Last week, I shared an #M365 #Breakglass #MaturityModel:
https://www.linkedin.com/posts/graham-gold_m365-breakglass-maturitymodel-activity-7317135482914557953-DNUb
— and the response blew me away.
Thanks to brilliant feedback from folks like Artem Borodai, Kennedy Torkura, Colin M, and Nathan McNulty, I quickly evolved the model — and then Eli Shlomo (SR) took it even further with his epic Attacker’s Breakdown (must-read):
https://www.linkedin.com/posts/elishlomo_security-cybersecurity-activity-7320131888096923648-8cxX
So I’m excited to announce v1.1 is now live — and part of my KuShu-Atama repo under the KuShuSec tools banner:
https://github.com/KuShuSec/KuShu-Atama
What’s New in v1.1:
• Level 6: Isolated Resilience (e.g. red tenant BGA paths)
• Offline recovery support: QR codes, printed passphrases, and physical failovers
• Scoped Conditional Access exemption guidance
• Recovery planning for Microsoft outages, misconfigs, and attacker lockouts
• Support for alternate IDPs or external identity control planes
I’m still very much looking for feedback and contributors — feel free to drop thoughts here, or fork the repo and open a pull request.
Also: if there are other maturity models or mind maps you wish existed — drop the idea below or DM me. Always open to collaborations.
More to come!