Proactive engagement / 03
Assurance Program.
A multi-year program whose hours are spent entirely on making a serious incident less likely, and less damaging if one still arrives.
Layered defense is built for the attacker who arrives at the perimeter and works inward. Most no longer do. A credential that already works crosses no layer at all, and an attack aimed at the backup infrastructure and the domain controllers goes straight at the systems everything else depends on. Depth closes neither route.
The program buys proactive work and nothing else. No hours are held back for incident response, because response is a separate instrument with a separate job. The hours go to the engagements that move the posture: threat landscape research, offensive engagements, detection engineering, continuous compromise assessment, readiness, and recovery assurance.
The mix is set by your maturity rather than by a package. A low-maturity estate buys hardening first; a mature one buys depth. Either way a senior consultant is embedded for the term, the Virtual Principal Consultant, accountable for the program from the first cycle to the last.
This is not an incident response retainer and does not replace one. Where both are held, the retainer answers the incident and the program reduces how often one arrives. The two are compared further down this page.
Every user with an email account, every website, API and public interface is part of your attack surface. So is every VPN and remote access gateway, every cloud tenant and the identities that sign in to it, every supplier with a connection into your estate, every piece of software you buy and the updates that come with it, and every help desk that can reset a password. Each one is a potential way in.
What the program runs
Every workstream owns one NIST function outright and contributes to a second. Run together they close the routes above.
Nothing here is scheduled because the calendar says so; a workstream runs at the frequency its own findings decay at.
What improves
Each cycle leaves the estate harder to enter and the team quicker to notice when someone tries.
Who this is for
What is needed to scope a program
NEXT / WHEN IT IS REAL
Digital Forensics and Incident ResponseThe response instrument this program is designed to be needed less often.
NEXT / SCOPING
EngageDescribe the situation. The call is with the consultant who would run the assessment, not a salesperson.