Solutions · Domain

Threat Detection

Would we actually see it? Start with how detections actually arrive. An organisation whose incidents mostly turn up as a colleague's message has a coverage problem it cannot see. Then where the attack pressure is aimed, how much access comes from devices outside the managed estate, and how much of that pressure lands on privileged accounts.

What this domain covers

Where the boundary sits.

The boundary against Resiliency is deliberate. Detection asks would we see it; Resiliency asks could we survive it. Detection owns coverage. Resiliency owns time to detect, contain and recover.

What is measured here

The signals read, and the work prescribed against them.

The summary of each is on the surface. Open one for the specific dimensions behind it.

SignalsWhat IO reads for this domain6 signal and evidence families, correlated deterministically rather than inferred.
  • Incidents found by tooling versus incidents raised by a person
  • Detectors that were firing and have gone quiet
  • Reliance on user reports as a share of all detections
  • Attack pressure against identity, and where it is aimed
  • Access arriving from devices outside the managed estate
  • Attack pressure landing on privileged accounts
PlaybooksWhat IO prescribes5 representative playbooks, each gated on prerequisites and maturity.
  • Review the detectors that have stopped firing
  • Close the detection gap behind the incidents people found before the tooling did
  • Bring the accounts under the heaviest identity pressure onto stronger controls
  • Reduce the share of access arriving from untrusted devices
  • Tighten the exposure on the privileged accounts taking the most pressure

See how a playbook is structured.

SeatsWho lands here first3 seats read this domain before anyone else does.
  • Threat intelligence
  • Security operations
  • CISO
Verification

What has to move for this to have worked.

Measure 01

Share of detections that were tool-led rather than person-led

Measure 02

Reliance on user reports over time

Measure 03

Untrusted device share, and privileged account exposure

Measure 04

Whether a reviewed detector is firing again afterwards, and whether that held on re-measurement

Enablement

Sessions that feed this domain.

We deliver these as part of IO Enablement Services.

Breakout

Former Red Teamer

What the inside of an engagement actually looks like, and which of your controls the attacker stopped bothering with.

Breakout

Weakness in Plain Sight

The exposures that sit in the open because everyone assumed someone else owned them, and how to tell whether you would see them being used.

Next step

See it before you talk to anyone.

Two quarters of recorded activity across sixteen seats. One click, no install.