Our Approach

Threat-informed.
Evidence-driven.

The method does not start from a product — it starts from what your organisation must protect, the threats that matter, and the evidence that proves whether your defences actually respond.

Five stages

From context to assurance

Each stage answers one question posed by the visitor, and each answer flows into the next without losing the thread.

  1. 01
    Understand

    What matters to this organisation?

    Business context, important services and assets, exposure and applicable threat intelligence establish what is genuinely at risk.

  2. 02
    Prioritise

    Why these threats and behaviours?

    Threat scenarios and a Threat Profile turn context into relevance. ATT&CK provides a common behavioural language for what follows.

  3. 03
    Design

    What should we validate?

    A Catalogue and coherent Validation Packages define clear objectives and keep every test traceable to an original need.

  4. 04
    Validate

    How do we test it?

    Morgana resolves what capability actually exists, plans controlled tests and gathers relevant evidence from the real environment.

  5. 05
    Learn

    What did the evidence show?

    Detection reasoning separates confidence from uncertainty, surfaces gaps and turns evidence into improvements that feed the next cycle.

Full traceability

Every conclusion points back to evidence

The chain is unbroken: from the organisation's context, through a defined validation objective, to a test, its evidence and an assurance conclusion.

  1. Context
  2. Threat Profile
  3. Validation Package
  4. Plan
  5. Test
  6. Evidence
  7. Assurance

Reading the evidence

Not every result is a score

A single alert, an ATT&CK mapping or an "Access Denied" message does not, by itself, prove detection or prevention. We distinguish what the evidence actually supports.

Blocked

The defence prevented or interrupted the activity before the objective was met.

Detected

The activity was observed and identified as it happened.

Insufficient evidence

Telemetry was missing or inconclusive — a finding in itself that drives better visibility.

Technology independence

Scoped to your environment

The method begins with threats and organisational needs — not with a specific platform. Validation is scoped to the actual environment and to the evidence it can provide, so the result reflects your defences as they really are.

ATT&CK acts as a shared behavioural vocabulary for alignment, while relevance comes from your context, not from a generic checklist.

Ready to understand what your defences actually prove?

The ecosystem that connects threat understanding to evidence is Merlino and Morgana.

Meet Merlino & Morgana