Overview
Real-life assessments to evaluate prevention, detection and response capabilities
Measuring the success of security operations on efficiency metrics alone can fail to address a key question all security leaders need to answer: how good are people and controls at preventing, detecting and responding to cyber threats?
Scenario-based testing performed by Redscan’s experienced team of consultants, can help to validate the true effectiveness of your organisation’s capabilities. This is achieved by simulating a wide range of adversarial tactics and providing recommendations to enhance the protection of key assets.
Benefits
Benefits of scenario-based testing
Scenario-based testing is a specialist form of offensive security assessment. Unlike traditional penetration testing, which is focused on uncovering vulnerabilities, scenario-based testing is designed to benchmark the performance of cyber security controls against specific adversarial tactics and behaviours. Scenario-based testing helps to answer important questions such as:
- How effective are security technologies at preventing, detecting and responding to threats?
- Are there any network security blind spots that persistent attackers could exploit?
- Are Blue Team security analysts able to shut down advanced and sophisticated attacks?
- How good are security analysts at differentiating genuine incidents from false positives?
- Are incident response plans in place to address threats and manage compromises?
- Do in-house security teams have the know-how to remediate breaches?
Purpose
Validate the effectiveness of
security operations
Scenario-based testing is commonly used to assess the ability of your organisation to prevent, detect and respond to threats. Unlike a Red Team Operation, which is designed to replicate a full-scale cyber-attack, a scenario-based test is a more focused type of assessment often constructed around a specific adversarial tactic. Regular scenario-based testing creates a culture of continuous improvement, ensuring that your security operations team is better prepared to act against current and emerging threats.
Assessments
Custom assessments
Redscan’s scenario-based testing service can be tailored to help evaluate your organisation’s ability to detect and respond to a range of security risks. The many scenarios and tactics that we can replicate include:
- A supply chain compromise
- Data exfiltration by an employee or contractor
- A spear phishing campaign to harvest credentials
- Installation of malware
MITRE ATT&CK
The MITRE ATT&CK™ framework
Scenario-based testing can be aligned to a range of adversarial behaviour frameworks. One of the most common is the Adversarial Tactics, Techniques and Common Knowledge (MITRE ATT&CK), which outlines the methods adversaries use to compromise, exploit and traverse networks. The MITRE ATT&CK Framework is divided into 11 groups of TTPs, all of which can be replicated by scenario-based testing.
Security insight
Gain deeper insight with scenario-based testing
Scenario-based testing can be commissioned as a standalone engagement or included as part of Kroll Responder, our award-winning Managed Detection and Response service, in order to continually validate visibility and coverage against current and emerging threats.
Expertise
Our security qualifications
About us
Why choose Kroll?
- A leading global MDR company
- Red and blue team CREST CSOC expertise
- High-quality intelligence and actionable outcomes
- Quick and hassle-free service deployment
- An agnostic approach to technology selection
- Avg. 9/10 customer satisfaction, 95% retention rate
Get in touch
Complete the form for a prompt response from our team.
Resources