What the Diagnostic Produces
NIST CSF 2.0 Gap Report
An honest scoring of your posture across all six CSF 2.0 functions — GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER — with the gaps that matter most clearly separated from the ones that don't.
Kill Chain Map
Using the Kill Chain Assessment app, we model your environment as an attack graph during the diagnostic. The app computes the cheapest adversary paths from entry points to your crown jewels — and the minimum-cost cut: the smallest priced set of interventions that severs every mapped path. That cut, not a severity list, is what the plan is built on.
Cut-Sized Remediation Plan
Every intervention is sized into a cut class: hour-cut (compensating control now, not the patch), day-cut (one change window), sprint-cut (normal engineering rhythm), or dark (needs discovery first). You leave with a plan ordered by time-to-existential-impact, not by CVSS score.
Prioritised Module Roadmap
A recommended sequence of modules derived directly from your gap picture and kill chain. Not a generic framework recommendation — a sequence built on what we actually found in your environment.
How It Works
The Diagnostic is a two half-day structured workshop with your IT lead, a business process owner, and whoever is accountable for security decisions. No homework before. No questionnaire to fill in. Pre-filled questionnaires produce aspirational answers; the workshop produces honest ones.
Session 1 — Context and Foundation: GOVERN and IDENTIFY domains. Who is accountable for security, how decisions are made, what assets exist, and how risk is assessed. This is where the governance gaps surface — usually faster than clients expect.
Session 2 — Controls, Detection, and Recovery: PROTECT, DETECT, RESPOND, and RECOVER. What controls are actually in place and enforced (not just configured), how alerts are handled, how incidents are managed, and whether recovery has ever been tested. Kill chain synthesis runs in parallel as findings accumulate.
What we do not do: install tools, collect data from systems, or make recommendations before the picture is complete. We earn the right to recommend by understanding the environment first.
Deliverables
Everything goes to your repository. At the end of the two days you receive:
- NIST CSF 2.0 gap report (strengths, gaps, severity ratings)
- Kill chain diagram and minimum-cost cut analysis
- Remediation priorities sized into cut classes (hour / day / sprint / dark)
- Module roadmap with recommended sequencing and rationale
- Findings backlog seeded and ready for the housekeeping stream
Scope and Prerequisites
| Duration | 2 half-days (4 hours each) |
| Format | In-person strongly preferred; remote with camera-on acceptable |
| Who attends | IT lead, executive sponsor (mandatory); business process owner (recommended) |
| Prerequisites | None — this is the starting point |
| Follow-on | Delivers a module roadmap; further modules are optional |
The Diagnostic is a bounded, fixed-price engagement. It delivers value regardless of whether further work follows. We have never run a diagnostic that did not surface something the client did not know.
Start here
Every engagement begins with the Brownhat Diagnostic. It is the only honest way to select a module sequence.