GLOBAL ENTERPRISE SECURITY
Integrating Cyber, Physical, Personnel, and Operational Protection
Six one-pagers

Identity-as-Perimeter Briefs

If digital compromise can become a badge, a vendor on site, or a muted door, these six pages show the identity seams that made it possible, and the questions to ask on Monday.

PDF six-pack of print-and-brief one-pagers. Identity as the enterprise control plane, tied to personnel lifecycle and third-party access.

Failures at enterprise scale are rarely missing identity products. They are fragmentation. Workforce identity, vendor SSO, break-glass, badge, VPN, and SaaS often share a plane nobody treats as a plane. Each team is mature in isolation, but the threat vector does not care.

These briefs are not an IAM configuration guide or a vendor bake-off. They take your IdP (Entra or equivalent) as the example control plane and keep the ideas portable to Okta, Ping, and whatever you actually run. The operational problem is personnel plus third parties: joiners, movers, leavers, contractors, emergency creds, and tokens that outlive the work order. Physical access systems and vendor portals ride the same plane more often than boards are told.

Read them before the tabletop in the Practical Security Kit. The Kit rehearses Vendor SSO to Facility Access. These pages explain the mechanism. Pair with Model in the Kill Chain when a cheap model or an agent with tools is how the vendor or the site was reconned. Identity is how that recon becomes entry.

What's in the box

Brief 1. IdP as SPOF

Blast radius, what rides the plane, and resilience beyond redundant IdP nodes.

Brief 2. IdP logging

What you must be able to reconstruct. GSOC use. Retention. Gaps that hide token theft and vendor SSO abuse.

Brief 3. Break-glass

Who holds it, personnel governance, dual control, physical plus logical, insider path.

Brief 4. Token theft

Session, PRT/refresh, adversary-in-the-middle at a practical level. How it becomes facility access. First-hour containment, pointing to the Kit runbook.

Brief 5. Vendor SSO

Third parties inside the boundary. Least privilege, time-bound access, work-order coupling, offboarding that kills tokens.

Brief 6. Board questions

Eight to twelve questions directors should ask. What a good answer sounds like, versus theater.

Who it's for

CSO/CISOs, identity leads who have to brief operators, GSOC leads who need reconstructable auth, CROs, and directors who are tired of "we have MFA" as a complete sentence.

Who it's not for

IAM engineers looking for Conditional Access recipes. Help desk runbooks. Product selection of Entra vs Okta. Compliance teams who want a control-by-control 800-53 or 800-171 mapping.

How it fits the other packs

The Practical Security Kit gives you the first-hour roster and the tabletop in which a stolen vendor SSO session becomes badge admin, a work order, and a muted door. These briefs are why that path exists and what to fix so the next tabletop is harder on the adversary. Model in the Kill Chain is how cheap models and vendor-side agents feed recon and tool-use into the same identity plane. Tabletop injects reuse these failure modes on purpose.

The other two packs