ARMORARMOR

Offensive security has no organizational home. Testing happens because something external required it, and the results are filed with no meaningful follow-through. There is no defined owner, no leadership visibility, and no connection between what testing reveals and how the organization decides.

Outcomes

  • ·A named individual or function is responsible for coordinating offensive security
  • ·Test results are documented and retained
  • ·Leadership is informed when assessments complete
  • ·Critical findings reach relevant operational stakeholders beyond the security team

Actions

  1. 01Assign a named owner to coordinate testing, track findings, and communicate results
  2. 02Establish a basic process for retaining assessment documentation
  3. 03Brief IT and business leadership after each assessment
  4. 04Tie critical findings to operational priorities so remediation reads as a business issue

Sustainment Criteria

All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.

A named owner for offensive security coordination exists and is known across the organization

Assessment documentation is retained and accessible to relevant staff

Leadership receives a summary of findings after each major assessment

Critical findings reach operational stakeholders beyond the security team

Practitioner note

G1 is a starting point, not a stable operating position. An organization that stays at G1 while advancing technically is building capability it cannot use. Results that reach no one, inform no decision, and drive no accountability do not improve resilience, whatever their technical quality.

Moving to G2

Document roles and responsibilities, stand up a remediation tracking process, set a defined leadership review cadence, and capture testing ownership in policy or SOPs.

Corresponding Technical Practice level

T1 Ad Hoc

Organizations often develop these axes at different rates. Compare your position on both.

View T1 Ad Hoc