A company should not simply assume that its SIEM is working.
The rules need to be tested.
This can be achieved by:
- simulations
- Purple Team drills
- controlled tests
- Atomic Red Team
- incident response exercises
- validation campaigns.
The goal is to answer a simple question:
“If this attack actually happens, will we be able to detect it?”
A rule that exists in a console but has never been tested does not necessarily offer reliable detection capabilities.