Defense Architecture
Five OODA Loops
Security has not one but five distinct decision loops, each with different cycle times. The fastest loop protects the slower loops. Every playbook below is structured around these five loops.
Respond
Incident Response Playbooks
It is happening now. Timed steps with the reason for each, a "How far has it got?" question list for triage, and a matching TheHive case template. Everything below this section is how you get ready.
Ransomware Response
The first 72 hours, by scenario: encryption in progress, discovered before encryption, data theft without encryption, hypervisor/NAS, backups destroyed, cloud data held hostage. Isolate, don't power off; protect the way back; the board's pay/don't-pay facts.
BEC Response
Compromised mailbox, payment in flight. Money first, then mailbox: bank recall, capture-then-purge rules, tenant sweep, and who to warn.
Identity Breach Response
You're already compromised — what to do in the next 15 minutes, 4 hours, 30 days. T+0 containment commands, 8 incident-type variations (account takeover, device-code, OAuth abuse, NHI, privileged). Password reset is not remediation.
Device Code Abuse Response
Device-code phishing confirmed or suspected. The 12-step containment checklist: revoke before reset, kill device registrations, audit OAuth consent, hunt tenant-wide.
Supply Chain Incident Response
A vendor disclosed a breach, or a package or update you install shipped malicious code. Vendor track: validate, suspend data flows, revoke every credential they hold. Package track: find everywhere it was installed, pin, and rotate every secret it could read.
Cloud Incident Response
An attacker in AWS, Azure or GCP. Keep the logs running, revoke the credential and the sessions it already minted, quarantine the account when the scope is unknown, and hunt every key, role and trust they created. Leaked keys, cryptomining, storage theft or hostage, compromised workloads and pipelines, root or tenant admin.
ClickFix Response
A user pasted a fake-CAPTCHA command. Isolate, capture the command from RunMRU or the PowerShell history, revoke every session the stealer took, and decide whether it is a stealer or a foothold.
Prevent — Loop 0
The Foundation: Hard Barriers
Before any threat-specific playbook, these three controls must be in place. They are chosen for one property: each one refuses the attacker's action rather than slowing it down. That is the doctrine for Loop 0 — invest in hard barriers first, treat friction as a bonus.
| Friction — slows the attacker | Hard barrier — refuses the attacker |
|---|---|
| Non-standard ports, renamed Administrator, hidden banners | Default-deny firewall rules between zones: workstations cannot reach domain-controller admin ports |
| TOTP codes and push approvals — phishable, they add effort | FIDO2 / passkeys — the key will not sign for a lookalike domain |
| Backups that are hidden, or "hard to find" on the network | WORM / Object Lock storage with separate backup credentials — deletion is refused, not delayed |
| Rate limits, CAPTCHAs, lockout thresholds, code obfuscation | Memory protections (W^X, KASLR) and memory-safe languages that remove a bug class |
Immutable Backups
3-2-1-1 architecture, WORM storage, tested restores. The control that makes ransomware a recoverable event, not an existential one. Includes backup kill chain analysis and management AD architecture.
The barrier: the storage layer refuses deletion, even for an admin. Hidden or obscure backups are only friction.
Network Segmentation
3-4 VLANs minimum. Workstations, servers, backup infrastructure, management. Default deny between zones. The compensating control when you can't patch fast enough — limits blast radius to one segment.
The barrier: a deny rule leaves nothing to grind through, only a different path to find. VLANs without enforced rules between them are friction.
Identity Hardening
MFA everywhere. FIDO2 for admins. Separate admin accounts. LAPS for local admin. Block legacy auth. 56% of breaches start with stolen credentials — this is where you stop them.
The barrier: phishing-resistant FIDO2 and blocked legacy auth. TOTP and push MFA are friction — better than nothing, but phishable.
Prevent — Threat Domains
Threat-Specific Playbooks
Each playbook addresses a specific threat across all five OODA loops, with free afternoon deploys, core consulting engagements, and target-state architecture. The matching response playbooks are under Respond above.
BEC Defense
Email Resilience Program. Universal impersonation protection with silent quarantine, FIDO2, browser isolation, CDR, behavioral AI. The four-layer stack that breaks attacker economics.
Identity Hardening
Defense in depth for the identity layer itself. FIDO2 universal, Conditional Access architecture, token discipline, OAuth consent posture, NHI program. Closes six branches of the identity attack tree.
Device Code Abuse
M365 / Entra ID runbook for Storm-2372 / EvilTokens / FlowerStorm class attacks. MFA does not stop this — the victim authenticates to a real Microsoft page. One Conditional Access policy closes the door; eight Sentinel hunts find the cases that slip through.
Ransomware Resilience
Recovery Without Paying. Patterson Cake containment playbooks (Kill Internet + Kill Authentication), immutable backups, EDR, segmentation. Insurance readiness checklist.
Supply Chain Security
Your Vendors Are Your Attack Surface. MSP access hardening, OAuth lockdown, SaaS sprawl discovery. NIS2 Article 21(d) compliance.
Cloud Security
Four Things That Matter: Auth, Keys, Permissions, Exposure. IP-bound API keys, managed identities, least privilege, public access prevention. Big 3 + mid-market provider guidance.
ClickFix
Fake-CAPTCHA Initial Access — Detection & Prevention. Win+R is largely obsolete; Win+X now dominates (~90%). Per-visitor unique payloads defeat YARA. Covers runspace hunting, RunMRU detection, download-folder correlation, AppLocker + WDAC script enforcement, and fake CAPTCHA awareness training.
Regional Sector Targeting
Who Gets Hit, by Region — a cross-vendor synthesis of the most-targeted sectors across Benelux, DACH, UK & the Nordics. De-biased across 16+ vendor & CERT sources, with the methodology caveat front and centre: each region is measured with a different ruler.
Prevent — Posture & Operations
Posture & Operations Playbooks
Configuration Drift
Stop Defending What You've Already Disabled. Shift down, not shift left — wire security into the platform so teams get it for free. Configuration-as-code for M365. Breach-forensic-driven priority list.
VM & Patching
Easy vs Hard. CISA KEV + EPSS prioritization replaces CVSS score chasing. Edge devices first (44% of zero-days). Auto-update what you can, segment what you can't.
Log Management
Keep data for the need, not the architecture. Four copies already exist — on-host, cloud native, backup, SIEM. Right-size your SIEM for detection (30–90d), not storage. €50–150/month vs €10K enterprise.
Windows LOLBIN Hardening
Cut Living-Off-The-Land execution. ACL DENY for SYSTEM as a stopgap, then WDAC application control for the durable answer. Renamed binaries and dropped copies don't bypass. Ships three working artifacts — deny script, WDAC supplemental, build+deploy pipeline.
MDR Detection Maturity
Detection at scale, prerequisites, and the five-level maturity ladder. For MDR builders, buyers evaluating vendors, and SOC leaders making the build-vs-partner call. Three-tier model, six detection sources, RFP question set.
All Playbooks at a Glance
| Playbook | Threat / Domain | Duration | Investment (200 seats) | Free Controls |
|---|---|---|---|---|
| Immutable Backups | Foundation (Loop 0) | 9–11 days | €11,250 – 13,750 | 6 |
| BEC Defense | Email / Identity | 10–15 days | €12,500 – 18,750 | 13 |
| Identity Hardening | Identity / Prevention | 10–15 days | €12,500 – 18,750 | 13 |
| Identity Breach Response | Active IR — Identity | 2–5 days (IR assist) | €5,000 – 12,500 | n/a (IR) |
| Device Code Abuse | Identity / Detection & Response | 3–5 days | €3,750 – 6,250 | 9 (1 CA + 8 KQL) |
| Ransomware Resilience | Ransomware / Recovery | 12–17 days | €15,000 – 21,250 | 12 |
| Supply Chain Security | Third-Party / Vendor | 9–13 days | €11,250 – 16,250 | 7 |
| Cloud Security | Cloud / IaaS / SaaS | 11–16 days | €13,750 – 20,000 | 12 |
| Configuration Drift | Posture / Compliance | 10–15 days | €12,500 – 18,750 | 10 |
| VM & Patching | Vulnerabilities / Patching | 10–15 days | €12,500 – 18,750 | 12 |
| Log Management | Logging / Detection Infra | 6–8 days | €7,500 – 10,000 | 4 |
| Windows LOLBIN Hardening | Posture / Endpoint Hardening | 11–17 days | €13,750 – 20,000 | 12 |
| MDR Detection Maturity | Operations / Detection Eng | 3–10 days | €3,750 – 12,500 | n/a (assess) |
| AI Agent Security | AI Governance / NIS2 | 12–19 days | €15,000 – 23,750 | 11 |
| ClickFix | Initial Access / Endpoint | 4–7 days | €5,000 – 8,750 | 8 |
| Regional Sector Targeting | Threat Intel / Reference | Reference | n/a (intel) | n/a |
AI SecOps
AI SecOps
Beyond playbooks: helping security teams build, test, and govern their own AI agents.
AI Agent Security
Govern the Machines Before They Govern You. Data safety levels (Block's CDC model), agent identity attribution, prompt injection defense, MCP governance. Five OODA loops from inventory through detection. NIS2 Article 21 compliance mapping included.
The Context Layer
Six architectural approaches to the contextual-triage layer — vector memory, entity graph, data lake, bespoke ML, full context graph, hybrid — scored on five dimensions (temporality, provenance, semantics, governance, decision trace). The conclusion is hybrid: no single substrate wins.