Enterprise Security Lab

Building and securing modern enterprise IT.

Brunner Security Labs is a practical cybersecurity project demonstrating how a modern enterprise environment can be designed, protected, monitored and continuously improved.

Mission

A practical model for securing a modern organization.

The lab simulates the security environment of a small or medium-sized enterprise. It combines cloud identity, managed endpoints, security monitoring, governance and incident response into one integrated security program.

  • Design secure enterprise architecture
  • Implement identity and endpoint controls
  • Monitor activity and detect threats
  • Respond to incidents and improve security

Enterprise Security Architecture

A layered approach to enterprise security.

The lab follows a vendor-neutral security architecture in which identity, endpoint protection, monitoring, incident response and governance work together as an integrated security system.

01

Identity & Access Management

Authentication, authorization and controlled access to enterprise resources.

02

Endpoint Management & Compliance

Centralized device management, configuration and compliance assessment.

03

Endpoint Protection

Protection, detection and response capabilities for enterprise endpoints.

04

Monitoring & Detection

Centralized collection and analysis of security events and telemetry.

05

Incident Response & Forensics

Investigation, containment, recovery and evidence-based analysis.

06

Governance, Risk & Improvement

Policies, risk management, compliance and continuous security improvement.

Implementation Roadmap

Building the lab in structured implementation phases.

The roadmap shows which parts of the enterprise security architecture have already been implemented and which areas are currently being expanded.

01

Enterprise Foundation

Microsoft 365 tenant, Entra ID, Intune, SharePoint and Azure security services

Implemented
02

Identity & Access

Identity lifecycle, authentication, authorization and privileged access management

Implemented
03

Endpoint Security

Device management, compliance, encryption and endpoint protection

Implemented
04

Monitoring & Detection

Microsoft Sentinel, Defender telemetry, KQL analytics and detection engineering

In Progress
05

Governance & Compliance

Microsoft Purview, information protection, compliance assessments, auditing and Secure Score

Implemented
06

Incident Response & DFIR

Incident handling, investigation, evidence collection and forensic analysis

Planned