Modular Engagements

Consulting Modules

Every module stands alone. Every module makes the next one easier. Start where the pain is highest — not where the framework says you should.

Every engagement begins with the Brownhat Diagnostic (Module 0): a structured two-day NIST CSF 2.0 baseline assessment that produces a prioritised module roadmap. The diagnostic is a paid, bounded engagement and delivers value regardless of whether further work follows.

Module 0

Brownhat Diagnostic

Structured two-day NIST CSF 2.0 baseline assessment. Honest picture of your security posture, prioritised gap list, and recommended module sequence. Kill chain synthesis using the Kill Chain Assessment app — maps the unknown estate into an attack graph, computes the cheapest paths to existential impact, and sizes the remediation into hour, day, and sprint cuts. Entry point for every new client.

2 days All clients
Module 1

Endpoint Management Foundation

Device inventory and enrollment, compliance baseline, shadow IT discovery, basic conditional access integration, ASTRAL deployment for Intune drift detection. Full device visibility in 30–45 days.

30–45 days M365 E3+
Module 2

M365 Identity Security

Full identity census, Conditional Access policy register, MFA enforcement, legacy auth blocked, PIM deployment or JIT process, PULSAR for audit log intelligence, guest access audit and governance.

30–60 days M365 E3+
Module 3

M365 Security Hardening

Exchange Online Protection tuning, mailbox auditing, Unified Audit Log forwarding, Secure Score baseline and improvement plan, ASR rules, ASTRAL baseline capture. No new licensing required for E3 clients.

30–60 days No new spend
Module 4

Data Governance & Compliance

Sensitivity label deployment, retention policies for all M365 workloads, DLP policies, eDiscovery readiness, Teams governance, SharePoint site provisioning. Regulatory evidence produced as a natural output.

45–90 days NIS2 · DORA · GDPR
Module 5

AI Sovereignty Bridge

Shadow AI inventory, Azure OpenAI deployment with private endpoints, conditional access for AI tools, first RAG pipeline or fine-tuned model on proprietary data, AI governance policy. Your intelligence stays yours.

30–60 days Azure
Module 6

On-Premise AD & Endpoint Hardening

Full AD identity census with orphan and privilege analysis, password audit of compromised credentials (Elysium), KRBTGT rotation, LAPS, Sysmon, PAW architecture, Azure AD Connect hardening.

45–60 days Hybrid identity
Module 7

Recovery & Resilience

Backup architecture review and remediation, immutable backup deployment, disaster recovery runbooks, tabletop exercise, ASTRAL baseline as rebuild blueprint. Tested recovery, not assumed.

30–60 days Ransomware-resilient
Module 8

Threat & Vulnerability Management

Network interdiction for the exploitation-first era. Graph position, reachability, and exploit availability replace CVSS as the sort key. The ~90% subtraction removes net-negative work — leaving the few interventions that actually sever mapped paths. Five classes of work: hour-cuts (compensating control, not the patch), day-cuts, sprint-cuts, dark (routed to discovery), and an explicitly declined class. Zero-budget discovery with osquery and scripts. The Kill Chain Assessment app maps the attack graph and computes the minimum-cost cut; cut depth (κ) is the programme metric.

45–90 days Open-source first
Module 9

Organisational Resilience

Dev/Sec/Ops merger, shift-left security integration, process assurance for teams feeling "not in control", quality management engagement, embedded security review in the delivery pipeline.

60–90 days Culture + process
Module 10

Red Team & Validation

Assumption validation after hardening modules. Targeted adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Measures real security improvement, not compliance scores.

15–30 days Post-hardening
Module 11

Blue/Purple Team Foundation

Building defensive capability from existing tool investments. Detection engineering, alert tuning, SIEM rule development, threat hunting playbooks. Your existing tools, made to actually work.

45–90 days Existing tools
Module 12

T0 Asset Protection

Tier 0 asset classification across identity, infrastructure, and data. Protection architecture for crown-jewel assets. Privileged access design ensuring Tier 0 is never reachable from Tier 1 or 2 compromise.

30–60 days Architecture
Module 13

Privileged Access Architecture

PAM design using Teleport, Tailscale/Headscale, and JIT access. Vendor remote access governance. Ephemeral credentials, session recording, and access reviews. Zero standing access where possible.

45–60 days Open-source PAM
Module 14

Sovereign Communications

Delta Chat chatmail relay, Matrix/Element deployment, crisis out-of-band channel design. Communication infrastructure that remains available and private even if your primary collaboration platform is compromised.

15–30 days Self-hosted

Not sure where to start?

The Brownhat Diagnostic maps your current posture to a prioritised module sequence. It is a bounded, fixed-price engagement and delivers value regardless of whether further work follows.