Threat Detection
Would we actually see it? Start with how detections actually arrive. An organisation whose incidents mostly turn up as a colleague's message has a coverage problem it cannot see. Then where the attack pressure is aimed, how much access comes from devices outside the managed estate, and how much of that pressure lands on privileged accounts.
Where the boundary sits.
The boundary against Resiliency is deliberate. Detection asks would we see it; Resiliency asks could we survive it. Detection owns coverage. Resiliency owns time to detect, contain and recover.
The signals read, and the work prescribed against them.
The summary of each is on the surface. Open one for the specific dimensions behind it.
SignalsWhat IO reads for this domain6 signal and evidence families, correlated deterministically rather than inferred.
- Incidents found by tooling versus incidents raised by a person
- Detectors that were firing and have gone quiet
- Reliance on user reports as a share of all detections
- Attack pressure against identity, and where it is aimed
- Access arriving from devices outside the managed estate
- Attack pressure landing on privileged accounts
PlaybooksWhat IO prescribes5 representative playbooks, each gated on prerequisites and maturity.
- Review the detectors that have stopped firing
- Close the detection gap behind the incidents people found before the tooling did
- Bring the accounts under the heaviest identity pressure onto stronger controls
- Reduce the share of access arriving from untrusted devices
- Tighten the exposure on the privileged accounts taking the most pressure
SeatsWho lands here first3 seats read this domain before anyone else does.
- Threat intelligence
- Security operations
- CISO
What has to move for this to have worked.
Share of detections that were tool-led rather than person-led
Reliance on user reports over time
Untrusted device share, and privileged account exposure
Whether a reviewed detector is firing again afterwards, and whether that held on re-measurement
Sessions that feed this domain.
We deliver these as part of IO Enablement Services.
Former Red Teamer
What the inside of an engagement actually looks like, and which of your controls the attacker stopped bothering with.
Weakness in Plain Sight
The exposures that sit in the open because everyone assumed someone else owned them, and how to tell whether you would see them being used.
Observed behaviour, reported culture and completed learning held as one position, and re-measured on the behaviour, not the completion record.
Which AI tools are really in use, what data reaches them, and whether the written guardrails are the ones in force.
Each policy statement tied to evidence that it holds in practice, not to the date it was last approved.
See it before you talk to anyone.
Two quarters of recorded activity across sixteen seats. One click, no install.