Skip to main content
NexITC
B9 · CYBERSECURITY · 6–12 WEEKS · BUILD

Identity. Access.
Segmentation. Logging.

B9 · Zero-Trust Core Build™ implements the four core zero-trust controls that prevent the majority of breaches — identity hardening with MFA at coverage, privileged access governance, network segmentation, and logging coverage adequate to reconstruct an incident. Not a Zero Trust marketing exercise. The four controls, done properly.

DURATION
6–12 wks
DELIVERABLES
5 named
COMMERCIAL
Fixed fee
B9·PROJECTION / MFA COVERAGE
B9
BEFORE
60%
MFA · PRIVILEGED SUBSET
B9
AFTER
98%
MFA · ENFORCED COVERAGE
WK 00
WK 03
WK 06
WK 09
STEADY
MFA COVERAGE
98%
PAM CONTROLLED
60%
LOG COVERAGE ↑
95%
SCENARIO · UAE FINANCIAL · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY FOUR
CONTROLS.

Every UAE enterprise CISO we work with has the same architecture diagram taped to the wall. Zero Trust in bold at the top. Concentric circles of colour underneath. Vendor logos scattered across the periphery. Somewhere behind the diagram sits the operational reality: MFA enforced on 60% of accounts, privileged access managed through shared credentials in a password vault someone set up in 2021, network segmentation described as "we have a firewall," and logging that captures enough to satisfy the audit checkbox and nothing more.

The instinct is to buy a Zero Trust platform. The instinct is expensive and it does not fix the underlying gap. What fixes the gap is implementing the four foundational controls properly — identity that cannot be bypassed by an internal account, privileged access with an audit trail no one can edit, segmentation that limits what a compromised endpoint can reach, logging adequate to reconstruct an incident three months after it happened. B9 does that work on a fixed scope in 6–12 weeks.

STATE · TRUSTED
Partial MFA. Shared privileged credentials. Flat network. Logs incomplete. Audit findings recur.
STATE · VERIFIED
MFA at coverage. PAM with audit trail. Segmentation live. Logs answer post-incident questions.
§ 01 · WORK STREAMS

Six streams,
ending in four controls live.

Gap assessment and identity hardening front-load weeks 1–4. Privileged access, segmentation, and logging overlap through weeks 4–10. Evidence pack and handover close weeks 10–12.

STREAM 01
WK 01–02

Gap assessment

Current state measured for MFA coverage, PAM controlled percentage, segmentation topology, and log coverage. Wave sequence agreed before enforcement begins.

STREAM 02
WK 02–04

Identity hardening

MFA enforcement expanded by wave with rollback procedures rehearsed per wave. Conditional access policies. Session controls.

OUTCOME
4
CORE CONTROLS LIVE
+ AUDIT EVIDENCE PACK
STREAM 03
WK 04–07

Privileged access governance

PAM tool selected on scorecard, privileged accounts inventoried, workflows designed for approval, session recording, and just-in-time access.

STREAM 04
WK 06–09

Segmentation

Segmentation model designed to actual asset criticality, implementation phased with change windows, rollback rehearsed per wave.

STREAM 05
WK 08–10

Logging coverage

Collection expanded to cover the three post-incident questions, retention configured against regulatory requirement, integrity controls verified.

STREAM 06
WK 10–12

Evidence pack & handover

Audit-ready evidence pack, operator runbooks per control, incident-reconstruction rehearsal, 30/60/90-day check-ins.

EXPLICITLY NOT COVERED
Continuous security operations after handover
run by your SOC, your MSSP, or C7 SecOpsCommand™ as a managed retainer.
Detection engineering and response workflow
that is B10 SOC Integration Build™. B9 builds the controls the detections operate against.
§ 02 · TIMELINE

Twelve weeks maximum.
Six minimum. Four phases.

Phase count is fixed. Duration flexes with account population, privileged-account count, and the number of change windows available for MFA and segmentation waves. Milestones are signed gates — not aspirations.

WK 0102030405060708091011 · 12Phase 1 · Assessment & identityPhase 2 · PAM & segmentation designPhase 3 · Segmentation & loggingPhase 4 · Evidence packMFA waves enforcedEND WK 04 · GATE 01PAM live · segmentation designedEND WK 07 · GATE 02Segmentation & loggingEND WK 11 · GATE 03Evidence pack handoverEND WK 12 · GATE 04OPERATING RHYTHMDaily standup · Weekly change-board check-in · Bi-weekly Practice Lead reviewNAMED ACCOUNTABILITYPractice Lead — Cybersecurity (CEO escalationavailable)
§ 03 · APPROACH

Controls scored,
not on vendor slideware.

Every engagement runs a six-criteria scorecard in weeks 1–2. Each candidate platform scored 1–5 against evidence from your own estate. Signed by the CISO before Phase 2 begins.

ZERO-TRUST PLATFORM SELECTION SCORECARD · TEMPLATE
CRITERIA · 06 · WEIGHTED 1–5
ILLUSTRATIVE SAMPLE RENDERING — actual scores are engagement-specific and derived from evidence gathered during discovery.
01
UAE data residency
In-country storage for session recordings and PAM logs — PDPL, ADHICS v2, CBUAE cloud oversight where applicable.
5/5
02
Native IAM integration depth
Depth of integration with the identity provider you already run. Shallow integration pushes cost into custom connectors.
4/5
03
Approval-workflow flexibility
Whether the tool supports the approval patterns your CISO office actually operates, rather than the ones the vendor demo assumes.
4/5
04
Auditability of sessions and exceptions
Completeness and immutability of PAM session records and MFA exception history. Auditors read these.
5/5
05
Three-year TCO
Total cost at your privileged-account count, including growth. Licensing that scales per account punishes success.
3/5
06
Rollback and change-window support
Whether staged rollout and per-wave rollback are first-class features or improvised procedures.
4/5
!
DISCLOSURE · VENDOR-NEUTRALITY
NexITC maintains commercial arrangements with several ZTNA vendors, PAM providers, and SIEM/logging platforms — these are how specialist consultancies build sustainable practices. We do not disclose which arrangements exist publicly because we do not want them to influence tool choice by anyone reading this page. The scorecard exists precisely so selection happens on evidence, not on economics. In practice, we have recommended tools with which we have no partnership when the scorecard result favoured them.
§ 04 · ARCHITECTURE

From trust everything
to verify everything.

A typical pre-engagement state has partial MFA, shared privileged credentials, a flat internal network, and logs that cannot reconstruct an incident. The engagement builds two control planes with change-windowed rollout.

BEFORE · T=0
TYPICAL STATE
CONTROL_01
Partial MFA on user accounts
60% COVERAGE
CONTROL_02
Shared privileged credentials
PASSWORD VAULT
CONTROL_03
Flat internal network
SINGLE VLAN
CONTROL_04
Logs collected, incomplete
CHECKBOX ONLY
INCIDENT · RECONSTRUCTION
Cannot answer who authenticated, what was done, which boundary was crossed
OPERATIONAL REALITY
  • Internal accounts bypass MFA on legacy workflows
  • Privileged sessions unrecorded and unattributable
  • Lateral movement unconstrained after one compromise
  • Retention insufficient for post-incident forensics
B9 · VERIFY
AFTER · STEADY STATE
TARGET-STATE
PLATFORM_01
Identity Control Plane
MFA · Conditional Access · Session Controls
PLATFORM_02
Access & Segmentation
PAM · JIT · Segments · Change-Controlled
↓ VERIFIED · RECORDED · SEGMENTED · RECONSTRUCTABLE ↓
IDENTITY PROVIDER · RETAINED
Hardened, not replaced
STEADY-STATE OUTCOME
  • MFA enforced at audit-defensible coverage
  • Every privileged session recorded and attributable
  • Segmentation limits blast radius by asset criticality
  • Logging answers the three post-incident questions

Reference pattern. Some engagements retain an existing PAM or logging platform where the scorecard result favours it. What always changes is that enforcement stops being partial and evidence stops being incomplete.

§ 05 · REPRESENTATIVE SCENARIO

A financial institution,
hardened.

Representative pattern for a UAE financial institution of this scale — MFA at 60%, no PAM, incomplete logging, an open audit finding. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / B9 / UAE FINANCIAL · CBUAE SUPERVISED
DURATION · 08 WKS
MFA COVERAGE
98%
Enforced across account populations
PRIVILEGED ACCOUNTS REDUCED
60%
Standing privilege replaced by JIT access
LOG COVERAGE
95%
Against the three post-incident questions
SITUATION

UAE financial institution under CBUAE supervision. MFA enforced on 60% of accounts with legacy workflows exempted, privileged access run through shared vault credentials, flat internal network, logging insufficient to reconstruct an incident. An open audit finding with a supervisor commitment date.

ENGAGEMENT

8-week B9. Weeks 1–4 gap assessment and MFA enforcement in three waves with rehearsed rollback. Weeks 4–7 PAM selection on scorecard, privileged inventory, JIT workflow. Weeks 6–8 segmentation by asset criticality and logging expansion, closing with the evidence pack.

OUTCOME

MFA at 98% enforced coverage with two documented exceptions on expiry dates. Standing privileged accounts down 60%, every session recorded. Log coverage at 95% verified against a rehearsed incident reconstruction. Institution moved to C7 SecOpsCommand™ to operate the controls.

§ 06 · DELIVERABLES

Five artifacts,
each with signed acceptance.

Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.

D_01

Identity Hardening

MFA enforcement waves, conditional access policies, and session controls — each wave with a rehearsed rollback procedure.

D_02 · CORE

Privileged Access Governance

PAM implementation with session recording and just-in-time access workflow. Standing privilege replaced, not documented.

D_03

Segmentation Model

Designed to actual asset criticality, implemented in phases inside agreed change windows.

D_04

Logging Coverage

Collection, retention against regulatory requirement, and integrity controls verified.

D_05 · AUDIT-READY

Evidence Pack & Incident-Reconstruction Runbook

Evidence pack demonstrating each control at operational coverage, plus a rehearsed runbook for incident reconstruction using the new logging estate — the document your incident team opens under pressure, and the one the auditor reads afterwards.

HANDOVER
WK 12
§ 07 · OUTCOMES

Six outcome metrics,
measured pre and post.

Success is not "Zero Trust is implemented." It is measured against six specific outcomes captured in a baseline report at engagement start and re-measured at post-handover steady state.

THE MFA COVERAGE JOURNEY · REPRESENTATIVE
Sixty to ninety-eight, across the four phases.
98%MFA · STEADY
100%75%50%25%060%BaselinePRE-ENGAGEMENT78%Waves enforcedEND WK 0492%Exceptions closedEND WK 1198%Steady state30 DAYS POST
01 · MFA
95+%
Enforced MFA coverage across in-scope account populations.
02 · PAM
95+%
Privileged accounts under governed, recorded access.
03 · LOGGING
95+%
Log coverage against the three post-incident questions.
04 · VULN AGING
40–60%
Reduction in aging of privileged-surface vulnerabilities.
05 · FINDINGS
50–70%
Reduction in audit findings on next cycle.
06 · MTTR
Meas.
Mean time to respond on privileged-access incidents, baselined and re-measured.
§ 08 · FIT

Honest scoping.

B9 is a fit when specific conditions are met. It is not a fit when other conditions are. We say so before the scope conversation, not after the commercial commitment.

PREREQUISITES
Move fast when these five conditions are in place at kickoff.
01
A security posture assessment complete

[[A4|A4 Security Posture Scorecard™]] or equivalent internal work. B9 closes a documented gap set; it does not discover one.

02
The CISO as counterpart, with authority

Enforcement decisions and exception approvals need a named owner who can say no to a business unit.

03
IAM and network team engagement

Both teams deliver alongside us. Segmentation and MFA cannot be implemented around them.

04
Change windows agreed

Named windows for MFA waves and segmentation phases. Compressed windows extend timeline or narrow scope.

05
An executive sponsor

Bi-weekly reviews, and the escalation path when a business unit resists enforcement.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
No gap set defined

Start with A4 Security Posture Scorecard™ — three weeks to the documented gap set.

You want security operations run for you

That's C7 SecOpsCommand™ or an MSSP. B9 builds the controls; it does not operate them.

You need SOC workflow, not underlying controls

That's B10 SOC Integration Build™ — detections into structured response.

Regulatory deadline is under 4 weeks

Honest scope conversation about a defensible subset. We do not compress rehearsed rollback to hit a date.

§ 09 · COMMERCIAL

Fixed fee.
Milestone-based.

Total engagement fee agreed in the scope statement. Not time-and-materials. Not day rate. Every engagement is preceded by a scope conversation to ensure fit before commitment.

STANDARD MODEL
ENGAGEMENT MODEL
Fixed fee
PAYMENT CADENCE
Milestone-based

Payment schedule aligned to engagement phases and defined delivery milestones agreed upfront.


INCLUDED IN SCOPE
  • All 5 named deliverables with acceptance criteria
  • Named Practice Lead throughout the engagement
  • Bi-weekly executive sponsor reviews
  • 30/60/90-day post-handover check-ins
  • Written scope amendment process for any changes
01

Signed scope statement

Every engagement begins with a signed scope statement fixing deliverables, timeline, milestones, and commercial terms. No verbal agreements. No moving targets.

02

No scope creep

Scope changes require a signed scope amendment. If scope changes, so does the commercial arrangement — always in writing, always signed by both parties.

03

Named accountability

The Practice Lead is accountable for commercial and delivery outcomes throughout the engagement, with escalation to the CEO within 24 hours if needed.

§ 10 · QUESTIONS

Five, most asked.

Q_01Isn't "Zero Trust" mostly marketing at this point?

The label is. The controls are not. Strip away the vendor slideware and Zero Trust is four things: identity that cannot be bypassed, privileged access that leaves an audit trail, segmentation that limits lateral movement, and logging that lets you reconstruct what happened.

B9 implements those four things and delivers the evidence pack that proves it. Whether anyone calls it Zero Trust afterwards is beside the point.

Q_02How do you roll out MFA without breaking operations?
Sequenced enforcement with a real fallback plan. Coverage starts with the highest-risk populations — privileged users, external-facing accounts, admin roles — and expands in waves with named change windows. Each wave has a rollback procedure rehearsed before it goes live. If a wave surfaces a workflow the current MFA design cannot support, we redesign that specific workflow rather than granting a blanket exception. The engagement produces the coverage number that survives an audit, not the coverage number that reads well on a status slide.
Q_03Which privileged access tool do you recommend?
Selection runs the scorecard, not the vendor list. Criteria include UAE data residency for session recordings, native integration with your existing IAM, workflow support for the approval patterns your CISO office actually operates, and three-year TCO at your privileged-account count. We have shipped B9 on multiple PAM platforms. Vendor-neutral is a scorecard, not a slogan.
Q_04What does "logging coverage" actually mean in practice?
The ability to answer three specific questions after an incident. Who authenticated. What privileged action they took. Which system boundary was crossed. If your current logging cannot answer all three within a defined retention window, coverage is not complete. B9 measures against those questions on a representative incident scenario before hand-over.
Q_05What comes after zero-trust controls are live?
C7 SecOpsCommand™ operates the controls continuously — logging pipelines, PAM session review, MFA exception handling, segmentation change control. If you have an internal SOC or MSSP already, B9 hands over cleanly to them with the evidence pack and runbooks. If not, C7 is the sequenced next engagement.
§ 11 · NAMED ACCOUNTABILITY

One name
on the engagement letter.

A named Practice Lead is accountable for delivery, commercial outcomes, and the client relationship throughout the engagement. Not a project manager who disappears after kickoff. Not a partner who nods at the SOW and vanishes.

THE ROLE

Practice Lead — Cybersecurity

Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments.

02
Deliverables acceptance

Signs off all 5 deliverables.

03
Bi-weekly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
Post-handover

30/60/90-day check-ins.

§ 13 · BOOK A CLINIC

Thirty minutes.
No slide deck.

A structured 30-minute scope conversation with the Practice Lead. You describe current MFA coverage, how privileged access works today, and what your logs can reconstruct. We describe whether B9 is the right engagement — and if not, what is.

Book a clinic →Email directly
DURATION
30 minutes
PREPARATION
None required
FOLLOW-UP
Written scope, 5 business days