Government Network Defense
- Home
- Projects
Project Overview
A government agency (confidential) engaged me to deliver full-spectrum security operations across its network, from offensive infiltration testing through to defensive detection engineering. The remit was broad by design: prove where a capable adversary could get in, then leave the agency measurably harder to breach and far better able to see an attack in progress. I ran red- and purple-team assessments against a demanding, nation-state-grade threat model, engineered detections mapped to adversary behaviour, and uplifted the internal SOC with tuned tooling, runbooks and hands-on training. The work spanned legacy platforms and tightly segmented, air-gapped systems, and had to respect strict compliance and data-handling rules with zero tolerance for downtime on critical public services.
Challenges
- Defend against a nation-state-grade threat model with the resources and patience to match.
- Secure a mix of legacy platforms alongside tightly segmented and air-gapped systems.
- Operate within strict compliance and data-handling rules governing sensitive government data.
- Guarantee zero downtime on critical public services throughout every phase of the work.
- Close an internal skills gap so the security gains would outlast the engagement itself.
Approach
- Conducted red- and purple-team assessments to expose realistic paths to sensitive systems.
- Engineered detections mapped to MITRE ATT&CK to turn attacker behaviour into actionable alerts.
- Uplifted the SOC with tuned tooling, triage runbooks and repeatable response playbooks.
- Re-architected network segmentation and moved the environment toward zero-trust principles.
- Delivered hands-on training and knowledge transfer so the internal team could carry it forward.