← CSI Knowledge

Cyber Security Roadmap - 90 Days

name
Cyber Security Roadmap - 90 Days
source
Notion Export
migration_status
Imported
document_id
DOC-1
document_type
Plan
domain
Cyber Security
hierarchy
Playbook
status
Under Review
version
v1.0
owner
Cyber Space Infocom
created
July 25, 2026 12:07 AM
last_updated
July 25, 2026 12:44 AM
review_date
August 8, 2026
review_priority
P3 Normal
effective
next_review
languages
Not Applicable
source_archive
CSI DOCS.tar(1).gz
source_formats
PDF
source_files
CSI_Cyber_Security_Roadmap_90_Days.pdf
source_path
/home/csi/master/inbox/imports/notion-verify/staging/notion/Export-a01daa1a-664a-4975-9744-61a6104bc176/CSI Nexus тАФ Operating System/07 тАФ Document Library/Cyber Security Roadmap - 90 Days 3a74d7783953811aa450e0bac0026d99.md
classification_reason
CSI security documentation
06-Cybersecurity/Cyber Security Roadmap - 90 Days.md

Cyber Security Roadmap - 90 Days

Attachments: ../../Untitled%203a74-6d99/CSI_Cyber_Security_Roadmap_90_Days.pdf Created: July 25, 2026 12:07 AM Document ID: DOC-1 Document Type: Plan Domain: Cyber Security Hierarchy: Playbook Languages: Not Applicable Last Updated: July 25, 2026 12:44 AM Migration Status: Migrated Owner: Cyber Space Infocom Remarks: Reviewed and approved as the CSI controlled working master on 2026-07-26. Recheck time-sensitive technical, pricing and legal details before external issue. Review Date: August 8, 2026 Review Priority: P3 Normal Source Archive: CSI DOCS.tar(1).gz Source Files: CSI_Cyber_Security_Roadmap_90_Days.pdf Source Formats: PDF Status: Under Review Version: v1.0

This page contains the readable working content migrated from the CSI source archive. Review and approve it before external or contractual use.

  • Current source
### Page 1

CYBER SPACE INFOCOM

CYBER SECURITY SERVICES

CSI Cyber Security

Roadmap - 90 Days

A practical launch plan for internal lab validation, security assessment, system

hardening, Wazuh monitoring and a controlled client pilot.

Prepared for Cyber Space Infocom

Focus Defensive security services and managed monitoring

Timeline 90 days (cid:127) Six implementation phases

Version 1.0 (cid:127) July 2026

### Page 2

Cyber Security Roadmap (cid:127) 90 Days

Executive Direction

Recommended launch position: Start as a defensive security assessment, hardening and

monitoring provider. Do not launch with public penetration-testing, red-team or 24x7 SOC promises.

Initial Service Scope

(cid:127) IT Security Assessment: assets, accounts, updates, exposure, backup and risk review.

(cid:127) System Hardening: Windows, server, firewall, remote-access and permission improvements.

(cid:127) Vulnerability Management: authorized scanning, remediation planning and retesting.

(cid:127) Wazuh Security Monitoring: endpoint visibility, file integrity, inventory and security alerts.

Services to Hold for a Later Stage

(cid:127) Public-facing penetration testing or exploit execution.

(cid:127) Red-team engagements and malware analysis.

(cid:127) Digital forensics or breach-attribution guarantees.

(cid:127) 24x7 SOC and guaranteed incident-response commitments.

Operating Rule

Authorization first: No client scanning or testing begins without written authorization, defined assets,

exclusions, approved timings, backup confirmation and an emergency contact.

90-Day Phase Map

Phase Timing Outcome

1. Foundation Week 1-2 Scope, lab plan, documentation and authorization controls
2. Wazuh Lab Week 3-4 Endpoint monitoring and detection validation
3. Assessment

Week 5-6 Repeatable assessment and reporting process

Practice

1. Internal Pilot Week 7-8 CSI environment monitored for seven stable days
2. Client Pilot Week 9-10 Controlled deployment for 5-10 endpoints
3. Commercial

Week 11-12 Packages, pricing, reports and AMC offering

Launch

Making Technology Work for You | +91 90547 79647 Page 2

### Page 3

Cyber Security Roadmap (cid:127) 90 Days

Phase 1 - Foundation (Week 1-2)

Build the operating discipline before installing tools.

Required Client Documents

(cid:127) Written authorization and named approver

(cid:127) In-scope systems, IP addresses, locations and applications

(cid:127) Explicit exclusions and prohibited tests

(cid:127) Testing window and expected service impact

(cid:127) Backup-readiness confirmation

(cid:127) Emergency contact and stop-test procedure

(cid:127) Data-handling, evidence-retention and confidentiality rules

(cid:127) Remediation and retest responsibilities

Minimum Knowledge Track

Area Practical target

Networking TCP/IP, VLAN, NAT, DNS, DHCP, VPN, firewall rules and packet flow

Windows Event logs, Defender, local policies, AD basics, RDP and permissions

Linux Authentication logs, users, services, packages, SSH and system hardening

Detection Wazuh alerts, log review, false positives and escalation

Frameworks CIS Controls, MITRE ATT&CK; and basic incident-response workflow

Commercial boundary: Security monitoring is a risk-reduction service, not a guarantee that a breach

cannot occur.

Making Technology Work for You | +91 90547 79647 Page 3

### Page 4

Cyber Security Roadmap (cid:127) 90 Days

Phase 2 - Build the CSI Security Lab (Week 3-4)

Use the current Ryzen 5600G system for testing only; keep production client monitoring

separate.

Recommended Lab Topology

Layer Component Purpose

OPNsense CSI-SEC-LAB

Network Isolation, firewall control and safe test boundaries

VLAN

Central alerts, inventory, FIM, SCA and vulnerability

SIEM/XDR Ubuntu Server + Wazuh

visibility

Endpoint Windows 11 VM Primary Windows alert and hardening tests

Server Windows Server evaluation VM AD, RDP, account and server-event practice

Linux Linux test VM SSH, authentication and system-log practice

Test host Kali Linux Authorized scanning inside the isolated lab only

Wazuh VM Starting Allocation

Resource Allocation

Operating system Ubuntu Server 24.04 LTS

CPU 4 vCPU

Memory 8-12 GB RAM

Storage 100 GB SSD

Network Static IP in isolated lab VLAN

Backup Daily configuration backup plus tested restore notes

Exposure control: Do not expose the Wazuh dashboard directly to the internet. Use LAN, VPN or

tightly controlled remote access.

Making Technology Work for You | +91 90547 79647 Page 4

### Page 5

Cyber Security Roadmap (cid:127) 90 Days

Detection and Testing Plan

Every lab test must record the activity, resulting alert, expected technician response and

closure evidence.

Wazuh Capability Sequence

1 Agent enrollment - Connect Windows and Linux endpoints and confirm stable reporting.

2 Event collection - Review Windows event logs and Linux authentication logs.

3 Inventory - Validate hardware, operating-system and installed-software data.

4 Vulnerability visibility - Review detected exposures and verify remediation priority.

5 Security Configuration Assessment - Compare endpoint configuration against available policies.

6 File Integrity Monitoring - Monitor defined files and folders for controlled changes.

7 Security alerts - Tune severity, ownership, response notes and notification rules.

Safe Detection Tests

Test Expected validation

Multiple failed Windows logins Authentication alert and source/user evidence

Create a local administrator Account/group change detection

Modify a monitored file FIM alert with file path and change context

EICAR antivirus test file Harmless Defender test alert; no live malware

Install unauthorized software Inventory change and software review

Connect USB storage Device event visibility where supported

Repeated failed SSH logins Linux authentication alert

Change a firewall/security setting Configuration-change evidence

Safety: Use test accounts and harmless simulation files only. Never place live malware in the CSI lab.

Making Technology Work for You | +91 90547 79647 Page 5

### Page 6

Cyber Security Roadmap (cid:127) 90 Days

Phase 3 - Security Assessment Workflow (Week 5-6)

The deliverable is not a scanner output. It is a risk-based report with evidence, remediation

and retest status.

Step Activity Deliverable

Discover business-critical systems, users, remote access and

1 Confirmed scope

backup dependencies.

Inventory hardware, software, accounts, network devices and

2 Asset register

public services.

Review updates, antivirus, RDP, SMB, firewall, Wi-Fi, VPN and

3 Control findings

permissions.

Run authorized inventory and vulnerability scans at approved

4 Validated exposures

intensity.

Prioritize by exploitability, exposure, business impact and existing

5 Risk ratings

controls.

6 Remediate, retest and record accepted residual risk. Closure report

Required Finding Format

(cid:127) Finding title and affected asset

(cid:127) Evidence and observation date

(cid:127) Business impact and likelihood

(cid:127) Severity with clear reasoning

(cid:127) Recommended remediation

(cid:127) Responsible owner and target date

(cid:127) Retest result: open, mitigated, accepted or closed

Approved Tools for the Initial Stage

(cid:127) Nmap: authorized asset and service discovery.

(cid:127) Greenbone/OpenVAS: controlled vulnerability assessment.

(cid:127) OWASP ZAP: owned or explicitly authorized web applications only.

(cid:127) Wazuh: endpoint posture, events, inventory and security monitoring.

Production caution: Aggressive scans are not the default. Confirm scan profile, timing, backups and

system owner approval first.

Making Technology Work for You | +91 90547 79647 Page 6

### Page 7

Cyber Security Roadmap (cid:127) 90 Days

Phase 4 - CSI Internal Pilot (Week 7-8)

Monitor CSI infrastructure first and convert the lessons into a repeatable client process.

Pilot Scope

(cid:127) Linux Mint server and Docker host

(cid:127) OPNsense security and authentication logs

(cid:127) Portainer/Docker events

(cid:127) RustDesk server where relevant

(cid:127) One Windows office or test computer

(cid:127) One controlled test user account

Success Criteria

Acceptance check Target

Agent stability All selected agents continuously connected for seven days

Alert quality Known false positives documented and tuned

Response Critical notification and escalation path tested

Operations Daily review completed in 20-30 minutes

Reporting Weekly management report generated

Recovery Wazuh configuration backup and restore procedure validated

Phase 5 - First Client Pilot (Week 9-10)

Parameter Recommended pilot

Endpoints 5-10

Servers 1

Firewall/router 1

Duration 30 days

Mode Monitoring and reporting; automatic blocking initially disabled

Review Weekly security review plus final remediation report

Privacy boundary: Cybersecurity monitoring and employee monitoring are separate services. Do not

use security telemetry as covert staff-surveillance data.

Making Technology Work for You | +91 90547 79647 Page 7

### Page 8

Cyber Security Roadmap (cid:127) 90 Days

Phase 6 - Commercial Launch (Week 11-12)

Launch three clear packages that match CSI's present capability and avoid unsupported

promises.

Package Included scope

Asset inventory; updates and antivirus; administrator accounts; firewall and

1. Security Health Check

remote-access review; backup readiness; findings report.

Health Check plus Windows/server hardening; firewall cleanup; permissions;

1. Security Hardening

RDP/VPN security; backup protection; remediation and retest.

1. Managed Security Hardening plus Wazuh deployment; vulnerability and file-integrity monitoring;

Monitoring alert review; monthly report; defined notification process.

Security Onion Expansion Gate

(cid:127) Wazuh is operational and the alert-review process is stable.

(cid:127) A managed switch with SPAN/mirror capability is available.

(cid:127) A dedicated second NIC is available for packet capture.

(cid:127) There is a separate physical system or properly resourced dedicated host.

(cid:127) CSI is ready to learn Suricata, Zeek, PCAP analysis and network detection.

Do not combine prematurely: Do not run Wazuh and a production-style Security Onion deployment

together on the current shared CSI server.

Immediate Next Actions

1 Create the isolated CSI-SEC-LAB VLAN in OPNsense.

2 Prepare an Ubuntu Server VM and install Wazuh all-in-one.

3 Enroll one Windows 11 test VM.

4 Run and document ten safe detection tests.

5 Finalize the CSI Security Assessment Report template.

6 Complete a seven-day internal monitoring pilot.

7 Review the results before selecting the first client pilot.

Making Technology Work for You | +91 90547 79647 Page 8

### Page 9

Cyber Security Roadmap (cid:127) 90 Days

Reference Standards and Official Guidance

The roadmap uses recognized defensive-security frameworks and official platform

guidance. Requirements should be rechecked before each production deployment.

Source Use in this roadmap

All-in-one deployment guidance, endpoint scale and starting hardware

Wazuh Quickstart

recommendations.

Security Onion Hardware Evaluation, standalone and production sizing; NIC and storage

Requirements considerations.

Common language for adversary tactics, techniques, detection and

MITRE ATT&CK;

assessment.

Prioritized controls for inventory, secure configuration, vulnerability

CIS Controls v8.1

management, logging, recovery and response.

OWASP Web Security Testing Structured web-application testing guidance for explicitly authorized

Guide targets.

90-day objective: CSI should be able to inventory an environment, identify weaknesses, detect

defined security events, recommend remediation and verify closure with evidence.

CYBER SPACE INFOCOM

IT Infrastructure (cid:127) AI (cid:127) Cyber Security

Making Technology Work for You

Making Technology Work for You | +91 90547 79647 Page 9