Build practical, low-noise detection rules for password attacks and lateral movement — thresholds, correlation logic, and tuning against false positives.
Hardening items
13 recommendations. Filter by category, criticality, maturity tier, or system.
Stop drowning in criticals — prioritize patching using exploitation evidence (KEV, EPSS), asset exposure, and business context instead of raw CVSS.
Design realistic phishing simulations that measure and reduce risk — with metrics that matter, training that sticks, and without blaming users.
Apply the CIS Level 1 baseline to Ubuntu Server — filesystem, kernel, auditing, and service hardening — with automated scanning to measure progress.
Combine subnet-level NSGs with a centralized Azure Firewall in a hub-spoke topology for defense-in-depth network filtering.
Separate servers, clients, management interfaces, and IoT/OT devices into VLANs with inter-VLAN firewall rules to contain lateral movement.