Practice turning a hybrid, multicloud scenario into explicit infrastructure decisions, control ownership, dependencies, verification, and staged delivery.
Scenario
A manufacturer operates Azure applications, on-premises servers, remote offices, an AWS analytics workload, and an OT plant network. It lacks a consistent inventory, gives administrators broad VPN access, and cannot show which critical assets are reachable from the internet.
Step 1: Establish visibility
Onboard supported resources to Defender for Cloud and use Azure Arc where it provides the required management reach. Reconcile cloud inventories with EASM discoveries. Assign business criticality and ownership before ranking recommendations.
Step 2: Protect administration and access
Move human privilege to eligible, time-bound roles and secure workstations. Replace broad remote network access with application-specific private access where feasible. Isolate OT access through controlled jump paths with monitored sessions and safety-approved response actions.
Step 3: Define workload baselines
Create separate baselines for cloud services, general-purpose servers, user devices, and OT assets. Use policy and configuration management for enforceable settings, with exceptions that include owner, reason, compensating controls, and expiry.
Step 4: Verify outcomes
Measure unknown assets, critical attack paths, standing privileged assignments, baseline compliance, logging coverage, and tested containment or recovery procedures. Deliver in stages so visibility and privileged-access improvements reduce risk while longer workload changes proceed. Architect habit: State the requirement, decision, owner, dependency, evidence, and rollback or recovery path for every major control.