Every UAE enterprise CISO we work with has the same architecture diagram taped to the wall. Zero Trust in bold at the top. Concentric circles of colour underneath. Vendor logos scattered across the periphery. Somewhere behind the diagram sits the operational reality: MFA enforced on 60% of accounts, privileged access managed through shared credentials in a password vault someone set up in 2021, network segmentation described as "we have a firewall," and logging that captures enough to satisfy the audit checkbox and nothing more.
The instinct is to buy a Zero Trust platform. The instinct is expensive and it does not fix the underlying gap. What fixes the gap is implementing the four foundational controls properly — identity that cannot be bypassed by an internal account, privileged access with an audit trail no one can edit, segmentation that limits what a compromised endpoint can reach, logging adequate to reconstruct an incident three months after it happened. B9 does that work on a fixed scope in 6–12 weeks.
Six streams,
ending in four controls live.
Gap assessment and identity hardening front-load weeks 1–4. Privileged access, segmentation, and logging overlap through weeks 4–10. Evidence pack and handover close weeks 10–12.
Gap assessment
Current state measured for MFA coverage, PAM controlled percentage, segmentation topology, and log coverage. Wave sequence agreed before enforcement begins.
Identity hardening
MFA enforcement expanded by wave with rollback procedures rehearsed per wave. Conditional access policies. Session controls.
Privileged access governance
PAM tool selected on scorecard, privileged accounts inventoried, workflows designed for approval, session recording, and just-in-time access.
Segmentation
Segmentation model designed to actual asset criticality, implementation phased with change windows, rollback rehearsed per wave.
Logging coverage
Collection expanded to cover the three post-incident questions, retention configured against regulatory requirement, integrity controls verified.
Evidence pack & handover
Audit-ready evidence pack, operator runbooks per control, incident-reconstruction rehearsal, 30/60/90-day check-ins.
Twelve weeks maximum.
Six minimum. Four phases.
Phase count is fixed. Duration flexes with account population, privileged-account count, and the number of change windows available for MFA and segmentation waves. Milestones are signed gates — not aspirations.
Controls scored,
not on vendor slideware.
Every engagement runs a six-criteria scorecard in weeks 1–2. Each candidate platform scored 1–5 against evidence from your own estate. Signed by the CISO before Phase 2 begins.
From trust everything
to verify everything.
A typical pre-engagement state has partial MFA, shared privileged credentials, a flat internal network, and logs that cannot reconstruct an incident. The engagement builds two control planes with change-windowed rollout.
Reference pattern. Some engagements retain an existing PAM or logging platform where the scorecard result favours it. What always changes is that enforcement stops being partial and evidence stops being incomplete.
A financial institution,
hardened.
Representative pattern for a UAE financial institution of this scale — MFA at 60%, no PAM, incomplete logging, an open audit finding. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.
Five artifacts,
each with signed acceptance.
Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.
Identity Hardening
MFA enforcement waves, conditional access policies, and session controls — each wave with a rehearsed rollback procedure.
Privileged Access Governance
PAM implementation with session recording and just-in-time access workflow. Standing privilege replaced, not documented.
Segmentation Model
Designed to actual asset criticality, implemented in phases inside agreed change windows.
Logging Coverage
Collection, retention against regulatory requirement, and integrity controls verified.
Evidence Pack & Incident-Reconstruction Runbook
Evidence pack demonstrating each control at operational coverage, plus a rehearsed runbook for incident reconstruction using the new logging estate — the document your incident team opens under pressure, and the one the auditor reads afterwards.
Six outcome metrics,
measured pre and post.
Success is not "Zero Trust is implemented." It is measured against six specific outcomes captured in a baseline report at engagement start and re-measured at post-handover steady state.
Honest scoping.
B9 is a fit when specific conditions are met. It is not a fit when other conditions are. We say so before the scope conversation, not after the commercial commitment.
[[A4|A4 Security Posture Scorecard™]] or equivalent internal work. B9 closes a documented gap set; it does not discover one.
Enforcement decisions and exception approvals need a named owner who can say no to a business unit.
Both teams deliver alongside us. Segmentation and MFA cannot be implemented around them.
Named windows for MFA waves and segmentation phases. Compressed windows extend timeline or narrow scope.
Bi-weekly reviews, and the escalation path when a business unit resists enforcement.
Start with A4 Security Posture Scorecard™ — three weeks to the documented gap set.
That's C7 SecOpsCommand™ or an MSSP. B9 builds the controls; it does not operate them.
That's B10 SOC Integration Build™ — detections into structured response.
Honest scope conversation about a defensible subset. We do not compress rehearsed rollback to hit a date.
Fixed fee.
Milestone-based.
Total engagement fee agreed in the scope statement. Not time-and-materials. Not day rate. Every engagement is preceded by a scope conversation to ensure fit before commitment.
Five, most asked.
Q_01Isn't "Zero Trust" mostly marketing at this point?
The label is. The controls are not. Strip away the vendor slideware and Zero Trust is four things: identity that cannot be bypassed, privileged access that leaves an audit trail, segmentation that limits lateral movement, and logging that lets you reconstruct what happened.
B9 implements those four things and delivers the evidence pack that proves it. Whether anyone calls it Zero Trust afterwards is beside the point.
Q_02How do you roll out MFA without breaking operations?
Q_03Which privileged access tool do you recommend?
Q_04What does "logging coverage" actually mean in practice?
Q_05What comes after zero-trust controls are live?
One name
on the engagement letter.
A named Practice Lead is accountable for delivery, commercial outcomes, and the client relationship throughout the engagement. Not a project manager who disappears after kickoff. Not a partner who nods at the SOW and vanishes.
Practice Lead — Cybersecurity
Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.
Including scope amendments.
Signs off all 5 deliverables.
With executive sponsor.
Authorised to negotiate.
CEO within 24 hours.
30/60/90-day check-ins.
Prior. Peer. Next.
Security Posture Scorecard™
3-week security posture assessment that identifies the specific gaps B9 closes. Sensible if the gap set isn't already documented.
SOC Integration Build™
Peer build for organisations where the SOC response workflow needs building alongside the underlying zero-trust controls. Often paired B9 + B10 for a full defensive rebuild.
SecOpsCommand™
Managed security operations. Runs the zero-trust controls continuously — logging, PAM review, MFA exception handling, segmentation change control.
Thirty minutes.
No slide deck.
A structured 30-minute scope conversation with the Practice Lead. You describe current MFA coverage, how privileged access works today, and what your logs can reconstruct. We describe whether B9 is the right engagement — and if not, what is.
