The necessary ones make the site work. The others measure which pages help and which ads bring the people who need DM11. Your choice, and you can revisit it from the footer.
Cybersecurity
The detection has been bought. What is missing is knowing what it covers.
We execute real attack techniques in your environment, in a controlled and agreed way, and record three answers for each one: what your detection saw and alerted on, what it only wrote to a log, and what went unnoticed. The result is a technique-by-technique map, grounded in MITRE ATT&CK.
Only what was actually executed goes on the map. Coverage claimed in vendor documentation stays out, because a promise is not detection. The chosen scope defines the reach: you can start with the techniques most used by the groups active in your sector, run the full chain from initial access to the objective, or turn the measurement into cycles that retest the deployed rules and show the evolution side by side.
Before executing, we survey what telemetry exists, where it comes from, and how long it is retained, because a technique without a data source is not detectable by any tool. We need an agreed window and approval to run in the environment. You receive the coverage map, the gaps in risk order and, depending on scope, the proposed detection rules and the cycle-over-cycle comparison.
The stages and deliverables below describe the The whole chain, from access to objective modality. The other modalities appear when you request the proposal.
Telemetry survey
Before talking about rules, we survey what records exist, where they come from and how long they are kept. A technique with no data source cannot be detected by any tool.
Controlled execution
We execute the techniques in your environment, in an agreed window, and record step by step what the detection saw, what it merely logged and what it missed.
Coverage analysis
We compare expected detection with observed detection and order the gaps by risk, with the rules proposed to close each one.
Presentation
A meeting with leadership translating the technical result into business risk and investment decisions. We arrive with the answers to the questions the board always asks: what to attack first, how much effort it takes and what happens if nothing is done.
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.