Cyber Security Roadmap - 90 Days
Attachments: ../../Untitled%203a74-6d99/CSI_Cyber_Security_Roadmap_90_Days.pdf Created: July 25, 2026 12:07 AM Document ID: DOC-1 Document Type: Plan Domain: Cyber Security Hierarchy: Playbook Languages: Not Applicable Last Updated: July 25, 2026 12:44 AM Migration Status: Migrated Owner: Cyber Space Infocom Remarks: Reviewed and approved as the CSI controlled working master on 2026-07-26. Recheck time-sensitive technical, pricing and legal details before external issue. Review Date: August 8, 2026 Review Priority: P3 Normal Source Archive: CSI DOCS.tar(1).gz Source Files: CSI_Cyber_Security_Roadmap_90_Days.pdf Source Formats: PDF Status: Under Review Version: v1.0
This page contains the readable working content migrated from the CSI source archive. Review and approve it before external or contractual use.
- Current source
### Page 1
CYBER SPACE INFOCOM
CYBER SECURITY SERVICES
CSI Cyber Security
Roadmap - 90 Days
A practical launch plan for internal lab validation, security assessment, system
hardening, Wazuh monitoring and a controlled client pilot.
Prepared for Cyber Space Infocom
Focus Defensive security services and managed monitoring
Timeline 90 days (cid:127) Six implementation phases
Version 1.0 (cid:127) July 2026
### Page 2
Cyber Security Roadmap (cid:127) 90 Days
Executive Direction
Recommended launch position: Start as a defensive security assessment, hardening and
monitoring provider. Do not launch with public penetration-testing, red-team or 24x7 SOC promises.
Initial Service Scope
(cid:127) IT Security Assessment: assets, accounts, updates, exposure, backup and risk review.
(cid:127) System Hardening: Windows, server, firewall, remote-access and permission improvements.
(cid:127) Vulnerability Management: authorized scanning, remediation planning and retesting.
(cid:127) Wazuh Security Monitoring: endpoint visibility, file integrity, inventory and security alerts.
Services to Hold for a Later Stage
(cid:127) Public-facing penetration testing or exploit execution.
(cid:127) Red-team engagements and malware analysis.
(cid:127) Digital forensics or breach-attribution guarantees.
(cid:127) 24x7 SOC and guaranteed incident-response commitments.
Operating Rule
Authorization first: No client scanning or testing begins without written authorization, defined assets,
exclusions, approved timings, backup confirmation and an emergency contact.
90-Day Phase Map
Phase Timing Outcome
1. Foundation Week 1-2 Scope, lab plan, documentation and authorization controls
2. Wazuh Lab Week 3-4 Endpoint monitoring and detection validation
3. Assessment
Week 5-6 Repeatable assessment and reporting process
Practice
1. Internal Pilot Week 7-8 CSI environment monitored for seven stable days
2. Client Pilot Week 9-10 Controlled deployment for 5-10 endpoints
3. Commercial
Week 11-12 Packages, pricing, reports and AMC offering
Launch
Making Technology Work for You | +91 90547 79647 Page 2
### Page 3
Cyber Security Roadmap (cid:127) 90 Days
Phase 1 - Foundation (Week 1-2)
Build the operating discipline before installing tools.
Required Client Documents
(cid:127) Written authorization and named approver
(cid:127) In-scope systems, IP addresses, locations and applications
(cid:127) Explicit exclusions and prohibited tests
(cid:127) Testing window and expected service impact
(cid:127) Backup-readiness confirmation
(cid:127) Emergency contact and stop-test procedure
(cid:127) Data-handling, evidence-retention and confidentiality rules
(cid:127) Remediation and retest responsibilities
Minimum Knowledge Track
Area Practical target
Networking TCP/IP, VLAN, NAT, DNS, DHCP, VPN, firewall rules and packet flow
Windows Event logs, Defender, local policies, AD basics, RDP and permissions
Linux Authentication logs, users, services, packages, SSH and system hardening
Detection Wazuh alerts, log review, false positives and escalation
Frameworks CIS Controls, MITRE ATT&CK; and basic incident-response workflow
Commercial boundary: Security monitoring is a risk-reduction service, not a guarantee that a breach
cannot occur.
Making Technology Work for You | +91 90547 79647 Page 3
### Page 4
Cyber Security Roadmap (cid:127) 90 Days
Phase 2 - Build the CSI Security Lab (Week 3-4)
Use the current Ryzen 5600G system for testing only; keep production client monitoring
separate.
Recommended Lab Topology
Layer Component Purpose
OPNsense CSI-SEC-LAB
Network Isolation, firewall control and safe test boundaries
VLAN
Central alerts, inventory, FIM, SCA and vulnerability
SIEM/XDR Ubuntu Server + Wazuh
visibility
Endpoint Windows 11 VM Primary Windows alert and hardening tests
Server Windows Server evaluation VM AD, RDP, account and server-event practice
Linux Linux test VM SSH, authentication and system-log practice
Test host Kali Linux Authorized scanning inside the isolated lab only
Wazuh VM Starting Allocation
Resource Allocation
Operating system Ubuntu Server 24.04 LTS
CPU 4 vCPU
Memory 8-12 GB RAM
Storage 100 GB SSD
Network Static IP in isolated lab VLAN
Backup Daily configuration backup plus tested restore notes
Exposure control: Do not expose the Wazuh dashboard directly to the internet. Use LAN, VPN or
tightly controlled remote access.
Making Technology Work for You | +91 90547 79647 Page 4
### Page 5
Cyber Security Roadmap (cid:127) 90 Days
Detection and Testing Plan
Every lab test must record the activity, resulting alert, expected technician response and
closure evidence.
Wazuh Capability Sequence
1 Agent enrollment - Connect Windows and Linux endpoints and confirm stable reporting.
2 Event collection - Review Windows event logs and Linux authentication logs.
3 Inventory - Validate hardware, operating-system and installed-software data.
4 Vulnerability visibility - Review detected exposures and verify remediation priority.
5 Security Configuration Assessment - Compare endpoint configuration against available policies.
6 File Integrity Monitoring - Monitor defined files and folders for controlled changes.
7 Security alerts - Tune severity, ownership, response notes and notification rules.
Safe Detection Tests
Test Expected validation
Multiple failed Windows logins Authentication alert and source/user evidence
Create a local administrator Account/group change detection
Modify a monitored file FIM alert with file path and change context
EICAR antivirus test file Harmless Defender test alert; no live malware
Install unauthorized software Inventory change and software review
Connect USB storage Device event visibility where supported
Repeated failed SSH logins Linux authentication alert
Change a firewall/security setting Configuration-change evidence
Safety: Use test accounts and harmless simulation files only. Never place live malware in the CSI lab.
Making Technology Work for You | +91 90547 79647 Page 5
### Page 6
Cyber Security Roadmap (cid:127) 90 Days
Phase 3 - Security Assessment Workflow (Week 5-6)
The deliverable is not a scanner output. It is a risk-based report with evidence, remediation
and retest status.
Step Activity Deliverable
Discover business-critical systems, users, remote access and
1 Confirmed scope
backup dependencies.
Inventory hardware, software, accounts, network devices and
2 Asset register
public services.
Review updates, antivirus, RDP, SMB, firewall, Wi-Fi, VPN and
3 Control findings
permissions.
Run authorized inventory and vulnerability scans at approved
4 Validated exposures
intensity.
Prioritize by exploitability, exposure, business impact and existing
5 Risk ratings
controls.
6 Remediate, retest and record accepted residual risk. Closure report
Required Finding Format
(cid:127) Finding title and affected asset
(cid:127) Evidence and observation date
(cid:127) Business impact and likelihood
(cid:127) Severity with clear reasoning
(cid:127) Recommended remediation
(cid:127) Responsible owner and target date
(cid:127) Retest result: open, mitigated, accepted or closed
Approved Tools for the Initial Stage
(cid:127) Nmap: authorized asset and service discovery.
(cid:127) Greenbone/OpenVAS: controlled vulnerability assessment.
(cid:127) OWASP ZAP: owned or explicitly authorized web applications only.
(cid:127) Wazuh: endpoint posture, events, inventory and security monitoring.
Production caution: Aggressive scans are not the default. Confirm scan profile, timing, backups and
system owner approval first.
Making Technology Work for You | +91 90547 79647 Page 6
### Page 7
Cyber Security Roadmap (cid:127) 90 Days
Phase 4 - CSI Internal Pilot (Week 7-8)
Monitor CSI infrastructure first and convert the lessons into a repeatable client process.
Pilot Scope
(cid:127) Linux Mint server and Docker host
(cid:127) OPNsense security and authentication logs
(cid:127) Portainer/Docker events
(cid:127) RustDesk server where relevant
(cid:127) One Windows office or test computer
(cid:127) One controlled test user account
Success Criteria
Acceptance check Target
Agent stability All selected agents continuously connected for seven days
Alert quality Known false positives documented and tuned
Response Critical notification and escalation path tested
Operations Daily review completed in 20-30 minutes
Reporting Weekly management report generated
Recovery Wazuh configuration backup and restore procedure validated
Phase 5 - First Client Pilot (Week 9-10)
Parameter Recommended pilot
Endpoints 5-10
Servers 1
Firewall/router 1
Duration 30 days
Mode Monitoring and reporting; automatic blocking initially disabled
Review Weekly security review plus final remediation report
Privacy boundary: Cybersecurity monitoring and employee monitoring are separate services. Do not
use security telemetry as covert staff-surveillance data.
Making Technology Work for You | +91 90547 79647 Page 7
### Page 8
Cyber Security Roadmap (cid:127) 90 Days
Phase 6 - Commercial Launch (Week 11-12)
Launch three clear packages that match CSI's present capability and avoid unsupported
promises.
Package Included scope
Asset inventory; updates and antivirus; administrator accounts; firewall and
1. Security Health Check
remote-access review; backup readiness; findings report.
Health Check plus Windows/server hardening; firewall cleanup; permissions;
1. Security Hardening
RDP/VPN security; backup protection; remediation and retest.
1. Managed Security Hardening plus Wazuh deployment; vulnerability and file-integrity monitoring;
Monitoring alert review; monthly report; defined notification process.
Security Onion Expansion Gate
(cid:127) Wazuh is operational and the alert-review process is stable.
(cid:127) A managed switch with SPAN/mirror capability is available.
(cid:127) A dedicated second NIC is available for packet capture.
(cid:127) There is a separate physical system or properly resourced dedicated host.
(cid:127) CSI is ready to learn Suricata, Zeek, PCAP analysis and network detection.
Do not combine prematurely: Do not run Wazuh and a production-style Security Onion deployment
together on the current shared CSI server.
Immediate Next Actions
1 Create the isolated CSI-SEC-LAB VLAN in OPNsense.
2 Prepare an Ubuntu Server VM and install Wazuh all-in-one.
3 Enroll one Windows 11 test VM.
4 Run and document ten safe detection tests.
5 Finalize the CSI Security Assessment Report template.
6 Complete a seven-day internal monitoring pilot.
7 Review the results before selecting the first client pilot.
Making Technology Work for You | +91 90547 79647 Page 8
### Page 9
Cyber Security Roadmap (cid:127) 90 Days
Reference Standards and Official Guidance
The roadmap uses recognized defensive-security frameworks and official platform
guidance. Requirements should be rechecked before each production deployment.
Source Use in this roadmap
All-in-one deployment guidance, endpoint scale and starting hardware
Wazuh Quickstart
recommendations.
Security Onion Hardware Evaluation, standalone and production sizing; NIC and storage
Requirements considerations.
Common language for adversary tactics, techniques, detection and
MITRE ATT&CK;
assessment.
Prioritized controls for inventory, secure configuration, vulnerability
CIS Controls v8.1
management, logging, recovery and response.
OWASP Web Security Testing Structured web-application testing guidance for explicitly authorized
Guide targets.
90-day objective: CSI should be able to inventory an environment, identify weaknesses, detect
defined security events, recommend remediation and verify closure with evidence.
CYBER SPACE INFOCOM
IT Infrastructure (cid:127) AI (cid:127) Cyber Security
Making Technology Work for You
Making Technology Work for You | +91 90547 79647 Page 9