Offensive security is now a deliberate program. Scope reaches past traditional infrastructure into cloud, SaaS, APIs, and third-party integrations, so the organization is testing its real attack surface rather than a compliance proxy for it. Threat modeling drives test planning, remediation runs against SLAs, and testing is wired into how the organization manages change.
Outcomes
- ·A documented offensive security strategy exists, is reviewed yearly, and ties to organizational risk priorities
- ·Testing covers on-premises infrastructure, cloud, SaaS, APIs, and critical third-party integrations
- ·Threat modeling drives scope and scenario selection ahead of major initiatives
- ·Remediation runs against SLAs that set timelines by severity, with compliance tracked
- ·Testing is triggered by significant business or technology change, not only by schedule
- ·Offensive security sits inside change management and project approval workflows
Actions
- 01Write and maintain an offensive security strategy that connects testing to organizational risk objectives
- 02Formally extend scope to cloud environments, SaaS platforms, APIs, and supply chain integrations
- 03Adopt a structured threat modeling method (STRIDE, PASTA, MITRE ATT&CK, or equivalent)
- 04Set remediation SLAs by severity tier and a formal escalation path for breaches
- 05Build testing requirements into change management, DevOps, and project approval
Sustainment Criteria
All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.
An approved offensive security strategy is current and reviewed yearly
Coverage of cloud, SaaS, and third-party environments is backed by documented evidence
SLAs are applied consistently and tracked, and breaches are escalated
Testing requirements are embedded in change management workflows
Threat modeling runs ahead of major initiatives and at least yearly for core assets
Practitioner note
T3 is where scope expansion most often outruns the capacity to act on what it finds. Before widening coverage further, confirm that SLA governance and remediation ownership are working. A broad program whose findings sit unaddressed is not T3, it is T2 with overextended scope.
Moving to T4
Introduce red and purple team exercises, feed threat intelligence into scenario design, start collecting resilience metrics, and run structured tabletops with cross-functional participants.
Corresponding Governance & Accountability level
G3 Strategic
Organizations often develop these axes at different rates. Compare your position on both.
