ARMORARMOR

The program shifts from finding vulnerabilities to measuring whether the organization can detect, respond to, and recover from realistic adversary behavior. Red and purple team exercises, adversary simulation, and structured tabletops are in place, and targeted social engineering tests human and process resilience. Resilience metrics gauge program effectiveness. How the work is resourced, whether internal staff, retained partners, managed services, or automated platforms, is an organizational choice.

Outcomes

  • ·Red and purple team exercises run at least yearly, with defined scope and documented after-action outcomes
  • ·Adversary simulations follow realistic attack paths drawn from current threat intelligence
  • ·Targeted social engineering, scenario-driven and spear-phishing style, is built into adversary simulation
  • ·Structured tabletops test coordination, escalation, and communication across security, IT, and management
  • ·Resilience metrics (MTTD, MTTR, detection coverage) are collected for critical systems and trended
  • ·Exercise findings produce traceable detection engineering and IR playbook improvements within the cycle

Actions

  1. 01Build a red and purple team plan; internal staff, retained partners, managed services, and BAS platforms all satisfy this
  2. 02Feed current threat intelligence into adversary simulation scenario design
  3. 03Design targeted social engineering scenarios (spear-phishing, pretexting) along realistic attack paths
  4. 04Measure and document detection and containment performance during exercises
  5. 05Run after-action reviews and convert findings into detection engineering within the same cycle

Sustainment Criteria

All criteria must be met to hold this level. If any criterion is unmet at reassessment, consider yourself at the previous level.

Red or purple team exercises run at least yearly, with documented after-action review and tracked closure

Adversary simulations incorporate current threat intelligence, refreshed each cycle

Targeted social engineering runs at least yearly as part of adversary simulation

At least one structured tabletop a year produces documented improvement actions

Resilience metrics are collected for each critical asset class and trended

Exercise findings have produced traceable detection engineering or IR playbook improvements within the current or immediately preceding cycle

Practitioner note

T4 is deliberately agnostic on delivery mechanism. Targeted social engineering sits at T4 rather than T3 because its value comes from integration with adversary simulation: spear-phishing and pretexting test process resilience and organizational response, not click rates.

Moving to T5

Deploy continuous validation tooling, stand up a threat intelligence monitoring function, define a minimum validation cadence justified by threat intelligence, and formalize a PDCA cycle linking validation outcomes to program improvement.

Corresponding Governance & Accountability level

G4 Integrated

Organizations often develop these axes at different rates. Compare your position on both.

View G4 Integrated