Methodology

How CyberZonic runs an engagement — from first conversation to handover and beyond.

A six-phase delivery methodology built from years of running cybersecurity programmes in regulated, high-pressure environments. Every phase has defined activities, defined artefacts, and a clear answer to the question what does the client actually see?

01

Scope

Understand before agreeing

Every engagement begins with a short, structured scoping conversation. The objective is not to sell — it is to get an honest picture of the environment, the pressure point driving the request, and the outcome that would actually count as success. If we are not the right fit, we say so at this stage.

Activities

  • Discovery call with the technical and operational stakeholders
  • Review of current architecture, tooling, and incident posture
  • Identification of critical assets, data flows, and trust boundaries
  • Alignment on outcome criteria — what does 'done' look like?
  • Commercial shaping — fixed-scope, phased, or retained?

Artefacts

  • Scope brief (problem, environment, outcome, timeline)
  • Commercial proposal with clear deliverables and exit criteria
  • Risk register seed — early view of known pressure points

What the client sees

A document they can hand to their leadership or board that explains exactly what CyberZonic will do, how long it will take, and what the success criteria are. No ambiguity, no fine print surprises.

02

Assess

Ground the work in reality

Before we recommend or build anything, we assess the real environment. This is where we validate what is actually deployed, what is actually logged, what is actually protected, and where the gaps sit. Every later phase references the evidence captured here.

Activities

  • Technical posture review against the baseline (MCSB, CIS, ISO 27001 Annex A, or Cyber Essentials depending on engagement)
  • Log coverage audit — what we see vs what we should see
  • Identity and access review — privileged accounts, Conditional Access, MFA coverage
  • Threat model relevant to the sector and the crown jewels identified in scope
  • Quick-win identification — controls we can fix within the engagement window

Artefacts

  • Assessment report with maturity scoring per theme
  • Evidence pack — screenshots, exported configurations, policy extracts
  • Prioritised gap backlog mapped to effort vs impact

What the client sees

A clear, evidence-backed picture of current state. No hand-wavy findings — every conclusion points to a specific control, policy, or log source the client can verify themselves.

03

Design

Decide the operating shape

Design is where the methodology separates itself from checkbox consulting. We design the target operating model — not just the tools, but how they are run day-to-day. A monitoring platform that nobody can operate is worth less than a simple one that the client can run confidently.

Activities

  • Target architecture aligned to the existing estate (no rip-and-replace unless justified)
  • Detection engineering strategy — what we tune, what we write, what we leave off
  • Runbooks and operating cadence — who does what, when, and how it is evidenced
  • Governance and escalation design — decision rights at the right level
  • Change and release strategy so the client's teams stay in control

Artefacts

  • Target-state architecture document
  • Detection strategy with MITRE ATT&CK coverage mapping
  • Runbook skeletons for the top incident types
  • Governance and escalation matrix

What the client sees

An operating blueprint that their engineers can implement with confidence. Design decisions are written down with reasoning, so future teams understand why the estate is shaped the way it is.

04

Build

Ship it, and ship it properly

Build phase is where most engagements either prove or break themselves. We implement the design in measured increments, pair with the client's team when possible, and evidence every change. No silent changes, no undocumented tweaks, no 'trust us' handovers.

Activities

  • Implementation against the design, change-controlled through the client's process
  • Sentinel analytics rules, Defender policies, Entra Conditional Access, Intune configuration — whichever elements the scope requires
  • Infrastructure-as-code where the client's maturity supports it (Bicep, Terraform)
  • Pair delivery with the client's engineers — they watch, they learn, they take over
  • Documentation written *as* the work is done, not at the end

Artefacts

  • Implementation log with per-change evidence
  • IaC repository (where applicable) with pull-request history
  • As-built documentation updated against the design

What the client sees

A working capability that matches the design and is fully documented. Their team was part of the build, so the handover is not a surprise — it is a continuation of work they have been watching for weeks.

05

Verify

Prove it works — before declaring it works

Verification is non-optional. We do not declare an engagement complete until we have evidence the capability works against the threats it was built for. This is where we stress-test the detection rules, tabletop the incident response, and close out the assessment gaps raised in Phase 2.

Activities

  • Detection validation — atomic red team, purple team, or Microsoft Sentinel validation playbooks
  • Tabletop exercise for the top two or three incident types
  • Coverage review against MITRE ATT&CK and the original gap backlog
  • Control effectiveness testing against the compliance framework in scope
  • Formal closure of Phase 2 findings with evidence

Artefacts

  • Verification report with test cases, results, and coverage maps
  • Tabletop exercise output with decisions and lessons
  • Final gap-backlog status — closed, deferred, or accepted

What the client sees

Proof, not promises. They have a document they can put in front of a regulator, a board, an insurer, or a customer that shows the capability works — and the evidence to back it up.

06

Operate

Hand over, stay available

The final phase is the hardest to do well. Most consultancies leave on the day the invoice clears. We do not. Operate phase covers the structured handover, the first operational cycles under the client's own team, and a defined aftercare window so problems surface while we can still help.

Activities

  • Knowledge transfer sessions recorded and added to the client's internal wiki
  • Run-alongside period where we shadow the client's operators
  • Defined aftercare window with named escalation path
  • Retainer option if the client wants ongoing support
  • Post-engagement review points agreed during scoping

Artefacts

  • Handover pack with runbooks, credentials (rotated), contact tree, escalation path
  • Recorded knowledge transfer sessions
  • Aftercare response model and named point of contact

What the client sees

A consultancy that cared whether the work outlived the engagement. The client's team feels ownership of the capability — not abandoned by a contractor who left on day one of handover.

Operating Principles

The rules we hold ourselves to — regardless of the engagement type.

Evidence over assertion

Every finding, design decision, and closure statement is backed by a specific artefact the client can inspect. 'Trust us' is not a deliverable.

Client ownership by default

We build so the client's team can operate. If a capability depends on CyberZonic being there forever, we have designed it wrong.

No theatre reporting

Dashboards exist to drive decisions, not to decorate a slide deck. If a number has no action attached, we do not report it.

Honest pacing

We scope to the work that genuinely fits the window. If the ask is unrealistic, we say so before the contract is signed — not three months in.

Security of the engagement itself

Credentials, evidence packs, and client data are handled with the same discipline we advise our clients to use. Encrypted transport, least privilege, audit trails.

Ready to start scoping

Bring us the pressure point. We will come back with a shaped engagement, not a template.

A scoping conversation is short, structured, and no-commitment until both sides agree the fit is right.