01Scope
Understand before agreeing
Every engagement begins with a short, structured scoping conversation. The objective is not to sell — it is to get an honest picture of the environment, the pressure point driving the request, and the outcome that would actually count as success. If we are not the right fit, we say so at this stage.
Activities
- Discovery call with the technical and operational stakeholders
- Review of current architecture, tooling, and incident posture
- Identification of critical assets, data flows, and trust boundaries
- Alignment on outcome criteria — what does 'done' look like?
- Commercial shaping — fixed-scope, phased, or retained?
Artefacts
- Scope brief (problem, environment, outcome, timeline)
- Commercial proposal with clear deliverables and exit criteria
- Risk register seed — early view of known pressure points
What the client sees
A document they can hand to their leadership or board that explains exactly what CyberZonic will do, how long it will take, and what the success criteria are. No ambiguity, no fine print surprises.
02Assess
Ground the work in reality
Before we recommend or build anything, we assess the real environment. This is where we validate what is actually deployed, what is actually logged, what is actually protected, and where the gaps sit. Every later phase references the evidence captured here.
Activities
- Technical posture review against the baseline (MCSB, CIS, ISO 27001 Annex A, or Cyber Essentials depending on engagement)
- Log coverage audit — what we see vs what we should see
- Identity and access review — privileged accounts, Conditional Access, MFA coverage
- Threat model relevant to the sector and the crown jewels identified in scope
- Quick-win identification — controls we can fix within the engagement window
Artefacts
- Assessment report with maturity scoring per theme
- Evidence pack — screenshots, exported configurations, policy extracts
- Prioritised gap backlog mapped to effort vs impact
What the client sees
A clear, evidence-backed picture of current state. No hand-wavy findings — every conclusion points to a specific control, policy, or log source the client can verify themselves.
03Design
Decide the operating shape
Design is where the methodology separates itself from checkbox consulting. We design the target operating model — not just the tools, but how they are run day-to-day. A monitoring platform that nobody can operate is worth less than a simple one that the client can run confidently.
Activities
- Target architecture aligned to the existing estate (no rip-and-replace unless justified)
- Detection engineering strategy — what we tune, what we write, what we leave off
- Runbooks and operating cadence — who does what, when, and how it is evidenced
- Governance and escalation design — decision rights at the right level
- Change and release strategy so the client's teams stay in control
Artefacts
- Target-state architecture document
- Detection strategy with MITRE ATT&CK coverage mapping
- Runbook skeletons for the top incident types
- Governance and escalation matrix
What the client sees
An operating blueprint that their engineers can implement with confidence. Design decisions are written down with reasoning, so future teams understand why the estate is shaped the way it is.
04Build
Ship it, and ship it properly
Build phase is where most engagements either prove or break themselves. We implement the design in measured increments, pair with the client's team when possible, and evidence every change. No silent changes, no undocumented tweaks, no 'trust us' handovers.
Activities
- Implementation against the design, change-controlled through the client's process
- Sentinel analytics rules, Defender policies, Entra Conditional Access, Intune configuration — whichever elements the scope requires
- Infrastructure-as-code where the client's maturity supports it (Bicep, Terraform)
- Pair delivery with the client's engineers — they watch, they learn, they take over
- Documentation written *as* the work is done, not at the end
Artefacts
- Implementation log with per-change evidence
- IaC repository (where applicable) with pull-request history
- As-built documentation updated against the design
What the client sees
A working capability that matches the design and is fully documented. Their team was part of the build, so the handover is not a surprise — it is a continuation of work they have been watching for weeks.
05Verify
Prove it works — before declaring it works
Verification is non-optional. We do not declare an engagement complete until we have evidence the capability works against the threats it was built for. This is where we stress-test the detection rules, tabletop the incident response, and close out the assessment gaps raised in Phase 2.
Activities
- Detection validation — atomic red team, purple team, or Microsoft Sentinel validation playbooks
- Tabletop exercise for the top two or three incident types
- Coverage review against MITRE ATT&CK and the original gap backlog
- Control effectiveness testing against the compliance framework in scope
- Formal closure of Phase 2 findings with evidence
Artefacts
- Verification report with test cases, results, and coverage maps
- Tabletop exercise output with decisions and lessons
- Final gap-backlog status — closed, deferred, or accepted
What the client sees
Proof, not promises. They have a document they can put in front of a regulator, a board, an insurer, or a customer that shows the capability works — and the evidence to back it up.
06Operate
Hand over, stay available
The final phase is the hardest to do well. Most consultancies leave on the day the invoice clears. We do not. Operate phase covers the structured handover, the first operational cycles under the client's own team, and a defined aftercare window so problems surface while we can still help.
Activities
- Knowledge transfer sessions recorded and added to the client's internal wiki
- Run-alongside period where we shadow the client's operators
- Defined aftercare window with named escalation path
- Retainer option if the client wants ongoing support
- Post-engagement review points agreed during scoping
Artefacts
- Handover pack with runbooks, credentials (rotated), contact tree, escalation path
- Recorded knowledge transfer sessions
- Aftercare response model and named point of contact
What the client sees
A consultancy that cared whether the work outlived the engagement. The client's team feels ownership of the capability — not abandoned by a contractor who left on day one of handover.