A company should not simply assume that its SIEM is working.

The rules need to be tested.

This can be achieved by:

  • simulations
  • Purple Team drills
  • controlled tests
  • Atomic Red Team
  • incident response exercises
  • validation campaigns.

The goal is to answer a simple question:

“If this attack actually happens, will we be able to detect it?”

A rule that exists in a console but has never been tested does not necessarily offer reliable detection capabilities.

Categories: