Offensive security testing has long been a cornerstone of cybersecurity, with penetration testing and red teaming being the primary methods of identifying vulnerabilities. However, a more advanced and tailored approach has emerged as defence mechanisms evolve: Assumed Breach (AB) testing.
AB testing assumes that a breach has already occurred and focuses on testing scenarios that mimic the post-compromise stages of an attack. This shift provides organisations with insights into their ability to detect and respond to threats once they’re inside the network.
WHAT IS ASSUMED BREACH?
Assumed Breach testing begins with the premise that an attacker has already gained access to the internal network through compromise—whether it’s a successful phishing campaign, physical intrusion, or perimeter breach. Unlike traditional penetration testing, which focuses on identifying potential vulnerabilities from the outside, AB testing dives directly into scenarios where the attacker is already “in the door”. It tests how quickly and effectively an organisation can respond.
Why Assumed Breach?
As businesses strengthen their perimeter defences with advanced firewalls, multi-factor authentication, and secure email gateways, attackers increasingly use more sophisticated methods to bypass them, such as exploiting compromised credentials or insider threats. By assuming the perimeter has already been breached, organisations can test their internal defences and gain insights into how their detection systems, incident response, and containment strategies hold up in the face of an active threat.
OFFENSIVE SECURITY TESTING: A NEW FOCUS
Traditional Penetration Testing vs. Assumed Breach
While penetration testing remains a vital component of security testing, its focus is typically on coverage—identifying as many exploitable vulnerabilities as possible within a network over a short period. Pen testers mimic an external attack, attempting to breach the perimeter and assess system vulnerabilities.
On the other hand, Assumed Breach testing narrows the focus to post-compromise scenarios. The goal is not just to find vulnerabilities but to simulate specific attack vectors, such as credential abuse or disgruntled insider scenarios, and observe how the organisation’s internal controls and security teams handle the attack.
KEY ASSUMED BREACH SCENARIOS
At its core, AB testing is scenario-based. Some common scenarios include:
- Perimeter Breach: Testing how attackers exploit access gained through a compromised web server or external service.
- Credential Abuse: Mimicking a situation where attackers use stolen credentials to move laterally through the network.
- Social Engineering Success: Simulate an attacker who gains access through a successful phishing campaign and assesses how far they can escalate privileges.
- Disgruntled Worker: Testing internal risks, such as how quickly a malicious insider can escalate privileges or exfiltrate data.
These scenarios focus on internal controls, threat detection systems, and incident response capabilities.
IMPROVING RESPONSE AND DETECTION
Post-Compromise Focus
Assumed Breach testing doesn’t just expose vulnerabilities; it provides insights into the effectiveness of detection tools like EDR (Endpoint Detection and Response) and how well incident response teams perform under pressure. Many organisations may have strong perimeter defences but lack the internal monitoring and rapid response to contain and mitigate an active threat. The results of an AB test help security teams improve their response playbooks, refine detection rules, and identify gaps in log monitoring and threat intelligence integration.
Lessons Learned from AB Testing
From the frontline experiences, StrikeCyber’s Assumed Breach tests have uncovered weaknesses in backup strategies, network segmentation, and endpoint protection. A typical post-compromise scenario involves moving laterally through a network and escalating privileges, much like during a ransomware attack. AB testing helps identify escalation paths that attackers can exploit and offers critical insights into how an organisation can contain an attack before it escalates.
WHY AB TESTING MATTERS
In an age when attackers can bypass even the most secure perimeters, Assumed Breach testing (AB testing) is a vital evolution in offensive security testing. By simulating real-world, post-compromise scenarios, AB testing gives organisations the necessary insights to strengthen internal defences, refine incident response procedures, and improve overall cyber resilience.
Businesses looking ahead of attackers should consider integrating AB testing into their cybersecurity strategies. It is no longer about whether an attack will happen but when—and how well-prepared the organisation is to respond and recover.
Assumed Breach isn’t just the evolution of security testing; it’s a blueprint for creating proactive, adaptive defences that can withstand tomorrow’s threats.