SOC monitoring online Response SLA · < 15 min Status · All systems nominal
CMMC · NIST · HIPAA aligned EST · 09:00 – 18:00
Consulting · The ZDT Framework

A defensible security program, built in three layers.

Our consulting engagements are organized around three disciplines that reinforce each other — Zero Trust redefines who gets in, Defense in Depth decides what happens when something does, and Risk Management & Mitigation turns the whole program into a written, auditable strategy. You can start with one; most clients end up with all three.

ZDT Consulting · Three-Layer Model
v1.0
Risk Management
Defense in Depth
Zero Trust
Assets
Data · Identity

Three disciplines, one program.

Most small and medium businesses have pieces of a security program — an antivirus here, an MFA prompt there, a dusty incident response doc from a vendor who left in 2022. What they don't have is a framework that ties those pieces to a defensible position.

ZDT's consulting engagements organize your investments around three disciplines that industry regulators, cyber insurers, and auditors already recognize. Each one has a scoped deliverable, a timeline, and a written artifact you can hand to your board.

Pillar 01

Zero Trust

Never trust · Always verify

Redesign access so every user, device, and request is continuously verified — not once at the firewall, but at every resource. Eliminates the "soft center" most SMBs still operate.

Pillar 02

Defense in Depth

Layered controls

Assume a layer will fail and make sure the next one catches it. Endpoint, email, network, identity, and data each get their own independent control set and telemetry.

Pillar 03

Risk Management

Measure · Prioritize · Mitigate

Translate the threat landscape into a ranked register your leadership team can read — with owners, dollar-weighted impacts, and a mitigation roadmap that survives contact with the budget.

Zero Trust — verify everything, every time.

Engagement 01 · 6–10 weeks

Zero Trust Architecture

The old model — a perimeter you trust and everything inside it — stopped working the moment your team started using laptops at coffee shops and SaaS tools over the open internet. Zero Trust assumes the perimeter is already compromised and re-anchors trust on identity and device posture instead.

Phase 01 · 2 weeks

Identity-first discovery

We map every account — employee, contractor, service, shared — across your tenant, then chart who actually needs access to what.

  • Account inventory & role review
  • Privileged-account audit
  • Conditional-access policy baseline
Phase 02 · 2–3 weeks

Access redesign

We collapse broad "network access" into per-resource, per-session decisions — MFA everywhere that matters, device-compliance gates on sensitive systems.

  • MFA rollout with fallback coverage
  • Device-compliance policy
  • Segmentation plan for legacy apps
Phase 03 · 2 weeks

Continuous verification

We instrument the signals — impossible travel, token reuse, risky sign-ins — so trust gets re-evaluated instead of granted once and forgotten.

  • Risk-based sign-in policies
  • Session lifetime & reauth rules
  • Telemetry routed to SIEM / SOC
Phase 04 · 1–2 weeks

Handover & hardening

Training for your IT lead, a written runbook, and a 30-day review to catch the access patterns nobody admitted to during discovery.

  • IT-admin runbook
  • End-user FAQ & comms pack
  • 30-day tuning review
Deliverables Zero Trust architecture doc Identity & access matrix Conditional-access policy set Board-ready executive summary

Defense in Depth — layered on purpose.

Engagement 02 · 8–12 weeks

Layered Controls Program

No single control stops every attack. Defense in Depth is the explicit practice of stacking independent controls across five layers — perimeter, network, endpoint, identity, and data — so a failure at any one layer meets another layer ready to catch it.

Layer 01 · Perimeter & email

Filter what arrives

Hardened email gateway, DNS filtering, inbound web protection. The first 83% of breach attempts never reach a user.

  • Email authentication (SPF/DKIM/DMARC)
  • Anti-phishing & impersonation rules
  • DNS filtering for command-and-control
Layer 02 · Network

Contain what lands

Segmentation, egress rules, and lateral-movement detection so a compromised laptop cannot become a compromised company.

  • VLAN / micro-segmentation review
  • Egress filtering & allow-lists
  • NDR or netflow telemetry
Layer 03 · Endpoint

Stop what executes

Managed EDR with behavioral detection, automated isolation, and a 24/7 human who can contain an infected machine in minutes.

  • Managed EDR rollout
  • Application control / allow-listing
  • Patch-management SLA
Layer 04 · Identity

Verify who acts

Hardened identity provider, MFA, privileged access controls, and alerting on session anomalies — the layer regulators ask about first.

  • MFA + phishing-resistant factors
  • Privileged access workstations
  • Identity-threat detection
Layer 05 · Data & backup

Recover what breaks

Encrypted, immutable backups with quarterly tabletop restores. An untested backup is a story, not a control.

  • 3-2-1 backup strategy
  • Immutable / offline copies
  • Quarterly tabletop restore
Layer 06 · Monitor & respond

See & react

Centralized telemetry, 24/7 SOC watch, and a written incident-response plan with named owners for when — not if — something trips.

  • SIEM / log aggregation
  • SOC response with 15-min SLA
  • Written IR plan & tabletop drill
Control layer
Typical SMB state
After engagement
Ongoing
Email / phishing
Basic spam filter
Hardened ✓
Quarterly simulations
Endpoint
Consumer AV
Managed EDR ✓
24/7 SOC watch
Identity
SMS MFA, partial
Phish-resistant ✓
Conditional access
Backup / recovery
Never restored
Tested ✓
Quarterly tabletop
Deliverables Layered controls map Written IR plan Tabletop exercise report 30/60/90 roadmap

Risk Management & Mitigation.

Engagement 03 · 4–6 weeks initial · quarterly cadence

Cyber Risk Program

Security without a risk framework is a shopping list. This engagement produces a written, prioritized risk register aligned to NIST CSF 2.0 — so every dollar you spend has a named threat, a named owner, and a measurable reduction in exposure.

Phase 01 · 1–2 weeks

Identify

Catalog your crown-jewel assets, data classifications, and regulatory obligations. You can't protect what you haven't named.

  • Asset & data inventory
  • Regulatory scope (HIPAA/CMMC/SOC 2)
  • Business-impact assessment
Phase 02 · 1 week

Assess

Score each risk on likelihood and dollar-weighted impact. Outputs a ranked register, not a 40-page narrative nobody reads.

  • Threat-likelihood modeling
  • Impact valuation per asset
  • Ranked risk register
Phase 03 · 1–2 weeks

Mitigate

For each top-tier risk: named owner, treatment decision (accept / mitigate / transfer / avoid), and a 90-day plan of action.

  • Treatment strategy per risk
  • Cyber-insurance alignment
  • Mitigation roadmap (30/60/90)
Phase 04 · Quarterly

Govern

Ongoing quarterly review so the register stays alive. New risks added, old ones closed out, with a written report your board can keep on file.

  • Quarterly risk review
  • Board & insurer reporting
  • Continuous control monitoring
Deliverables Written risk register NIST CSF 2.0 gap assessment 30/60/90 mitigation plan Quarterly governance report

From first call to quarterly governance, in four steps.

Step 01 · 30 min

Scoping call

A plain-English conversation about your business, data, and existing controls. We tell you which pillar to start with.

Step 02 · 1 week

Engagement proposal

Fixed scope, fixed price, named engineer. No open-ended retainers dressed up as discovery.

Step 03 · 4–12 weeks

Delivery

Weekly working sessions, shared backlog, and written artifacts you own at the end — not slides we retain on our server.

Step 04 · Quarterly

Governance cadence

Optional quarterly review to keep the register current and show your insurer the program is alive, not shelfware.

Not sure where you'd start?

A 30-minute scoping call, no pitch deck, and a written recommendation for which pillar will produce the most risk reduction per dollar for your business.

Book a scoping call