Overview
Real-life assessments to evaluate prevention, detection and response capabilities
Measuring the success of security operations on efficiency metrics alone can fail to address a key question all security leaders need to answer: how good are people and controls at preventing, detecting and responding to cyber threats?
Scenario-based testing performed by Redscan’s experienced team of consultants, can help to validate the true effectiveness of your organisation’s capabilities. This is achieved by simulating a wide range of adversarial tactics and providing recommendations to enhance the protection of key assets.
Benefits
Benefits of scenario-based testing
Scenario-based testing is a specialist form of offensive security assessment. Unlike traditional penetration testing, which is focused on uncovering vulnerabilities, scenario-based testing is designed to benchmark the performance of cyber security controls against specific adversarial tactics and behaviours. Scenario-based testing helps to answer important questions such as:
- How effective are security technologies at preventing, detecting and responding to threats?
 - Are there any network security blind spots that persistent attackers could exploit?
 - Are Blue Team security analysts able to shut down advanced and sophisticated attacks?
 - How good are security analysts at differentiating genuine incidents from false positives?
 - Are incident response plans in place to address threats and manage compromises?
 - Do in-house security teams have the know-how to remediate breaches?
 
Purpose
Validate the effectiveness of 
security operations
                            Scenario-based testing is commonly used to assess the ability of your organisation to prevent, detect and respond to threats. Unlike a Red Team Operation, which is designed to replicate a full-scale cyber-attack, a scenario-based test is a more focused type of assessment often constructed around a specific adversarial tactic. Regular scenario-based testing creates a culture of continuous improvement, ensuring that your security operations team is better prepared to act against current and emerging threats.
Assessments
Custom assessments
Redscan’s scenario-based testing service can be tailored to help evaluate your organisation’s ability to detect and respond to a range of security risks. The many scenarios and tactics that we can replicate include:
- A supply chain compromise
 - Data exfiltration by an employee or contractor
 - A spear phishing campaign to harvest credentials
 - Installation of malware
 
MITRE ATT&CK
The MITRE ATT&CK™ framework
Scenario-based testing can be aligned to a range of adversarial behaviour frameworks. One of the most common is the Adversarial Tactics, Techniques and Common Knowledge (MITRE ATT&CK), which outlines the methods adversaries use to compromise, exploit and traverse networks. The MITRE ATT&CK Framework is divided into 11 groups of TTPs, all of which can be replicated by scenario-based testing.
Security insight
Gain deeper insight with scenario-based testing
Scenario-based testing can be commissioned as a standalone engagement or included as part of Kroll Responder, our award-winning Managed Detection and Response service, in order to continually validate visibility and coverage against current and emerging threats.
Expertise
Our security qualifications
About us
Why choose Kroll?
- A leading global MDR company
 - Red and blue team CREST CSOC expertise
 - High-quality intelligence and actionable outcomes
 - Quick and hassle-free service deployment
 - An agnostic approach to technology selection
 - Avg. 9/10 customer satisfaction, 95% retention rate
 
Get in touch
Complete the form for a prompt response from our team.

Resources









