
Rate your organisation's control maturity against the aggregate threat actor TTP heatmap. Instantly see where your defences are missing for the highest-priority threats.
Proportion of techniques with missing controls in each ATT&CK phase.
Rate each control. Expand a technique to toggle maturity for its individual defensive controls.
Rate all unique defensive controls in one place. Changes save automatically.
Rapid patch cadence (48-hr SLA for critical CVEs)
Email sandboxing & attachment detonation
Disable Office macros via Group Policy
Email sandboxing & link rewriting
File integrity monitoring (FIM) on web roots
Application whitelisting / WDAC
EDR with behavioural analytics
Phishing-resistant MFA (FIDO2)
Least-privilege access model
MFA enforcement on all cloud services
Immutable, off-device SIEM logging
Alert on log gap / tampering events
Encrypted communications (TLS 1.3 / E2E)
Management plane isolation (OOB)
New account creation alerting
VPN appliance patching (critical priority)
MFA on all remote access (FIDO2)
EDR with memory protection (Credential Guard)
Network segmentation to limit blast radius
Immutable backups (WORM / offline copy)
EDR with ransomware behavioural detection
Backup isolation (air-gap or WORM)
PowerShell constrained language mode
EDR with PowerShell behavioural detection
Phishing-resistant MFA (FIDO2 / passkeys)
Phishing-resistant MFA (session cookie resistant)
Device registration approval workflow in IdP
Least-privilege access to sensitive repos
Incident response retainer (pre-contracted)
Notifiable Data Breach response plan
Cloud storage access policy & CSPM
Immutable backups (WORM / offline)
EDR with process injection detection
RDP access restricted to PAWs / jump servers
MFA on all RDP sessions
EDR tamper protection enabled
Alerting on security tool process termination
EDR behavioural analytics
Least-privilege user model on Linux
Web application firewall (WAF)
Security awareness training
DNS-layer filtering
Web server hardening
Outbound HTTPS inspection
Script block logging
Privileged access workstations (PAWs)
Conditional access with device compliance
Background screening & access reviews
Cloud credential scanning
Cloud CSPM
Egress proxy with TLS inspection
DLP on endpoint and email egress
Data classification & sensitivity tagging
Tamper-evident audit trail
Vendor security assessment (TPRM)
Secure SDLC
Third-party update integrity verification
Certificate pinning
Network-level encryption (mTLS)
Privileged identity management (PIM)
Anomalous account change detection
VPN traffic behavioural analytics
LSASS protection via Windows Credential Guard
Behavioural network baseline (not geo-IP)
DNS over HTTPS (DoH) inspection
DDoS protection (cloud-based scrubbing)
Network segmentation to limit propagation
Egress proxy with DLP inspection
SIEM alerting on anomalous outbound data volume
VSS protection via GPO / tamper alerts
EDR alerting on vssadmin execution
Service creation monitoring in SIEM
Least-privilege service account model
Script block logging & AMSI integration
MFA push notification rate limiting
Help desk social engineering training
Zero trust email controls
Anomalous internal email pattern detection
AiTM phishing detection (Entra ID Protection)
Alert on new device registration from unmanaged device
DLP on SharePoint / Confluence / repos
CASB — block bulk uploads to non-approved storage
DLP on cloud egress
Cyber insurance with extortion coverage
CASB with cloud anomaly detection
API rate limiting & DLP on API egress
Change management controls on critical data
EDR alerting on mass file modification
SIEM alerting on automated bulk transfers
DLP on automated egress channels
Memory integrity protection
PAM session recording for privileged RDP
Privileged access required to modify security config
Command shell execution monitoring in SIEM
Linux EDR / auditd rules for shell execution
Container / VM security hardening
CASB — cloud storage upload monitoring
DLP on egress to unapproved cloud services
Email filtering (typosquat domain detection)
External attack surface management (EASM)
Browser isolation
Insider threat program
CASB for cloud service anomaly detection
JA3/JA4 TLS fingerprinting in SIEM
UEBA — anomalous bulk access alerts
Software supply chain security (SBOM)
Code signing & build integrity
CALEA architecture security review
Network device integrity verification
Zero trust network architecture
Resilience testing & continuity plans
Data classification & tagging
Insider threat monitoring program
Browser isolation for privileged users
UEBA — anomalous data repository access
Egress traffic anomaly alerting in SIEM
Network flow monitoring (NetFlow / IPFIX)
Proxy with category-based blocking
Turn gaps into a roadmap
Our analysts will validate your control maturity against live threat actor TTPs and build a risk-ranked remediation roadmap.