Project X IT application suite

Resilience Workbench

Reverse engineer business functions from operational data, map the people and assets that support them, and guide each organization toward an owned, secured, and recoverable target state.

The target model

More than an employee in a department.

Person and positionWho the person is, which position they occupy, employment status, manager, department, executive hierarchy, and accountable owner.
Function allocationOne person may perform several business functions. Each allocation carries a percentage, required role, system access, and loaded labor cost.
Operating costVendor, software, infrastructure, audit, staffing, separation-of-duties, and resilience costs are attached to the functions they support.
Business impactMTD, RTO, RPO, dependency, data, regulatory, and financial context give the risk engine both the cost to operate and the exposure of disruption.

Evidence needs business context

A baseline is not a declaration of security.

Configuration auditShows the observed current state of accounts, permissions, software, services, ports, jobs, controls, and exceptions. It cannot decide whether that state is required by the business.
Penetration testTests whether implemented controls prevent or expose attack paths within the tested scope and time window. It can show that controls are working as intended, insufficient, or bypassable, but it cannot prove that access itself is authorized. If the wrong person is placed in an approved group, the technical control may function exactly as configured while the data and environment remain insecure.
Business comparisonLinks each person, service account, system, database, application, privilege, and communication path to an approved function, role, owner, data purpose, and resilience requirement.
Security conclusionBecomes defensible only after observed evidence is compared with that approved target model, gaps are remediated, and the resulting controls are continuously verified.

Reverse engineering workflow

Build the model from the customer data that already exists.

Directory, business system, cloud, scanner, host, log, and owner input are reconciled into an evidence-backed operating model.

01

Map the business

Define functions, executive ownership, people, positions, costs, dependencies, and recovery obligations.

02

Discover the environment

Identify accounts, assets, applications, databases, data, services, ports, communications, and vendors.

03

Establish the baseline

Preserve the current observed state with scope, source, collection time, and evidence lineage.

04

Approve the target

Define required access, controls, data flows, staffing, resilience, and accepted exceptions by function.

05

Remediate and verify

Assign and fund gaps, implement changes, recollect evidence, and independently confirm outcomes.

06

Monitor for drift

Run routine audits, notify owners when approved state changes, and reopen remediation until resolved.

Connected applications, one evidence model

Business impact, system security plans, identity, assets, and industry standards complete the picture together.

Each application contributes to the same operating model, so compliance artifacts become outputs of how the organization is actually owned, protected, and recovered.

Business impact analysis

Identify critical functions, owners, dependencies, workarounds, maximum tolerable downtime, and recovery priorities.

System security plans

Document company-specific users, groups, jobs, services, data, ports, communications, access, and control implementation.

Industry standards

Import configuration and vulnerability results, track exceptions, assign ownership, and verify remediation.

Identity and zero trust

Compare actual access to function requirements and drive toward least privilege, approved data flows, and continuous verification.

Policy and adherence

Generate separate policy and procedure foundations, then monitor evidence, practice, staffing capacity, and outcomes.

Assurance reporting

Track progress across NIST CSF, SOC 2, ISO 27001, privacy overlays, recovery planning, and customer-defined obligations.

Business value

Turn security evidence into executive decisions and measurable resilience.

The operating model connects ownership, risk, cost, recovery, and control evidence so leaders can act before an incident forces the decision.

Fiduciary oversight evidence

Maintain reporting systems, accountable ownership, red-flag escalation, risk decisions, remediation status, and review history that boards, officers, counsel, and auditors can use in Caremark-related oversight processes.

Resilience with a business clock

Connect dependencies and recovery capability to CFO-approved MTD, RTO, and RPO so recovery investment protects the functions and timelines that matter most.

Lower incident exposure

Reduce expected loss by removing unnecessary access, limiting communication paths, assigning unknown assets, closing control gaps, and verifying that response and recovery plans work.

Insurance-ready proof

Present current control evidence, asset and identity scope, quantified scenarios, remediation progress, and tested recovery capabilities during underwriting and renewal discussions.

The platform supports documented oversight and risk decisions; it does not determine whether fiduciary duties are satisfied or provide legal advice. Stronger evidence and controls may support cyber-insurance underwriting and reduce total risk cost, but carriers determine coverage, terms, and premiums. See the Delaware Court of Chancery's discussion of Caremark oversight, the SEC cybersecurity governance rule, and NIST CSF 2.0.

Network visualization representing connected systems and evidence

Protected customer workspace

A public site outside. A tenant-isolated workbench inside.

The public Project X IT site explains the service. Customer functions, identities, evidence, reports, and documentation remain within the authenticated portal and are authorized again on the server for every request.

  • Customer-specific workspaces and tenant authorization
  • MFA enrollment and account recovery controls
  • Encrypted evidence and tenant key separation design
  • Role-aware user, tenant administrator, and platform documentation
  • Administrative logging and investigation workflow

Turn scattered operational data into a defensible security and resilience model.

Plan a guided trial