GLOBAL ENTERPRISE SECURITY
Integrating Cyber, Physical, Personnel, and Operational Protection
Starter pack

Practical Security Kit

Turn the operating model into something you can run on Monday: who has authority in the first hour, what a CSO briefs, and a tabletop that crosses cyber, physical, personnel, and a preferred vendor.

PDF pack of three artifacts: first-hour runbook, eight CSF KPI one-pagers, and a 90-minute tabletop.

Failures at enterprise scale are rarely missing controls. They are fragmentation. Cyber, physical, personnel, and ops are typically mature in isolation and fail at the seams. This kit is how you stop rehearsing those functions separately.

The runbook is not a SIEM cookbook and not an alert-triage SOP. It is a first-hour command document: who has authority, who talks, who shows up, who does not freelance. The clock is 0-15, 15-30, 30-60. Vendors get a named seat because they are inside the boundary. Identity is how a stolen session becomes a door. Automation may contain an incident, but humans decide on people, facilities, public statements, and strategy.

The KPI pages are few on purpose. A CSO can brief them to execs and a board. They measure risk reduction and seam health, not ticket volume. NIST CSF is the briefing language, not a religion. You can map to ISO 27001 and NIST SP 800-171, but mapping is not the product.

The tabletop is 90 minutes. Same seats as the runbook. The path of this tabletop's story is how this kit talks to the Identity briefs and the Model pack.

What's in the box

First-Hour Converged Runbook

Purpose, roster of named seats, triggers that cross seams, the clock, decision rights, legitimacy, PIO, geography and GSOC as shared mental model, and close of first hour (common operating picture, open questions, 4-hour plan, after-action seed). One-page wall chart: roles by 0-15 / 15-30 / 30-60. Checklists as appendices, not the main event.

CSF KPI one-pagers

Eight measures. Each is a single page: the question it answers, why execs should care, formula and data source, qualitative bands (good / watch / bad), owner, cadence, how it fails if gamed, and the converged angle. These go beyond the free Sample Governance-Relevant Metrics list. They are not that list with a price tag.

90-minute tabletop

Facilitator guide, ground rules, six timed injects plus a curveball, evaluation, and after-action worksheet. Players match the runbook seats.

Who it's for

CSO/CISOs, security directors, GSOC leads, CROs, and the Executive Sponsor who will be asked to lock a site or keep shipping. Teams that already have tools and still fail when a vendor, a badge, and an IdP event happen in the same hour.

Who it's not for

SOC analysts looking for detection content. IAM engineers looking for Conditional Access recipes. Teams that want a cyber-only ransomware tabletop. Anyone who wants the free ICS org chart reproduced. This kit assumes ICS-style unified command and keeps it light.

How it fits the other packs

Run this kit first if you can only buy one thing. Identity-as-Perimeter Briefs explain the identity plane this scenario rides: SPOF, logging, break-glass, token theft, vendor SSO, board questions. Model in the Kill Chain explains cheap models in recon and agent tool-use, including vendor-side models drafting work orders.

The other two packs