Framework

My three-step framework for Securing Critical National Infrastructure

Visibility, remediation, detection: A 17-year practitioner’s guide to building national cybersecurity capacity, from government to enterprise.

Step 1
Visibility

You cannot fix what you cannot see

Before you assess risk or buy tools, you need to know what you actually have, what it's connected to, and what it's doing — not what procurement says you have.

Map the political and institutional landscape first. The political landscape shapes the technical landscape.

What this means
Discover everything you own, including hidden and unmanaged assets.
Understand who owns what across ministries and independent institutions.
Build an accurate map of what exists, how it connects, and what it does.
Step 2
Remediation and hardening

Fixing what you can now see

Once you can see your state, you fix it. People and processes matter as much as any tool.

A vulnerability report nobody acts on has not improved your security posture. Accountability, timelines, and tracking are the actual work.

Key focus areas
Strong governance: clear ownership and accountability.
Remediation processes: timelines, tracking, and evidence.
Harden systems: start with the basics (credential policies, patching, configuration).
Watch out for

The transition state: the window nobody is watching

During change, risk goes up. Systems are partially configured, partially connected, partially secured. That window is when breaches happen. Continuous monitoring is essential.

Step 3
Detection and response

Earned, not bought

Detection and response depends entirely on the quality of the first two steps.

Automating detection and response, and increasingly using AI, is the right direction — but automation on a bad foundation produces bad outcomes faster.

What good looks like
Accurate baseline = meaningful detections.
AI and automation amplify good processes — they don't fix bad ones.
Respond to real threats, not noise.
The sequence matters as much as the tools
1 See it

Map and understand your true surface.

2 Fix it

Remediate and harden with people and process.

3 Detect it

Detect and respond on a strong foundation.

People. Process. Governance.

These are the force multipliers that make security real.