The program shifts from finding vulnerabilities to measuring whether the organization can detect, respond to, and recover from realistic adversary behavior. Red and purple team exercises, adversary simulation, and structured tabletops are in place, and targeted social engineering tests human and process resilience. Resilience metrics gauge program effectiveness. How the work is resourced, whether internal staff, retained partners, managed services, or automated platforms, is an organizational choice.
Outcomes
- ·Red and purple team exercises run at least yearly, with defined scope and documented after-action outcomes
- ·Adversary simulations follow realistic attack paths drawn from current threat intelligence
- ·Targeted social engineering, scenario-driven and spear-phishing style, is built into adversary simulation
- ·Structured tabletops test coordination, escalation, and communication across security, IT, and management
- ·Resilience metrics (MTTD, MTTR, detection coverage) are collected for critical systems and trended
- ·Exercise findings produce traceable detection engineering and IR playbook improvements within the cycle
Actions
- 01Build a red and purple team plan; internal staff, retained partners, managed services, and BAS platforms all satisfy this
- 02Feed current threat intelligence into adversary simulation scenario design
- 03Design targeted social engineering scenarios (spear-phishing, pretexting) along realistic attack paths
- 04Measure and document detection and containment performance during exercises
- 05Run after-action reviews and convert findings into detection engineering within the same cycle
Sustainment Criteria
All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.
Red or purple team exercises run at least yearly, with documented after-action review and tracked closure
Adversary simulations incorporate current threat intelligence, refreshed each cycle
Targeted social engineering runs at least yearly as part of adversary simulation
At least one structured tabletop a year produces documented improvement actions
Resilience metrics are collected for each critical asset class and trended
Exercise findings have produced traceable detection engineering or IR playbook improvements within the current or immediately preceding cycle
Practitioner note
T4 is deliberately agnostic on delivery mechanism. Targeted social engineering sits at T4 rather than T3 because its value comes from integration with adversary simulation: spear-phishing and pretexting test process resilience and organizational response, not click rates.
Moving to T5
Deploy continuous validation tooling, stand up a threat intelligence monitoring function, define a minimum validation cadence justified by threat intelligence, and formalize a PDCA cycle linking validation outcomes to program improvement.
Corresponding Governance & Accountability level
G4 Integrated
Organizations often develop these axes at different rates. Compare your position on both.
