T0 Asset Protection
Tier 0 asset classification across identity, infrastructure, and data. Protection architecture ensuring crown jewels are never reachable from a Tier 1 or Tier 2 compromise.
Module 13 — Privileged Access Architecture
PAM design using Teleport, Tailscale/Headscale, and JIT access. Vendor remote access governance, ephemeral credentials, session recording, and zero standing access.
Module 14 — Sovereign Communications
Delta Chat chatmail relay, Matrix/Element deployment, and crisis out-of-band channel design. Communication infrastructure that stays available and private when your primary platform is compromised.
Module 2 — M365 Identity Security
Full identity census, Conditional Access architecture, MFA enforcement, legacy auth elimination, PIM deployment, and PULSAR audit log intelligence for your M365 tenant.
Module 3 — M365 Security Hardening
Exchange Online Protection tuning, mailbox auditing, Unified Audit Log forwarding, Secure Score baseline, ASR rules, and ASTRAL configuration capture — no new licensing required for E3 clients.
Module 4 — Data Governance & Compliance
Sensitivity label deployment, retention policies, DLP, eDiscovery readiness, Teams governance, and SharePoint external sharing controls. Regulatory evidence produced as a natural output.
Module 5 — AI Sovereignty Bridge
Shadow AI inventory, Azure OpenAI deployment with private endpoints, Conditional Access for AI tools, first RAG pipeline on proprietary data, and AI governance policy.
Module 6 — On-Premises AD & Endpoint Hardening
Full AD identity census, password audit of compromised credentials, KRBTGT rotation, LAPS, Sysmon, PAW architecture, and Entra Connect hardening for hybrid environments.
Module 7 — Recovery & Resilience
Backup architecture review, immutable backup deployment, disaster recovery runbooks, tabletop exercise, and ASTRAL baseline as rebuild blueprint. Tested recovery, not assumed.
Module 8 — Threat & Vulnerability Management
Network interdiction for the exploitation-first era. Minimum-cost cuts instead of CVSS lists, the ~90% subtraction, hour/day/sprint cuts, and the Kill Chain Assessment app.
Module 9 — Organisational Resilience
Dev/Sec/Ops merger, shift-left security integration, process assurance for teams feeling out of control, and embedded security review in the delivery pipeline.