What this covers
Start with what cannot be lost. Work backwards to every reachable path.
Crown-jewel protection fails when teams secure the final system but cannot see the identities, APIs and suppliers that lead to it.
01Define the consequence
- Identify the data, service or mission outcome that would create material harm.
- Record the systems, identities and trust boundaries that directly protect it.
- Attach business impact and accountable owners before technical prioritisation begins.
02Work backwards through the graph
- Trace upstream APIs, authentication paths, cloud relationships and supplier dependencies.
- Surface weak links that are low severity in isolation but meaningful when chained.
- Recalculate paths as exposed assets, ownership and controls change.
03Validate the shortest credible route
- Test each required hop under approved scope rather than assuming the graph relationship is exploitable.
- Capture failed as well as successful validation so defensive controls receive credit.
- Identify the smallest remediation breakpoint that removes the path to impact.
04Evidence delivered
- A crown-jewel-centred attack-path view.
- Per-hop validation and control evidence.
- Prioritised breakpoints with owner and retest status.