ciso.diy
C2 Companion — The Operator Node DIY Build preview
Security Program Pillars operator nodeC2self-hostedinfrastructure

C2 Companion — The Operator Node DIY Build

The box the security department runs on. Self-host the living risk register, the ISMS and the evidence vault on one hardened machine — zero inbound, hardware-rooted, on your keys, severable in one step. Ships with the scoping module and the AI data-handling annex as editable templates.

What this actually gives you

  • Deploy the register and ISMS as version-controlled documents, framework-mapped on a NIST CSF 2.0 baseline with SOC 2 and ISO 27001 overlays, and wire report generation to the live source rather than to a copy.
  • If your answer to whose data is on this box is “a client’s, heading into diligence”, Part 4 says so plainly.
  • Phase 0 maps the estate; this is where that map becomes a running configuration.

The infrastructure layer under the programme, and the engineered companion to C2 — The Operator's Manual. The C2 manual is about operating the department — the console, the gates, the register, agent orchestration. This is about the box it all runs on. Complementary by design: buy the manual to learn the operating model, this to build the infrastructure it assumes. Sold on its own, and as the self-host pair.

Your security programme should not live in an inbox or a vendor's cloud tenant. Every engagement produces artifacts — a risk register, an ISMS, policies, findings, evidence. The traditional answer to where they live is a PDF, and a PDF is stale the day it is delivered: no version history, no access control after send, no provenance, and no way to prove what changed or when. The answer is one hardened box you control, versioned in git, reachable only over a private mesh, on your own keys.

One box, three jobs. A NUC, mini-PC or hardened VM running a minimal Linux base, holding the Obsidian-git vault, the living risk register and the ISMS, and the evidence store. Full-disk encryption, services reduced to the essentials, host hardening baseline. The box does one job and does it off production.

Zero inbound, by construction. Tailscale — or Headscale if you would rather self-host the coordinator — so nothing is published to the internet. No listening service, no VPN concentrator, outbound-initiated and mutually authenticated, with named identities and ACLs so a sponsor or counsel gets read-only. An optional Cloudflare front covers the narrow cases where something genuinely needs a public seam.

Hardware-rooted, and severable. A hardware token gates disk unlock, admin access and git commit signing; BYOK keys stay on the box. No key, no access. And the one-click sever is wired from the start, so the AI layer can be cut with production untouched — the containment guarantee is a build step, not a promise.

Six steps, with the commands. Harden the base. Stand up the Obsidian-git vault — assets, topology, personas, runbooks, findings and history, the version-controlled knowledge base every pillar reads and writes, where git history is the audit trail. Deploy the register and ISMS as version-controlled documents, framework-mapped on a NIST CSF 2.0 baseline with SOC 2 and ISO 27001 overlays, and wire report generation to the live source rather than to a copy. Mesh it with zero trust. Enroll the hardware root and prove a restore before you rely on the backup. Then scaffold the six pillar seams and the C2 seat, and wire the sever.

Hardware-agnostic, with a sourcing table anyway. Any NUC, mini-PC or hardened VM works, and the guide is written that way. Appendix A maps three build tiers to real parts with current prices — a homelab tier on hardware you already own, a practitioner tier, and a high-assurance tier on open-firmware machines — plus the two pieces worth buying regardless: a hardware token and an HSM turn a box you already have into a hardware-rooted node for around $215. securitygadgets.shop carries the open-firmware machines if you want them; they are an upgrade, not a requirement.

Honest about the line it does not cross. A node you build and run yourself is real and capable — and it is yours to patch, back up and prove. What it does not give you is documented provenance: vendor-direct procurement with firmware verified on record, a dedicated workstation that never touches another client's data, a managed lifecycle, and a certificate of sanitisation at exit. If your answer to whose data is on this box is "a client's, heading into diligence", Part 4 says so plainly and points at the done-for-you Operator Node. Read Part 4 before you buy hardware, not after.

Where it sits. Phase 0 maps the estate; this is where that map becomes a running configuration. The C2 seat conducts from it. The six pillar guides are scaffolded on it. It is deliberately the cheapest door into the programme, because the box is what everything else needs to exist somewhere.

What you download: the 24-page guide in four parts with six appendices — hardware reference builds and sourcing, the vault and register starter schema, the zero-trust mesh ACL recipe, a hardening and hardware-root checklist, a fillable build-day runbook, and the done-for-you spec. Plus two editable Word templates carried over from the managed service: a Phase 0 add-on scoping module for quoting a commissioned node as client work, and the AI Data Handling Standard, the data-classification annex a client's security or legal reviewer asks for. They are templates to adapt for your own practice, which is what makes the vCISO/MSSP tier actionable rather than theoretical.

What's included

  • PDF — fully editable
  • Engagement Package (.zip) — the overview, the Phase 0 scoping module and the AI data-handling annex, all editable — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-01
Pages 24