
The "Feisty Fox Security" Desired State
Rate each control from 0 (Non-existent) to 3 (Optimised/Automated) to calculate your organisation's resilience score.
Critical
FIDO2/Passkeys enforced for all cloud (M365/Google) and VPN access. SMS/Push-only is now a "1".
Backups are encrypted, off-site, and logically air-gapped (cannot be deleted by compromised admin creds).
"Extreme Risk" vulnerabilities in internet-facing assets are patched within 48 hours of disclosure.
Zero persistent admin rights. Admins use separate, non-internet-facing accounts for all changes.
The "flat network" is dead. Workstations cannot talk to each other; they only talk to the gateway.
The "Eyes On"
All endpoint, cloud, and network logs flow into a central SIEM/XDR with automated alerting.
Use of AI-driven tools to baseline "normal" behavior and flag anomalies (e.g., unusual data egress).
Strict control over what "phones home." All non-essential outbound ports are blocked at the host level.
Do your vendors (like Base44 or hosting providers) meet the same E8 ML2 standard?
Training specifically covers AI-generated social engineering (voice/video clones).
No "Legacy IT" (unsupported OS/Apps) remains in the production environment.
You are a high-value target with low-level shields. One stolen credential could collapse the entire operation.
You have good hygiene, but a sophisticated actor (APT style) could likely dwell in your network for weeks undetected.
This is the Feisty Fox target. You assume the breach will happen, but your architecture ensures the attacker is trapped in a sandbox and your data is safe.
Where do these controls come from?
The controls in this scorecard are drawn from the 2026 Top 35 — a reordering of the DSD Top 35 strategies for the modern threat landscape.