Back to selected work

GRC strategy / Radical Resilience

Make resilience part of the operating model.

A proposed defense-sector framework connecting sensitive data, suppliers, control evidence, and operational continuity.

Interlocking titanium bands and blue glass suggesting continuity and resilience
Conceptual artwork / Higgsfield
Context
Defense-sector strategy
Contribution
Framework design & research
Project type
Proposed framework

Scope

Four connected risk domains

Method

Controls, evidence, ownership

Output

Phased implementation roadmap

01 / The problem

A control is only as strong as the process around it.

Sensitive information moves through employees, suppliers, enterprise systems, and manufacturing environments. An access policy can fail if a supplier connection bypasses its assumptions or nobody notices when the environment changes.

Radical Resilience explores governance, risk, and compliance as an ongoing practice. The challenge is sequencing scope, ownership, and controls—then collecting enough evidence to understand whether those controls still work.

Information crosses boundaries

Data protection depends on understanding where sensitive information lives and who can move it.

Operations must continue

Security changes need to account for manufacturing dependencies and the cost of interruption.

Readiness needs evidence

A documented policy and a working control are different claims. Both need an accountable owner.

02 / My contribution

Connect the domains, then sequence the work.

I organized the strategy around four connected domains, a five-level maturity model, and a staged roadmap: a progression from inconsistent practices toward repeatable, measured improvement.

A connected control map

Group controls by the risk they address and expose the dependencies between domains.

A maturity progression

Move from ad hoc activity through documented, standardized, measured, and improving practices.

An implementation sequence

Establish foundations before expanding monitoring, automation, and more advanced detection.

03 / How it works

Explore the resilience framework.

Explore the scope, evidence, and sequence behind the proposed approach.

Interactive system modelExplore the logic

01 / Scope

Four domains, shared dependencies.

The interfaces between risk domains deserve equal attention.

Shared foundation / Scope · Ownership · Evidence
Stage 01 / Information

Data protection

Identify sensitive information, its approved locations, and the people or services that need it. Classification, authentication, access control, and encryption address different parts of that path. The model treats their coordination as essential to protecting information across its lifecycle.

Conceptual views of the proposed framework, evidence cycle, and implementation sequence.

Read all model notes
Control domains
  1. Data protection — Identify sensitive information, its approved locations, and the people or services that need it. Classification, authentication, access control, and encryption address different parts of that path. The model treats their coordination as essential to protecting information across its lifecycle.
  2. Supply chain — Vendor assessment should consider both the information a supplier receives and the service the organization depends on. The proposed approach connects due diligence with ongoing review so that a changed service, connection, or business relationship can trigger a fresh assessment.
  3. Compliance — The original framework references CMMC, NIST 800-171, and DFARS in its defense-sector context. This view focuses on the operating principle: translate applicable requirements into owned controls and evidence.
  4. IT / OT — Network segmentation and endpoint protection belong within a broader understanding of operational dependencies. A proposed change needs an owner who understands its effect on production. The framework therefore connects technical protection with continuity planning and a deliberate approach to implementation.
Evidence loop
  1. Define — Begin with what the control should accomplish. Identify who maintains it and what would demonstrate that it works. This conceptual step prevents a collection of screenshots or policies from becoming a substitute for a clear statement of control effectiveness.
  2. Review — Review configuration, records, and exceptions against the control's purpose. Evidence needs context: what system it covers, when it was collected, and what it cannot prove. Human judgment remains necessary to distinguish a documentation gap from an operational exposure.
  3. Improve — Turn a finding into an owned action with a reason for its priority. After a change, check whether the intended behavior is observable. Repeat the review when systems or dependencies change, keeping the roadmap responsive to the actual environment.
Roadmap
  1. Foundation — The first phase proposes a gap assessment, governance structure, baseline security controls, and the start of a vendor assessment program. Its purpose is to make the environment understandable enough that later investment addresses known gaps instead of adding disconnected tools.
  2. Acceleration — The next phase proposes continuous monitoring, compliance workflow automation, broader supplier coverage, and tabletop exercises. These activities depend on usable inventories and clear ownership. Exercises provide a way to question assumptions before an incident tests them under pressure.
  3. Optimization — The final phase explores more advanced detection, reporting, supply-chain verification, and access architecture. Automation should inherit explicit boundaries and escalation paths. Its value would need to be demonstrated through reviewable evidence rather than assumed from the sophistication of the technology.

Choose a perspective, then select a stage. Keyboard: arrow keys switch perspectives.

Implementation logic / Proposed roadmap

Progress when the foundations hold.

Each phase creates the conditions for the next. The calendar provides a planning horizon; evidence determines readiness.

  1. Months 1–6

    Foundation

    Make the environment understandable.

    • Assess gaps and define scope
    • Assign governance and control owners
    • Establish baseline controls
    • Begin supplier assessments
    Readiness gateScope & ownership are clear

    Known gaps have accountable owners. Baseline controls have reviewable evidence.

  2. Months 7–12

    Acceleration

    Build a repeatable review cycle.

    • Expand monitoring coverage
    • Automate recurring evidence tasks
    • Review critical supplier exposure
    • Practice response through exercises
    Readiness gateMonitoring leads to action

    Signals reach responsible people. Exercises reveal gaps that can be tracked and resolved.

  3. Year 2 onward

    Optimization

    Improve what can be measured.

    • Evaluate advanced detection
    • Refine reporting automation
    • Strengthen supplier verification
    • Revisit access and trust boundaries
    Continuing reviewChanges earn their place

    Evaluate effectiveness, exceptions, and operational impact. Keep human escalation available.

Derived from the proposed Radical Resilience roadmap. Readiness gates clarify its dependencies; phase timing does not establish achieved maturity.

04 / Key decisions

The choices behind the solution.

DecisionWhy it mattersTradeoff to manage

Connect control domains

Why it mattersA control catalogue can hide dependencies.

The tradeoffShared ownership requires deliberate coordination.

Sequence maturity before automation

Why it mattersAutomation needs stable processes and reliable inputs.

The tradeoffFoundational work offers less immediate visual impact.

Separate evidence from ambition

Why it mattersA target cannot prove control effectiveness.

The tradeoffProgress requires explicit review, beyond a completion score.

05 / What it produced

A strategy that makes the next decisions clearer.

The framework, maturity progression, and roadmap show how I translate a broad security problem into connected responsibilities and a practical sequence.

The original presents projected outcomes. This case establishes no completed audit, certification, or measured operational improvement.

01 / DELIVERABLE

Domain map

A shared vocabulary for data, suppliers, compliance, and operational systems.

02 / DELIVERABLE

Maturity model

A way to discuss capability development without treating maturity as a certification.

03 / DELIVERABLE

Staged roadmap

A proposed sequence that makes prerequisites and future evaluation visible.

Resilience is the ability to keep learning.

A useful framework creates feedback. As systems and constraints change, the organization needs to revisit ownership, reassess exposure, and adapt its plan.

Project context & references

2023 · Proposed framework

Next / The Algorithmic Shift

Understand the people around the technology.