Skip to content

Kit · Assurance

Exercise & assurance kit

NIS2 requires policies and procedures to assess the effectiveness of the risk-management measures. Effectiveness, not existence — which makes this a testing obligation, and the SOC is where the test happens.

Cadence
Quarterly
Output
Findings with owned actions
All kits

Three kinds of test, for three kinds of question

TestAnswersCost
Atomic technique testDoes this specific detection fire when this specific behaviour occurs?Low — can be run continuously
Table-top exerciseDo the people know what to do, and do the decision paths actually work?Medium — a few hours of the right people
Purple team engagementWould we catch a capable adversary working towards an objective?High — but the only one that tests the chain end to end

Running a table-top exercise

The point is to find the decisions nobody has made, not to demonstrate that the team is competent.

Quarterly
0/10

Detection efficacy testing

Prove that the detection stack still does what your coverage map claims it does.

Quarterly, or continuously where automated
0/7

Four failure points, four different fixes

No telemetry means a collection problem. Telemetry but no rule fire means a content problem. Rule fired but no alert reached anyone means a routing or suppression problem. Alert reached someone who did nothing means a procedure or workload problem. Reporting these as one number — “we detected 7 of 12” — hides which of the four you need to fix.

Next kit

Board communication kit

The arguments that land with a management body, the numbers to bring, and how to ask for resource in terms of accepted risk.

Open Board communication kit