Proactive engagement / 03

Cyber Defense

Assurance Program.

A multi-year program whose hours are spent entirely on making a serious incident less likely, and less damaging if one still arrives.

Layered defense is built for the attacker who arrives at the perimeter and works inward. Most no longer do. A credential that already works crosses no layer at all, and an attack aimed at the backup infrastructure and the domain controllers goes straight at the systems everything else depends on. Depth closes neither route.

The program buys proactive work and nothing else. No hours are held back for incident response, because response is a separate instrument with a separate job. The hours go to the engagements that move the posture: threat landscape research, offensive engagements, detection engineering, continuous compromise assessment, readiness, and recovery assurance.

The mix is set by your maturity rather than by a package. A low-maturity estate buys hardening first; a mature one buys depth. Either way a senior consultant is embedded for the term, the Virtual Principal Consultant, accountable for the program from the first cycle to the last.

Multi-yearProgram term, by design
Proactive onlyNo hours held back for response
5 of 5NIST functions owned, not one
EmbeddedVirtual Principal Consultant, start to finish

This is not an incident response retainer and does not replace one. Where both are held, the retainer answers the incident and the program reduces how often one arrives. The two are compared further down this page.

[ HOW COMPROMISES BEGIN ]

One missed defense is one opportunity.

Every user with an email account, every website, API and public interface is part of your attack surface. So is every VPN and remote access gateway, every cloud tenant and the identities that sign in to it, every supplier with a connection into your estate, every piece of software you buy and the updates that come with it, and every help desk that can reset a password. Each one is a potential way in.

One missed defense is one opportunityIllustration: an organization shown as its crown jewels, inside its estate, inside a ring of internet-exposed points: website, APIs, public interfaces, software and updates, suppliers, help desk, identities, cloud tenant, VPN and remote access, and email users. Attempts arrive continuously, colored by kind, and die at the edge. At random intervals one connects and a path forms from that exposure point through the estate to the crown jewels. Every exposure point has its own route inward, drawn in gold once it gets through, with every node it passes turned red; some email attacks are contained at the endpoint. THE ATTACK SURFACE most attempts die at the edge. One is enough. EXPOSED TO THE INTERNET YOUR ESTATE Crown jewels Backups Servers Databases Instrumentation SaaS apps Cloud data Domain controller Endpoints Website APIs Public interfaces Software and updates Suppliers Help desk Identities Cloud tenant VPN and remote access Email users Every point leads inwardeach exposure connects to something inside the estate Illustration of the pattern, not live data.

What the program runs

Five functions, and something that owns each one.

Every workstream owns one NIST function outright and contributes to a second. Run together they close the routes above.

Nothing here is scheduled because the calendar says so; a workstream runs at the frequency its own findings decay at.

WHAT THE PROGRAM RUNS six workstreams, five functions, and how often each one runs IDENTIFY PROTECT DETECT RESPOND RECOVER CADENCE Threat landscape research exposure, leaked credentials, who targets you continuous OWNS Offensive engagements attack paths, inside and out, to tier zero each cycle adds OWNS Detection engineering log sources, use cases, playbooks attached continuous OWNS adds Continuous compromise assessment selected hunts, to forensic depth on a cycle OWNS adds Readiness IR plan, table-top, DFIR functional scheduled OWNS adds Recovery assurance backup design, restoration against SLA, runbooks periodic adds OWNS Every hour is spent before an incident, and the mix is set by your maturity rather than by a package.

What improves

Fewer ways in, and the ones left are watched.

Each cycle leaves the estate harder to enter and the team quicker to notice when someone tries.

Reduced attack surface Attack paths found in one cycle are closed before the next, so there are fewer ways in at the end of the term than at the start.
Intrusions found earlier Detection built from your own threat landscape, and hunts taken to forensic depth, find an actor already inside on a regular cycle.
Reliable recovery Restoration is tested against the SLA, so the recovery time you plan around has been measured.
A team immediately ready The plan, the exercises and the detection content stay with your people, so when something happens they already know what to do.
Insights a board can act on Posture is reported from what was tested and what was found, the form a board, an insurer or a regulator asks for.
Budget aligned to current risk The plan is revised every cycle against what the last one found, so effort moves to where the exposure is now.

Who this is for

Where the conversation usually starts.

A retainer that changed nothing Organizations holding a DFIR retainer who have noticed that it answers incidents without reducing them.
Budget spent reacting Security functions whose spend is consumed by the last incident, with nothing left to prevent the next.
An assurance the board asked for Leadership told the posture is sound, who want that established against evidence rather than against a control inventory.
Uneven maturity Estates where one domain is strong and another is untouched, so any fixed package fits neither.

What is needed to scope a program

These are enough to shape a term.

Environment size How many endpoints and how many users.
What exists today Which security functions are running, and who owns each one.
Response arrangements Whether a DFIR retainer is already in place, since that changes what the program does not need to carry.
Term How many years, because the mix is sequenced across the term rather than delivered at once.

NEXT / WHEN IT IS REAL

Digital Forensics and Incident Response

The response instrument this program is designed to be needed less often.

NEXT / SCOPING

Engage

Describe the situation. The call is with the consultant who would run the assessment, not a salesperson.