The exercise ends. The evidence begins.
Verdus Cyber turns a live run into an executive-ready readiness profile, scored across eight competencies and mapped to framework coverage, so you can prove exactly where the team is strong and where to invest next.
Readiness profile
Framework coverage
Which controls were exercised, and how well the team met each one.
Scored on what actually matters under fire.
Every decision is timestamped and graded against a consistent rubric, turning a stressful afternoon into a defensible, comparable score.
How quickly the team recognised the incident for what it was.
Prioritisation of competing signals and impacts.
Decisiveness and correctness of isolation actions.
Internal, customer, media and regulator communication.
Notification duties, evidence handling and sign-off.
Quality and governance of high-stakes calls.
Safe, verified restoration and service return.
Evidence capture and timeline discipline throughout.
Where is your team today?
Set each competency to where you honestly believe your team stands. The outline shows an illustrative target profile, example data, not customer benchmarks.
Drag the sliders. The radar updates live.
Every decision, mapped to a standard your auditors already use.
Scores map to the frameworks and obligations that matter to your board and your regulator, including a full MITRE ATT&CK view of the adversary.
Identify · Protect · Detect · Respond · Recover
Adversary tactics & techniques mapping
Annex A controls & incident management
EU digital operational resilience testing
Entity reporting & governance duties
72-hour breach notification obligations
Cardholder-data incident handling
Critical-infrastructure protection
The adversary, mapped tactic by tactic.
Injects are tagged to ATT&CK techniques, so the debrief shows exactly which adversary behaviours the team faced, and which they detected, contained or missed.
Initial Access
- Phishing
- Valid Accounts
- External Remote Services
Execution
- Command & Scripting
- User Execution
Lateral Movement
- Remote Services
- Internal Spearphishing
Exfiltration
- Exfil Over C2
- Transfer to Cloud
Impact
- Data Encrypted for Impact
- Service Stop
- Inhibit Recovery
A board-ready readiness report.
You leave with more than a feeling. Every run produces a board-ready artefact.
- Readiness score across eight competencies
- Framework-coverage heatmap (NIST · ISO · DORA · NIS2)
- MITRE ATT&CK detection & response mapping
- Timestamped decision timeline with evidence
- Prioritised findings and a remediation roadmap