
You have a SIEM, an EDR and a SOC. The only question that matters is whether any of it would actually fire during a real attack, and “I think so” is not an answer you want to give after a breach.
Here is the audit question nobody enjoys. An assessor turns to your SOC lead and asks: “if an attacker dumped credentials from that finance server tomorrow, would you see it?” More often than it should be, the honest answer is “I think so.” “I think so” is not a great thing to be saying after an incident.
Detection is usually assumed, not proven. You buy the SIEM, enable the rule pack, the dashboard goes green, everyone moves on. But between an attacker's action and an analyst being alerted sits a long, fragile chain: the right log source, shipping the right fields, with synchronised clocks, matched by a rule that is written, enabled, and routed to a human with the context to act. Break any single link and the attack happens in silence.
A green dashboard proves your tooling is running. It does not prove your tooling would catch an attacker.
We find the same broken links again and again: a critical log source that stopped shipping months ago and nobody noticed; rules written for a technique the business retired years back while newer ones go uncovered; alerts firing into a queue no one triages; clocks skewed across the estate so correlation silently never matches.
Detection-gap analysis swaps the assumption for evidence. We safely replay real attacker techniques, initial access, execution, persistence, credential access, lateral movement, exfiltration, against your environment, every action mapped to MITRE ATT&CK, and watch what your defences actually do. Each technique lands in one of four honest verdicts:
The line between a gap and a blind spot is the whole game. A gap is usually a rule you can write this week against logs you already hold. A blind spot means you never collected the evidence in the first place, a bigger, more expensive problem, and the one most maturity assessments quietly skip over.
Because Forefront runs this through AETOS, the exposure-management platform we supply, the same validation re-runs after every rule change, tooling upgrade or SOC hand-over. The output isn't a maturity score or a colour on a heat-map; it is a prioritised list of specific, reproducible gaps, each tied to the technique that exposed it and the control that should have caught it. Run the techniques, find the gaps, tune the rules, re-run to prove the fix. After a few cycles, coverage stops being an article of faith and becomes something you can put in front of an auditor.
A penetration test tells you where you are vulnerable. Detection-gap validation tells you whether you'd even notice. You want both: one measures your defences, the other measures whether you can see them being tested.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.