Consulting Module

Module 12 โ€” T0 Asset Protection

A T0 asset is not merely important. It is existential โ€” its compromise does not cause downtime, it causes dissolution. Most organisations have never explicitly classified which assets belong here, which means they have never specifically protected them.

What It Delivers

๐Ÿ†

T0 Asset Classification

Every asset classified into tiers: T0 (existential โ€” compromise destroys the operation), T1 (critical โ€” material harm), T2 (important โ€” significant disruption), T3 (standard). Classification is not a spreadsheet exercise โ€” it is a conversation about what the organisation genuinely cannot operate without. Domain controllers, ADCS, the Entra Connect sync server, cryptographic key material, and the systems that hold sovereign intelligence all belong at T0.

๐Ÿ›ก๏ธ

Crown Jewel Protection Architecture

A protection design for each T0 asset: access controls, network segmentation, monitoring requirements, and privilege boundaries. The architecture's primary constraint is that T0 must never be reachable from the compromise of a T1 or T2 system. If an attacker owns a member server, they should not be able to reach a domain controller. If they compromise an admin laptop, they should not reach the ADCS root.

๐Ÿ”’

Privilege Tier Enforcement

Administrative access enforced per tier โ€” T0 administrators use dedicated, hardened workstations and dedicated accounts that do not log in to T1 or T2 systems. Service accounts that currently span tiers identified and decomposed. Entra Connect sync server permissions tightened so the bridge between on-premises T0 and the cloud tenant cannot be weaponised.

๐Ÿ“ก

T0 Monitoring and Alert Design

Custom detection rules scoped specifically to T0 assets โ€” any authentication attempt, any privilege escalation, any configuration change on a T0 system generates a high-fidelity alert that reaches a human immediately. Noise from T1 and T2 does not bury T0 signals.

The Kill Chain Connection

The Kill Chain Assessment app from Module 0 identifies which assets are crown jewels โ€” the end of the kill chain. Module 12 builds the architecture that ensures an attacker cannot reach them even after compromising entry-level systems. Together, Module 0 finds the path and Module 12 removes it at the structural level.

Scope and Prerequisites

Duration30โ€“60 days
EnvironmentAny
PrerequisitesModule 0 (Diagnostic) to identify crown jewels; Module 6 if on-premises AD is in scope
Natural follow-onModule 13 (Privileged Access Architecture) for the PAM layer that enforces the tier boundaries in practice

Protect what the organisation cannot lose

Everything else can be rebuilt. T0 assets cannot. Module 12 ensures the architecture reflects that distinction.