Security Operations

Five decision loops, three deployment tiers, methodology that works whether you're building a practice or leading a team.

5
OODA Loops
2
Capabilities
16
Applied Playbooks
80+
Free Tools
Capability Frameworks

Two capability frameworks that underpin every playbook — detection engineering for finding threats, investigation automation for understanding them.

80% Plumbing. 20% AI. 100% Yours. — Read the Approach →
Architecture

Five OODA Loops

Security has not one but five distinct decision loops, each with different cycle times. The fastest loop protects the slower loops. Every playbook below is structured around these five loops.

Five OODA defense loops: Containment (minutes), Detection (minutes-hours), Posture (continuous), Vulnerability Management (hours-days), Structural (weeks-months).
Defense Architecture
Five OODA Loops
The fastest loop protects the slower loops.
Each layer is a decision cycle with its own tempo.
05Structural
weeks – months
CONSULT
04Vulnerability Management
hours – days
HUNT
03Posture / Drift
continuous
AUTO
02Detection & Response
minutes – hours
AUTO
01Containment
minutes
AUTO
Loop 0 — Hard Barriers  •  Immutable Backups  •  Segmentation  •  Identity Hardening

The Principle

If containment (loop 1) is fast enough, you buy time for everything downstream. If detection (loop 2) is good enough, containment triggers early and blast radius stays small. This cascading protection is why a breach becomes a bounded incident rather than an existential crisis.

Three Tiers Per Loop

Quick wins — free, deployable today, no vendor required.
Core engagement — consulting deliverable, expert-led, scoped and priced.
Target state — the architectural endgame that makes the threat structurally difficult.

The Goal: Make DFIR the Exception, Not the Plan

Most mid-market companies have no detection capability. When something goes wrong, they discover it weeks later — after encryption, after data exfiltration, after the attacker has left. Then they call a DFIR team at €300/hour to figure out what happened, often with incomplete or missing logs.

The playbook architecture flips this:

LayerWhat It DoesEffect on DFIR Need
365 days compressed on-host
Raw logs, cheap storage
Forensic evidence always exists. Windows Event Log at 1GB+ per channel, Linux syslog 12 months, on every server. Compressed, not indexed. Costs less than a coffee per day per server. If you DO need DFIR, you hand them a complete evidence package instead of "we don't have logs from before Tuesday."
30–90 days in SIEM
Normalized, tagged, searchable
Detection rules run here. Alerts fire here. Wazuh (free) or equivalent. Tuned to the 15 specific settings from breach forensics — not generic "detect everything." You detect lateral movement at hour 2, not day 14. The detection window closes before DFIR is needed.
Detection rules tuned to real breaches
The 15 settings, not 10,000 CIS checks
Legacy auth attempts, MFA bypass patterns, RDP lateral movement, shadow copy deletion, backup agent termination, off-hours admin activity, AD CS abuse, credential stuffing. Catches the specific attack patterns that show up in 59–84% of real incidents. Not noise — signal.
24/7 automated investigation
Investigation automation
Investigates every alert with auditable reasoning. Works at 2 AM Saturday when 88% of ransomware deploys. Contains automatically or escalates with complete investigation report. Containment is scoped at least as wide as the attacker could be, so a second foothold isn't left live while the first is cut. Containment happens in minutes, not days. The attacker is evicted before they reach the encryption phase. DFIR is never called.
Every incident feeds the slow loops
Machines collect, humans curate
Each closed case is mined for how the attacker got in, what detection missed, and which visibility or process gaps slowed the response. Those go to the patching, posture, detection and architecture backlogs. Indicators become intelligence only after an analyst checks them and gives each one a date, a source, an expiry and a confidence level. The same intrusion doesn't work twice. Each incident removes a path instead of just closing a ticket, so fewer incidents reach DFIR.
The economics: A DFIR engagement costs €50K–200K and takes weeks. The detection + containment layer costs a fraction of that and prevents the incident from escalating to the point where DFIR is needed. When DFIR IS needed (loops 1–3 failed), the 365 days of raw logs mean the investigation starts with evidence, not guesswork. You're buying DFIR avoidance, not DFIR readiness.
Playbooks

Applied Playbooks

Each playbook applies the detection engineering and investigation automation methodology to a specific threat domain.

Loop 0: The Foundation — Hard Barriers

Before any threat-specific playbook, these three controls must be in place. They are chosen for one property: each one refuses the attacker's action rather than slowing it down. That is the doctrine for Loop 0 — invest in hard barriers first, treat friction as a bonus.

The barrier test. Ask of every control: can an attacker get past it with more attempts, more time or more patience? Then it is friction. Does it refuse the action outright, so the attacker needs a specific bypass that doesn't exist by default? Then it is a hard barrier.
Friction — slows the attackerHard barrier — refuses the attacker
Non-standard ports, renamed Administrator, hidden bannersDefault-deny firewall rules between zones: workstations cannot reach domain-controller admin ports
TOTP codes and push approvals — phishable, they add effortFIDO2 / passkeys — the key will not sign for a lookalike domain
Backups that are hidden, or "hard to find" on the networkWORM / Object Lock storage with separate backup credentials — deletion is refused, not delayed
Rate limits, CAPTCHAs, lockout thresholds, code obfuscationMemory protections (W^X, KASLR) and memory-safe languages that remove a bug class
Why this matters more now. Anthropic's Frontier Red Team, assessing Claude Mythos Preview (April 2026): “Mitigations whose security value comes primarily from friction rather than hard barriers may become considerably weaker against model-assisted adversaries. Defense-in-depth techniques that impose hard barriers (like KASLR or W^X) remain an important hardening technique.” Models grind through tedious steps quickly and at scale, which is exactly what friction relies on attackers not doing. Two caveats: this is Anthropic's stated expectation, not a measured result, and the same assessment reports Mythos producing KASLR bypasses — hard barriers force the attacker to chain more exploits, they are not unbreakable. The mapping of segmentation, FIDO2 and WORM backups onto the barrier column is our application of the principle, not Anthropic's.
Loop 0 — Hard Barrier

Immutable Backups

3-2-1-1 architecture, WORM storage, tested restores. The control that makes ransomware a recoverable event, not an existential one. Includes backup kill chain analysis and management AD architecture.

The barrier: the storage layer refuses deletion, even for an admin. Hidden or obscure backups are only friction.

94% of ransomware targets backups • 57% succeed
Loop 0 — Hard Barrier

Network Segmentation

3-4 VLANs minimum. Workstations, servers, backup infrastructure, management. Default deny between zones. The compensating control when you can't patch fast enough — limits blast radius to one segment.

The barrier: a deny rule leaves nothing to grind through, only a different path to find. VLANs without enforced rules between them are friction.

Cross-cutting control • Referenced in every playbook
Loop 0 — Hard Barrier

Identity Hardening

MFA everywhere. FIDO2 for admins. Separate admin accounts. LAPS for local admin. Block legacy auth. 56% of breaches start with stolen credentials — this is where you stop them.

The barrier: phishing-resistant FIDO2 and blocked legacy auth. TOTP and push MFA are friction — better than nothing, but phishable.

56% of initial access via stolen creds

Threat-Specific Playbooks

Posture & Operations

See all playbooks →
Risk Quantification

Risk Quantification & Assessment

Before you start fixing things, you need to know where you stand and what an incident actually costs. These tools give you the numbers — no email gates, no telemetry, no accounts required.

Interactive Tool

Security Self-Assessment

Evidence-based posture check. Tier A: instant email security analysis via DNS (SPF, DMARC, MX). Tier B: paste command output for identity and logging checks (MFA exceptions, legacy auth, stale admins, forwarding rules, event log sizing). All client-side — nothing leaves your browser.

10 checks • 0–100 score • Links to relevant playbooks
Interactive Tool

PHOSI Calculator

Potential Harm Of Security Incident. Interactive risk quantification tool that calculates the business impact of a security incident based on your specific organization: revenue, data sensitivity, regulatory exposure, reputation risk. Produces a scored risk matrix with annual cost projections.

Drives playbook prioritization • Board-ready output • Insurance evidence
Interactive Tool

Incident Severity Scoring

8-dimension weighted severity assessment based on CISA NCISS methodology. Score operational continuity, data exposure, threat activity, asset criticality, threat sophistication, recovery complexity, attack progression, and control effectiveness. Includes materiality flags for governance escalation. All client-side.

8 dimensions • 0–100 composite • Exportable assessment

How PHOSI Connects to the Playbooks

PHOSI answers "how bad could it be?" for your specific organization. The playbooks answer "what do we do about it?" Use PHOSI to:

1. Prioritize which playbook to start with — if your PHOSI score for data breach is higher than ransomware, start with BEC Defense and Cloud Security before Ransomware Resilience.

2. Justify the investment — the PHOSI annual cost projection vs. the playbook investment makes the ROI conversation concrete, not theoretical.

3. Report to the board — PHOSI produces a one-page risk summary that non-technical executives understand. Pair with playbook progress reports for quarterly board updates.

The Free Tool Stack (referenced across all playbooks)

M365: CISA ScubaGear, Maester, Microsoft365DSC, Secure Score
AD: PingCastle, Purple Knight, BloodHound CE, Microsoft LAPS
Cloud: Prowler, ScoutSuite, Steampipe, Checkov, Cloud Custodian
Endpoints: Wazuh, Velociraptor, Lynis, OpenSCAP
Email: Sublime Security, IRONSCALES (free 500), Check by CyberDrain
Network: CrowdSec, OpenCanary, Canarytokens, Batfish
Secrets: TruffleHog, cazadora
Backup: Kopia, Restic, BorgBackup, MinIO
Scanning: OpenVAS, Nuclei, Shodan ($49), CISA Cyber Hygiene
Dependencies: Renovate, Dependabot, Socket.dev, Syft+Grype
Prioritization: CISA KEV, EPSS API
Vendor: CSA CAIQ, CISA Software Acquisition Guide, Wing Security

The Mid-Market Gap

Enterprise has 24/7 SOCs, dedicated DFIR teams, and seven-figure security budgets. Small business has nothing and accepts the risk. Mid-market (50–500 employees) is stuck in between: big enough to be targeted, too small for enterprise tools, and often relying on an MSP who has domain admin on everything.

These playbooks close that gap with three layers: free tools you deploy this week, consulting engagements that build the architecture, and automation that keeps it running 24/7 without a SOC team.

NIS2 + Insurance = The Forcing Function

NIS2 mandates risk management measures including incident handling, business continuity, supply chain security, and access control. Compliance deadline: October 2026. Penalties: up to 10M EUR or 2% of global turnover.

Cyber insurance underwriters now require MFA, EDR, immutable backups, tested IR plans, and patch management evidence. 41% of applications denied on first submission. 82% of denied claims had no MFA.

Every playbook maps to both. Build once, satisfy both.