Process

A practice,
not a product.

Three phases. One accountable lead. No handoffs, no black boxes. Here’s what the first twelve weeks with VKonSec actually look like.


Phase 01
Week 1 — 2

Map

We inventory your stack, your crown jewels, and the adversaries who actually care about you. You leave with a written threat model — not a spreadsheet — and a prioritized list of what to fix in what order.

01Asset & identity inventory
02Business-impact threat model
03Risk-ranked remediation plan
04Exec debrief & board-ready summary
Phase 02
Week 3 — 6

Harden

We close the gaps that matter first — identity, endpoints, edges — and instrument what we can’t yet close. Deploy windows are scoped to avoid shipping seasons; rollbacks are rehearsed, not hoped for.

01Identity & access hardening
02EDR / SIEM tuning & rollout
03Cloud control baselines
04Tabletop & runbook authoring
Phase 03
Ongoing

Defend

Our SOC runs your detections; our strategists run your program. Monthly reviews with your leadership, quarterly red-team pressure, and a single phone number when something goes sideways at 3 AM.

0124/7 managed detection & response
02Monthly metrics & program reviews
03Quarterly red-team pressure tests
04On-call incident command

Principles

How we decide
when things get hard.

P.01

Compounding beats heroics.

We’d rather raise your median control quality than dazzle you with a single showpiece. Boring wins.

P.02

One throat to choke.

A named lead owns your outcome end-to-end. If something breaks, you know who to call — and they already know your name.

P.03

Evidence, not opinions.

Every recommendation is justified by a measurement. Every claim of progress is provable with data you can audit.

P.04

Small team, senior bench.

We don’t backfill engagements with juniors. The person who sold you is the person defending you.


Deliverables

What ends up
in your Drive.

Threat model

Your business, not a template. 14–22 pages.

Metric dashboard

MTTR, MTTD, phish-click, coverage %. Updated live.

Runbooks

Containment, comms, and recovery steps, tested.

Quarterly review

Board-ready deck. Signed by your lead.

Audit evidence

Auto-collected, auditor-matched, versioned.

Tabletop playbooks

Scenario-specific; drilled with your leadership.


Start the map

Week one is
on us.

Book a 30-minute strategy call. We’ll run the opening of Phase 01 live and leave you with a draft threat model — whether or not you work with us.