two sections most guides leave out
How to verify. Nearly every hardening guide tells you to change a setting and stops there. Whether the setting applied is a different question from whether you set it: policy loses to a local override, a management profile fails silently on a subset of devices, and a tick in a console is not evidence. Every step here says how to confirm it took.
What it does not cover. A control trusted beyond its reach is worse than no control, because the gap it leaves is one nobody is looking at.
01
Whoever owns the build, in an estate that is already deployed
Three published baselines exist and they disagree with each other on purpose. Picking one and applying a subset beats reading all of them and applying none, which is what usually happens.
5 steps · 1 take minutes · 3 stated limits
02
Anyone asked to reduce phishing risk without a budget
Business email compromise remains the most commonly reported incident type, and in essentially every case where MFA was deployed it was defeated rather than absent. The technical layer is worth doing and it is not the layer that decides the outcome.
5 steps · 2 take minutes · 3 stated limits
03
Anyone publishing a report, responding to a request, or handling disclosure
Redaction failures are among the most reliably embarrassing incidents there are, because the document is usually already public by the time anybody notices and it cannot be recalled.
5 steps · 4 take minutes · 3 stated limits
04
Network and security staff sharing responsibility for the edge
Physical ports in meeting rooms, receptions and lecture theatres are an access route that nothing else on this site covers, and the controls are old, well understood and frequently unconfigured.
5 steps · 0 take minutes · 3 stated limits