Law 25 — run your compliance in our platform, 1 month free

Whether your detection actually detects

A realistic attack scenario run against your live environment, with defined objectives, to test people and process as well as technology.

The challenge

A pentest tells you whether a weakness exists. It does not tell you whether anyone would have noticed the attack.

Scope — included and not included
Included
  • Threat-informed scenario design
  • Initial access, persistence, lateral movement, objective
  • Detection gap analysis
  • Full attack narrative mapped to ATT&CK
  • Joint debrief with your team
Not included
  • Destructive actions
  • Testing without executive authorisation
  • Physical intrusion unless scoped
  • Anything outside the agreed objectives
How it works
01
Objective setting

What a real attacker would want from you — that becomes the goal.

02
Threat modelling

Scenario designed from threats relevant to your sector.

03
Execution

The scenario runs over weeks, quietly, against the live environment.

04
Debrief

Full narrative, what was detected and when, and the gap review.

What you receive
  • Attack narrative with timeline
  • Detection gap analysis
  • ATT&CK coverage map
  • Executive briefing
  • Recommended detection rules
What we need from you
  • ·Executive authorisation
  • ·Defined objectives and off-limits systems
  • ·A single trusted contact who knows the exercise is running
  • ·Emergency stop procedure
Timeline and engagement

3 to 6 weeks. Fixed scope.

Standards, methods and tooling
MITRE ATT&CKTIBER-EU informedCRTPeWPTXPortal hosted in Canada
Frequently asked questions

Test the whole chain

Technology, people and process — one scenario tells you how they hold together.