Continuous Validation

Detection needs to keep proving itself.

A single test shows a point in time. Continuous validation revisits the behaviours that matter, retests after change, and uses evidence — not assumptions — to keep defences honest.

The story

Entry, visibility, response, proof

An attack can start with a person or trusted access

A deceptive message, a compromised identity or an abused process cancreate an entry point — not every click compromises a system, but the path exists outside the systems you are used to protecting.

Visibility and response matter after entry

Detection and timely response help limit an attack's progression. They work alongside prevention rather than promising that detection alone guarantees safety.

Test the behaviours that matter

Start from organisation-specific intelligence and scenarios, then validate relevant adversary behaviours. ATT&CK provides a common behavioural language.

Merlino establishes WHY and WHAT; Morgana HOW and WHAT HAPPENED

Merlino defines the rationale and scope. Morgana plans and runs the validation, records what happened and supports the reasoning over what was learned.

Include the operational response

Evidence should support triage, investigation, containment and learning — where these are part of the agreed validation scope.

As threats and environments change, repeat

Scope, plan, test, observe, assess, improve and retest. Link evidence across iterations rather than showing a permanent green score.

The recurring cycle

Questions every cycle must answer

  1. Why are we testing this behaviour now?

    Start from organisation-specific intelligence and scenarios, not a generic checklist.

  2. What should the control or detection do?

    Define the expected response before running anything, so the result is meaningful.

  3. What happened, and what telemetry supports it?

    Correlate execution evidence with detection telemetry — timing, match and quality.

  4. What needs to change?

    Turn gaps and uncertainty into concrete, prioritised improvements.

  5. Did the next test confirm the improvement?

    Revalidate after change and record the difference, not a restated score.

A word on clarity

Vulnerability, penetration, emulation

Vulnerability assessment, penetration testing and adversary emulation have different objectives that can overlap. Adversary emulation focuses on validating how well detections respond to realistic behaviours — it is not the only useful security activity, and no single activity replaces the others.

Continuous validation is a sustained, governed practice that can include agreed scheduled tests and revalidation after meaningful changes.