Two capability frameworks that underpin every playbook — detection engineering for finding threats, investigation automation for understanding them.
Detection Engineering
From artisan rules to deployable artifacts. Signal quality ratio, three detection tiers, CI/CD pipeline for detection lifecycle.
Investigation Automation
Context assembly, not playbook execution. Why SOAR fails at scale, the three-layer framework, what makes multi-tenant investigation hard.
Five OODA Loops
Security has not one but five distinct decision loops, each with different cycle times. The fastest loop protects the slower loops. Every playbook below is structured around these five loops.
Each layer is a decision cycle with its own tempo.
The Principle
If containment (loop 1) is fast enough, you buy time for everything downstream. If detection (loop 2) is good enough, containment triggers early and blast radius stays small. This cascading protection is why a breach becomes a bounded incident rather than an existential crisis.
Three Tiers Per Loop
Quick wins — free, deployable today, no vendor required.
Core engagement — consulting deliverable, expert-led, scoped and priced.
Target state — the architectural endgame that makes the threat structurally difficult.
The Goal: Make DFIR the Exception, Not the Plan
The playbook architecture flips this:
| Layer | What It Does | Effect on DFIR Need |
|---|---|---|
| 365 days compressed on-host Raw logs, cheap storage |
Forensic evidence always exists. Windows Event Log at 1GB+ per channel, Linux syslog 12 months, on every server. Compressed, not indexed. Costs less than a coffee per day per server. | If you DO need DFIR, you hand them a complete evidence package instead of "we don't have logs from before Tuesday." |
| 30–90 days in SIEM Normalized, tagged, searchable |
Detection rules run here. Alerts fire here. Wazuh (free) or equivalent. Tuned to the 15 specific settings from breach forensics — not generic "detect everything." | You detect lateral movement at hour 2, not day 14. The detection window closes before DFIR is needed. |
| Detection rules tuned to real breaches The 15 settings, not 10,000 CIS checks |
Legacy auth attempts, MFA bypass patterns, RDP lateral movement, shadow copy deletion, backup agent termination, off-hours admin activity, AD CS abuse, credential stuffing. | Catches the specific attack patterns that show up in 59–84% of real incidents. Not noise — signal. |
| 24/7 automated investigation Investigation automation |
Investigates every alert with auditable reasoning. Works at 2 AM Saturday when 88% of ransomware deploys. Contains automatically or escalates with complete investigation report. Containment is scoped at least as wide as the attacker could be, so a second foothold isn't left live while the first is cut. | Containment happens in minutes, not days. The attacker is evicted before they reach the encryption phase. DFIR is never called. |
| Every incident feeds the slow loops Machines collect, humans curate |
Each closed case is mined for how the attacker got in, what detection missed, and which visibility or process gaps slowed the response. Those go to the patching, posture, detection and architecture backlogs. Indicators become intelligence only after an analyst checks them and gives each one a date, a source, an expiry and a confidence level. | The same intrusion doesn't work twice. Each incident removes a path instead of just closing a ticket, so fewer incidents reach DFIR. |
Applied Playbooks
Each playbook applies the detection engineering and investigation automation methodology to a specific threat domain.
Loop 0: The Foundation — Hard Barriers
Before any threat-specific playbook, these three controls must be in place. They are chosen for one property: each one refuses the attacker's action rather than slowing it down. That is the doctrine for Loop 0 — invest in hard barriers first, treat friction as a bonus.
| Friction — slows the attacker | Hard barrier — refuses the attacker |
|---|---|
| Non-standard ports, renamed Administrator, hidden banners | Default-deny firewall rules between zones: workstations cannot reach domain-controller admin ports |
| TOTP codes and push approvals — phishable, they add effort | FIDO2 / passkeys — the key will not sign for a lookalike domain |
| Backups that are hidden, or "hard to find" on the network | WORM / Object Lock storage with separate backup credentials — deletion is refused, not delayed |
| Rate limits, CAPTCHAs, lockout thresholds, code obfuscation | Memory protections (W^X, KASLR) and memory-safe languages that remove a bug class |
Immutable Backups
3-2-1-1 architecture, WORM storage, tested restores. The control that makes ransomware a recoverable event, not an existential one. Includes backup kill chain analysis and management AD architecture.
The barrier: the storage layer refuses deletion, even for an admin. Hidden or obscure backups are only friction.
Network Segmentation
3-4 VLANs minimum. Workstations, servers, backup infrastructure, management. Default deny between zones. The compensating control when you can't patch fast enough — limits blast radius to one segment.
The barrier: a deny rule leaves nothing to grind through, only a different path to find. VLANs without enforced rules between them are friction.
Identity Hardening
MFA everywhere. FIDO2 for admins. Separate admin accounts. LAPS for local admin. Block legacy auth. 56% of breaches start with stolen credentials — this is where you stop them.
The barrier: phishing-resistant FIDO2 and blocked legacy auth. TOTP and push MFA are friction — better than nothing, but phishable.
Threat-Specific Playbooks
BEC Defense
Email Resilience Program. Universal impersonation protection with silent quarantine, FIDO2, browser isolation, CDR, behavioral AI. The four-layer stack that breaks attacker economics.
Ransomware Resilience
Recovery Without Paying. Patterson Cake containment playbooks (Kill Internet + Kill Authentication), immutable backups, EDR, segmentation. Insurance readiness checklist.
Supply Chain Security
Your Vendors Are Your Attack Surface. MSP access hardening, OAuth lockdown, SaaS sprawl discovery, vendor breach response playbook. NIS2 Article 21(d) compliance.
Cloud Security
Four Things That Matter: Auth, Keys, Permissions, Exposure. IP-bound API keys, managed identities, least privilege, public access prevention. Big 3 + mid-market provider guidance.
Posture & Operations
Configuration Drift
Stop Defending What You've Already Disabled. Shift down, not shift left — wire security into the platform so teams get it for free. Configuration-as-code for M365. Breach-forensic-driven priority list.
VM & Patching
Easy vs Hard. CISA KEV + EPSS prioritization replaces CVSS score chasing. Edge devices first (44% of zero-days). Auto-update what you can, segment what you can't.
Log Management
Keep data for the need, not the architecture. Four copies already exist — on-host, cloud native, backup, SIEM. Right-size your SIEM for detection (30–90d), not storage. €50–150/month vs €10K enterprise.
Risk Quantification & Assessment
Before you start fixing things, you need to know where you stand and what an incident actually costs. These tools give you the numbers — no email gates, no telemetry, no accounts required.
Security Self-Assessment
Evidence-based posture check. Tier A: instant email security analysis via DNS (SPF, DMARC, MX). Tier B: paste command output for identity and logging checks (MFA exceptions, legacy auth, stale admins, forwarding rules, event log sizing). All client-side — nothing leaves your browser.
PHOSI Calculator
Potential Harm Of Security Incident. Interactive risk quantification tool that calculates the business impact of a security incident based on your specific organization: revenue, data sensitivity, regulatory exposure, reputation risk. Produces a scored risk matrix with annual cost projections.
Incident Severity Scoring
8-dimension weighted severity assessment based on CISA NCISS methodology. Score operational continuity, data exposure, threat activity, asset criticality, threat sophistication, recovery complexity, attack progression, and control effectiveness. Includes materiality flags for governance escalation. All client-side.
How PHOSI Connects to the Playbooks
PHOSI answers "how bad could it be?" for your specific organization. The playbooks answer "what do we do about it?" Use PHOSI to:
1. Prioritize which playbook to start with — if your PHOSI score for data breach is higher than ransomware, start with BEC Defense and Cloud Security before Ransomware Resilience.
2. Justify the investment — the PHOSI annual cost projection vs. the playbook investment makes the ROI conversation concrete, not theoretical.
3. Report to the board — PHOSI produces a one-page risk summary that non-technical executives understand. Pair with playbook progress reports for quarterly board updates.
The Free Tool Stack (referenced across all playbooks)
The Mid-Market Gap
Enterprise has 24/7 SOCs, dedicated DFIR teams, and seven-figure security budgets. Small business has nothing and accepts the risk. Mid-market (50–500 employees) is stuck in between: big enough to be targeted, too small for enterprise tools, and often relying on an MSP who has domain admin on everything.
These playbooks close that gap with three layers: free tools you deploy this week, consulting engagements that build the architecture, and automation that keeps it running 24/7 without a SOC team.
NIS2 + Insurance = The Forcing Function
NIS2 mandates risk management measures including incident handling, business continuity, supply chain security, and access control. Compliance deadline: October 2026. Penalties: up to 10M EUR or 2% of global turnover.
Cyber insurance underwriters now require MFA, EDR, immutable backups, tested IR plans, and patch management evidence. 41% of applications denied on first submission. 82% of denied claims had no MFA.
Every playbook maps to both. Build once, satisfy both.