Every engagement begins with the Brownhat Diagnostic (Module 0): a structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised module roadmap. The diagnostic is a paid, bounded engagement and delivers value regardless of whether further work follows.
Brownhat Diagnostic
Structured two-day NIST CSF 2.0 baseline assessment. Honest picture of your security posture, prioritised gap list, and recommended module sequence. Kill chain synthesis using the Kill Chain Assessment app — maps the unknown estate into an attack graph, computes the cheapest paths to existential impact, and sizes the remediation into hour, day, and sprint cuts. Entry point for every new client.
Endpoint Management Foundation
Device inventory and enrollment, compliance baseline, shadow IT discovery, basic conditional access integration, ASTRAL deployment for Intune drift detection. Full device visibility in 30–45 days.
M365 Identity Security
Full identity census, Conditional Access policy register, MFA enforcement, legacy auth blocked, PIM deployment or JIT process, PULSAR for audit log intelligence, guest access audit and governance.
M365 Security Hardening
Exchange Online Protection tuning, mailbox auditing, Unified Audit Log forwarding, Secure Score baseline and improvement plan, ASR rules, ASTRAL baseline capture. No new licensing required for E3 clients.
Data Governance & Compliance
Sensitivity label deployment, retention policies for all M365 workloads, DLP policies, eDiscovery readiness, Teams governance, SharePoint site provisioning. Regulatory evidence produced as a natural output.
AI Sovereignty Bridge
Shadow AI inventory, Azure OpenAI deployment with private endpoints, conditional access for AI tools, first RAG pipeline or fine-tuned model on proprietary data, AI governance policy. Your intelligence stays yours.
On-Premise AD & Endpoint Hardening
Full AD identity census with orphan and privilege analysis, password audit of compromised credentials (Elysium), KRBTGT rotation, LAPS, Sysmon, PAW architecture, Azure AD Connect hardening.
Recovery & Resilience
Backup architecture review and remediation, immutable backup deployment, disaster recovery runbooks, tabletop exercise, ASTRAL baseline as rebuild blueprint. Tested recovery, not assumed.
Threat & Vulnerability Management
Network interdiction for the exploitation-first era. Graph position, reachability, and exploit availability replace CVSS as the sort key. The ~90% subtraction removes net-negative work — leaving the few interventions that actually sever mapped paths. Five classes of work: hour-cuts (compensating control, not the patch), day-cuts, sprint-cuts, dark (routed to discovery), and an explicitly declined class. Zero-budget discovery with osquery and scripts. The Kill Chain Assessment app maps the attack graph and computes the minimum-cost cut; cut depth (κ) is the programme metric.
Organisational Resilience
Dev/Sec/Ops merger, shift-left security integration, process assurance for teams feeling "not in control", quality management engagement, embedded security review in the delivery pipeline.
Red Team & Validation
Assumption validation after hardening modules. Targeted adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Measures real security improvement, not compliance scores.
Blue/Purple Team Foundation
Building defensive capability from existing tool investments. Detection engineering, alert tuning, SIEM rule development, threat hunting playbooks. Your existing tools, made to actually work.
T0 Asset Protection
Tier 0 asset classification across identity, infrastructure, and data. Protection architecture for crown-jewel assets. Privileged access design ensuring Tier 0 is never reachable from Tier 1 or 2 compromise.
Privileged Access Architecture
PAM design using Teleport, Tailscale/Headscale, and JIT access. Vendor remote access governance. Ephemeral credentials, session recording, and access reviews. Zero standing access where possible.
Sovereign Communications
Delta Chat chatmail relay, Matrix/Element deployment, crisis out-of-band channel design. Communication infrastructure that remains available and private even if your primary collaboration platform is compromised.
Not sure where to start?
The Brownhat Diagnostic maps your current posture to a prioritised module sequence. It is a bounded, fixed-price engagement and delivers value regardless of whether further work follows.