What It Delivers
T0 Asset Classification
Every asset classified into tiers: T0 (existential โ compromise destroys the operation), T1 (critical โ material harm), T2 (important โ significant disruption), T3 (standard). Classification is not a spreadsheet exercise โ it is a conversation about what the organisation genuinely cannot operate without. Domain controllers, ADCS, the Entra Connect sync server, cryptographic key material, and the systems that hold sovereign intelligence all belong at T0.
Crown Jewel Protection Architecture
A protection design for each T0 asset: access controls, network segmentation, monitoring requirements, and privilege boundaries. The architecture's primary constraint is that T0 must never be reachable from the compromise of a T1 or T2 system. If an attacker owns a member server, they should not be able to reach a domain controller. If they compromise an admin laptop, they should not reach the ADCS root.
Privilege Tier Enforcement
Administrative access enforced per tier โ T0 administrators use dedicated, hardened workstations and dedicated accounts that do not log in to T1 or T2 systems. Service accounts that currently span tiers identified and decomposed. Entra Connect sync server permissions tightened so the bridge between on-premises T0 and the cloud tenant cannot be weaponised.
T0 Monitoring and Alert Design
Custom detection rules scoped specifically to T0 assets โ any authentication attempt, any privilege escalation, any configuration change on a T0 system generates a high-fidelity alert that reaches a human immediately. Noise from T1 and T2 does not bury T0 signals.
The Kill Chain Connection
The Kill Chain Assessment app from Module 0 identifies which assets are crown jewels โ the end of the kill chain. Module 12 builds the architecture that ensures an attacker cannot reach them even after compromising entry-level systems. Together, Module 0 finds the path and Module 12 removes it at the structural level.
Scope and Prerequisites
| Duration | 30โ60 days |
| Environment | Any |
| Prerequisites | Module 0 (Diagnostic) to identify crown jewels; Module 6 if on-premises AD is in scope |
| Natural follow-on | Module 13 (Privileged Access Architecture) for the PAM layer that enforces the tier boundaries in practice |
Protect what the organisation cannot lose
Everything else can be rebuilt. T0 assets cannot. Module 12 ensures the architecture reflects that distinction.