ARMORARMOR

Offensive security is a managed business discipline. Board-level oversight treats it as a standard input to enterprise risk governance. PDCA cycles are formalized and running, and crisis simulations involve executives and the board. Investment decisions are explicitly informed by resilience metrics, and the organization can show this with evidence rather than assertion. The distance from G4 to G5 is measured in organizational culture as much as process.

Outcomes

  • ·Board-level oversight of offensive security is a standing governance function, not a periodic briefing
  • ·A formalized PDCA cycle runs, with outcomes reviewed at board level and investment demonstrably adjusted
  • ·Enterprise crisis simulations involve executive and board participation, testing governance and strategic decisions
  • ·Investment and resourcing decisions are explicitly informed by resilience metrics, with documented evidence
  • ·Governance structures adapt as technology, business, and threat landscape change

Actions

  1. 01Make board-level reporting a standing governance function with a documented cadence and metrics
  2. 02Formalize the PDCA cycle at enterprise level, with documented evidence of complete loops
  3. 03Design and run enterprise crisis simulations with executive and board participation
  4. 04Build explicit, documented links between resilience metrics and investment decisions
  5. 05Set enterprise resilience targets and report performance against them to the board on a set cadence

Sustainment Criteria

All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.

Board-level oversight is a standing function, with evidence that board feedback shapes program direction

PDCA evidence is current and complete: objectives defined, validation executed, board review held, adjustments documented

Enterprise crisis simulations with board participation run at least semi-annually, with verified improvements

Documented evidence shows investment decisions explicitly informed by offensive security outcomes

Enterprise resilience targets are defined, tracked, and reported to the board on a set cadence

Legal, HR, and communications take part in crisis simulations regularly

Practitioner note

G5 is intentionally aspirational. The evidentiary bar is deliberately higher because G5 makes the strongest organizational claims. An organization claiming G5 should be able to point to specific decisions that changed on offensive security evidence. The PDCA requirement demands documentation of the complete loop, not just that objectives were set and validation occurred.

Corresponding Technical Practice level

T5 Resilient

Organizations often develop these axes at different rates. Compare your position on both.

View T5 Resilient