Debrief & Reporting

The exercise ends. The evidence begins.

Verdus Cyber turns a live run into an executive-ready readiness profile, scored across eight competencies and mapped to framework coverage, so you can prove exactly where the team is strong and where to invest next.

Readiness profile

readiness profileSample datascore 74 / 100
DetectionTriageContainmentCommsLegalDecisionRecoveryDocs

Framework coverage

Which controls were exercised, and how well the team met each one.

NIST CSF · Respond88%
Communication & escalation76%
ISO 27001 · Incident mgmt81%
DORA · Resilience testing69%
Regulatory notification (72h)62%
Eight competencies

Scored on what actually matters under fire.

Every decision is timestamped and graded against a consistent rubric, turning a stressful afternoon into a defensible, comparable score.

01
Detection

How quickly the team recognised the incident for what it was.

02
Triage

Prioritisation of competing signals and impacts.

03
Containment

Decisiveness and correctness of isolation actions.

04
Comms

Internal, customer, media and regulator communication.

05
Legal

Notification duties, evidence handling and sign-off.

06
Decision

Quality and governance of high-stakes calls.

07
Recovery

Safe, verified restoration and service return.

08
Docs

Evidence capture and timeline discipline throughout.

Self-assessment

Where is your team today?

Set each competency to where you honestly believe your team stands. The outline shows an illustrative target profile, example data, not customer benchmarks.

DetectionTriageContainmentCommsLegalDecisionRecoveryDocs

Drag the sliders. The radar updates live.

50/100Your readiness estimate
Biggest gapContainment
Close the gap: book the exercise
Framework mapping

Every decision, mapped to a standard your auditors already use.

Scores map to the frameworks and obligations that matter to your board and your regulator, including a full MITRE ATT&CK view of the adversary.

NIST
NIST CSF 2.0

Identify · Protect · Detect · Respond · Recover

ATT&CK
MITRE ATT&CK

Adversary tactics & techniques mapping

ISO
ISO 27001

Annex A controls & incident management

DORA
DORA

EU digital operational resilience testing

NIS2
NIS2

Entity reporting & governance duties

GDPR
GDPR

72-hour breach notification obligations

PCI
PCI DSS

Cardholder-data incident handling

KRITIS
KRITIS / BSIG

Critical-infrastructure protection

MITRE ATT&CK

The adversary, mapped tactic by tactic.

Injects are tagged to ATT&CK techniques, so the debrief shows exactly which adversary behaviours the team faced, and which they detected, contained or missed.

Initial Access
  • Phishing
  • Valid Accounts
  • External Remote Services
Execution
  • Command & Scripting
  • User Execution
Lateral Movement
  • Remote Services
  • Internal Spearphishing
Exfiltration
  • Exfil Over C2
  • Transfer to Cloud
Impact
  • Data Encrypted for Impact
  • Service Stop
  • Inhibit Recovery
The deliverable

A board-ready readiness report.

You leave with more than a feeling. Every run produces a board-ready artefact.

  • Readiness score across eight competencies
  • Framework-coverage heatmap (NIST · ISO · DORA · NIS2)
  • MITRE ATT&CK detection & response mapping
  • Timestamped decision timeline with evidence
  • Prioritised findings and a remediation roadmap

Turn your next exercise into evidence.