Roadmap For A Security And Resiliency Program

Jan 2019 - Updated Aug 2024

After trying several approaches, I found the following simple(ish) and scalable roadmap to be a good way to establish a foundational and stable security program with a focus on security resiliency. The roadmap includes four strategic phases, each focusing on building strong foundations, enhancing capabilities, and ensuring adaptability.

Remember, stagnant equals death, so even when you think you have a stable foundation and an ongoing program, revisit, assess, and change as needed. That's the critical component of a good resilient security program.

Timeline and Phase Summary

Times are best cases. Adjust as needed.

  1. Assessment Phase: 0–6 Months - Baseline security and building an IR foundation
  2. Enhancement Phase: 6–12 Months - Improving visibility and operational control
  3. Proactive Defense Phase: 12–24 Months - Advanced defenses and adaptability
  4. Continuous Improvement Phase: 24+ Months - Innovation and creation of a security culture

Phases In Depth

Phase 1: Assessment and Foundational Security (0–6 Months)

Goal: Establish a baseline and build the groundwork for an incident response program.

1. Assess Current State:

2. Define Security Resiliency Objectives:

3. Develop a Resiliency Framework:

4. Strengthen Incident Response (IR) Capability:

5. Implement Basic Hygiene:

Phase 2: Enhance Visibility and Detective Controls (6–12 Months)

Goal: Build detection capabilities and improve control mechanisms.

1. Enhance Monitoring:

2. Automate Threat Detection:

3. Improve Access Management:

4. Establish Redundancy:

5. Develop Contingency Plans:

Phase 3: Proactive Defense and Controls Adaptability (12–24 Months)

Goal: Build advanced defenses and prepare for emerging threats.

1. Conduct Regular Testing:

2. Collect Threat Intelligence:

3. Integrate "Chaos Security Engineering":

4. Expand Security Training:

5. Focus On Vendor and Supply Chain Security:

Phase 4: Continuous Improvement, Innovation, and Modernization (24+ Months)

Goal: Establish a culture of security and resilience, and continuous adaptation.

1. Foster a Security-First Culture:

2. Leverage Emerging Technologies:

3. Measure and Optimize:

4. Participate in Information Sharing:

5. Prepare for the Future: