The methodology is structured: we ask about how your logging, detection, and response actually work today, not what your vendor's dashboard says. No agents are installed, and production is never touched.
A short set of structured questions across six signal areas — no log exports, no read access to your SIEM.
Your exposure signals and any critical gaps are shown immediately — the self-assessment is completely ungated.
A validation call is offered only after you've seen your results — and it's always on the table, regardless of outcome.
Are the log sources an attacker would actually touch — identity, endpoint, network, cloud control plane — reaching your SIEM at all?
Do your detection rules map to real attack techniques, or just the defaults your SIEM shipped with three years ago?
Is signal getting lost in noise? A rule nobody trusts because it fires 200 times a day is a rule that gets ignored.
Can your team correlate an alert back to a specific identity, service account, or session fast enough to act on it?
From the moment an attacker acts to the moment your team is paged — how much of that window is actually yours?
When a detection fires, is there a runbook and an owner, or does it sit in a channel until someone has time?