Know and control
See every identity and asset you defend.
Practical playbooks, checklists, crosswalks, and 30/60/90-day plans to strengthen IT, protect operational technology, and secure sensitive defense information.
Independent resource. Official titles and source guidance remain authoritative.Official numbering remains authoritative. This sequence is our independent recommendation for resource-constrained teams.
See every identity and asset you defend.
Keep one breached device from becoming ten.
Close the gaps attackers reach first.
Prove you can restore before you need to.
Build new capability without new risk.
Keep your people and monitoring sharp.
Recommended implementation sequence by the Brilliant at the Basics Resource Center — not an official DoW ordering.
Every practice starts from an authoritative source. What we add is an independent implementation layer.
24-hour, 30-day, and 90-day work with owners.
Ways to prove a practice operates, not just that it was purchased.
Governance, configuration, operational, and validation records.
Caveated mappings to NIST, CMMC, CIS, and CSF.
Stop credential phishing from becoming account takeover.
A walked-down, verified list of every OT asset.
Contain a compromised account or device to one zone.
What the campaign asks for — and how this site helps you carry it out. Silent by design; everything is on screen.
Turning on the right settings is where most teams get stuck. These plain-language guides walk you through it — with diagrams and click-by-click checklists — for the ten requirements that matter most.
Each record identifies its publisher, provenance, and our most recent verification date.
The authoritative campaign page and source for the IT and OT Top 10 practices.
The department-level target architecture that the IT Top 10 supports.
The foundational reference for securing industrial control systems.