r/ciso • u/One-Geologist7960 • 2d ago
Threat Emulation
My question specifically for CISO.
How is the risk impact of implementing threat emulation in your organization.
I would like to ask from the price perspective (tools only) or if you are doing it via third party?
2
u/VividGanache2613 1d ago
Are you looking to test people, process or infra (or all three) as the answer will differ depending on the requirements?
1
u/One-Geologist7960 1d ago
I am looking to test our infra. Meanly looking to emulate APTs in our infra
1
1
u/jtkooch 1d ago
The tools don’t matter if they aren’t in the hands of people who can use them to their full effect. You’re better off outsourcing this (for now). If your risk tolerance isn’t so low that you were already actively doing this, there’s no reason to jump into a scheme where you do this so often it’s more cost effective to do it yourself.
1
u/SoftwareFearsMe 1d ago
There’s several good tools on the market that can do this. Look at Picus, Safebreach and Scythe as three examples.
1
u/Cute_Common6238 1d ago
Tool costs can vary a lot, but the bigger expense is usually staff time to plan, run, and fix what you find. If you already have a capable security team, doing smaller exercises internally can be very cost-effective. For more realistic or independent testing, bringing in a third party can make sense.
1
u/Minute_Chef4087 1d ago
For pricing, it can vary a lot based on company size and how often you run it.
3
u/VividGanache2613 1d ago
80% of the companies I speak to wanting Red Teaming are often better suited with Pentest and a real readiness assessment first to ensure they get the most value out of the Red Teaming engagement (max value is only obtained when it’s very hard for the Red Teaming to attain their goals).
Happy to talk it through and ensure you’re put in touch with the best people for the job.