Offensive security has no organizational home. Testing happens because something external required it, and the results are filed with no meaningful follow-through. There is no defined owner, no leadership visibility, and no connection between what testing reveals and how the organization decides.
Outcomes
- ·A named individual or function is responsible for coordinating offensive security
- ·Test results are documented and retained
- ·Leadership is informed when assessments complete
- ·Critical findings reach relevant operational stakeholders beyond the security team
Actions
- 01Assign a named owner to coordinate testing, track findings, and communicate results
- 02Establish a basic process for retaining assessment documentation
- 03Brief IT and business leadership after each assessment
- 04Tie critical findings to operational priorities so remediation reads as a business issue
Sustainment Criteria
All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.
A named owner for offensive security coordination exists and is known across the organization
Assessment documentation is retained and accessible to relevant staff
Leadership receives a summary of findings after each major assessment
Critical findings reach operational stakeholders beyond the security team
Practitioner note
G1 is a starting point, not a stable operating position. An organization that stays at G1 while advancing technically is building capability it cannot use. Results that reach no one, inform no decision, and drive no accountability do not improve resilience, whatever their technical quality.
Moving to G2
Document roles and responsibilities, stand up a remediation tracking process, set a defined leadership review cadence, and capture testing ownership in policy or SOPs.
Corresponding Technical Practice level
T1 Ad Hoc
Organizations often develop these axes at different rates. Compare your position on both.
