Consulting Module

Module 0 — Brownhat Diagnostic

Before any module recommendation, we need an honest picture of where you actually stand. The Brownhat Diagnostic is a structured two-day workshop — no tools installed, no scanning — that produces the clearest picture of your security posture and what matters most to fix.

What the Diagnostic Produces

📋

NIST CSF 2.0 Gap Report

An honest scoring of your posture across all six CSF 2.0 functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — with the gaps that matter most clearly separated from the ones that don't.

🗺️

Kill Chain Map

Using the Kill Chain Assessment app, we model your environment as an attack graph during the diagnostic. The app computes the cheapest adversary paths from entry points to your crown jewels — and the minimum-cost cut: the smallest priced set of interventions that severs every mapped path. That cut, not a severity list, is what the plan is built on.

Cut-Sized Remediation Plan

Every intervention is sized into a cut class: hour-cut (compensating control now, not the patch), day-cut (one change window), sprint-cut (normal engineering rhythm), or dark (needs discovery first). You leave with a plan ordered by time-to-existential-impact, not by CVSS score.

📦

Prioritised Module Roadmap

A recommended sequence of modules derived directly from your gap picture and kill chain. Not a generic framework recommendation — a sequence built on what we actually found in your environment.

How It Works

The Diagnostic is a two half-day structured workshop with your IT lead, a business process owner, and whoever is accountable for security decisions. No homework before. No questionnaire to fill in. Pre-filled questionnaires produce aspirational answers; the workshop produces honest ones.

Session 1 — Context and Foundation: GOVERN and IDENTIFY domains. Who is accountable for security, how decisions are made, what assets exist, and how risk is assessed. This is where the governance gaps surface — usually faster than clients expect.

Session 2 — Controls, Detection, and Recovery: PROTECT, DETECT, RESPOND, and RECOVER. What controls are actually in place and enforced (not just configured), how alerts are handled, how incidents are managed, and whether recovery has ever been tested. Kill chain synthesis runs in parallel as findings accumulate.

What we do not do: install tools, collect data from systems, or make recommendations before the picture is complete. We earn the right to recommend by understanding the environment first.

Deliverables

Everything goes to your repository. At the end of the two days you receive:

  • NIST CSF 2.0 gap report (strengths, gaps, severity ratings)
  • Kill chain diagram and minimum-cost cut analysis
  • Remediation priorities sized into cut classes (hour / day / sprint / dark)
  • Module roadmap with recommended sequencing and rationale
  • Findings backlog seeded and ready for the housekeeping stream

Scope and Prerequisites

Duration2 half-days (4 hours each)
FormatIn-person strongly preferred; remote with camera-on acceptable
Who attendsIT lead, executive sponsor (mandatory); business process owner (recommended)
PrerequisitesNone — this is the starting point
Follow-onDelivers a module roadmap; further modules are optional

The Diagnostic is a bounded, fixed-price engagement. It delivers value regardless of whether further work follows. We have never run a diagnostic that did not surface something the client did not know.

Start here

Every engagement begins with the Brownhat Diagnostic. It is the only honest way to select a module sequence.