Turn the operating model into something you can run on Monday: who has authority in the first hour, what a CSO briefs, and a tabletop that crosses cyber, physical, personnel, and a preferred vendor.
PDF pack of three artifacts: first-hour runbook, eight CSF KPI one-pagers, and a 90-minute tabletop.
Failures at enterprise scale are rarely missing controls. They are fragmentation. Cyber, physical, personnel, and ops are typically mature in isolation and fail at the seams. This kit is how you stop rehearsing those functions separately.
The runbook is not a SIEM cookbook and not an alert-triage SOP. It is a first-hour command document: who has authority, who talks, who shows up, who does not freelance. The clock is 0-15, 15-30, 30-60. Vendors get a named seat because they are inside the boundary. Identity is how a stolen session becomes a door. Automation may contain an incident, but humans decide on people, facilities, public statements, and strategy.
The KPI pages are few on purpose. A CSO can brief them to execs and a board. They measure risk reduction and seam health, not ticket volume. NIST CSF is the briefing language, not a religion. You can map to ISO 27001 and NIST SP 800-171, but mapping is not the product.
The tabletop is 90 minutes. Same seats as the runbook. The path of this tabletop's story is how this kit talks to the Identity briefs and the Model pack.
Purpose, roster of named seats, triggers that cross seams, the clock, decision rights, legitimacy, PIO, geography and GSOC as shared mental model, and close of first hour (common operating picture, open questions, 4-hour plan, after-action seed). One-page wall chart: roles by 0-15 / 15-30 / 30-60. Checklists as appendices, not the main event.
Eight measures. Each is a single page: the question it answers, why execs should care, formula and data source, qualitative bands (good / watch / bad), owner, cadence, how it fails if gamed, and the converged angle. These go beyond the free Sample Governance-Relevant Metrics list. They are not that list with a price tag.
Facilitator guide, ground rules, six timed injects plus a curveball, evaluation, and after-action worksheet. Players match the runbook seats.
CSO/CISOs, security directors, GSOC leads, CROs, and the Executive Sponsor who will be asked to lock a site or keep shipping. Teams that already have tools and still fail when a vendor, a badge, and an IdP event happen in the same hour.
SOC analysts looking for detection content. IAM engineers looking for Conditional Access recipes. Teams that want a cyber-only ransomware tabletop. Anyone who wants the free ICS org chart reproduced. This kit assumes ICS-style unified command and keeps it light.
Run this kit first if you can only buy one thing. Identity-as-Perimeter Briefs explain the identity plane this scenario rides: SPOF, logging, break-glass, token theft, vendor SSO, board questions. Model in the Kill Chain explains cheap models in recon and agent tool-use, including vendor-side models drafting work orders.
If digital compromise can become a badge, a vendor on site, or a muted door, these six pages show the identity seams that made it possible, and the questions to ask on Monday.
Treat models as capability in recon, malware-assist, and vendor tool-use, then give the board questions, evidence, and a 90-day program that does not require a new platform religion.