Detection and Testing

A measure that fails silently is a measure you don't have.

Block 1 closes the controls: access, patching, segmentation. Each of them can fail without saying so. A rule is dropped during a change window. A patch cycle slips. A segment is opened for a supplier and never closed again. The measures still exist on paper, and no one in the building can say whether they still hold.

This block covers that gap. Detection tells you when a control has failed. Testing tells you whether it holds before it is put to the test.

What each layer catches

Network anomaly detection (NDR). Traffic inside the perimeter, watched for the movement a failed control permits: the connection between two segments that should not be able to reach each other, the account going somewhere it has never gone. Operated and tuned during business hours.

24/7 monitoring (SOC/MDR). A signal raised outside business hours has to be read and acted on, not merely logged. This is the continuous coverage for those hours.

Automated penetration testing. Continuous testing against your own perimeter, so an exposure is found on the day it opens rather than at the next scheduled review. Findings are verified by hand before they reach you.

Manual penetration testing and DORA TLPT. Three minor weaknesses chained into one working path — the finding no automation reproduces, because it depends on knowing what to try next.

Where the machine stops

The first three layers run on tooling, and tooling closes volume: traffic watched without pause, coverage held overnight. It does not close judgement.

The fourth layer is therefore a person, and the person has to be accredited — OSCP, CREST, TIBER — rather than merely available. For significant entities under DORA, that is not our call to make.

What the law requires

§30(2) No. 2 of the BSIG requires you to handle security incidents. Handling presupposes noticing: an incident you never saw is not an incident you managed.

§30(2) No. 6 requires you to test whether the measures in Block 1 work. Purchasing a tool does not discharge that duty; the evidence it requires is a test result.

For financial firms, DORA Articles 26–27 go further. Threat-led penetration testing by external, accredited testers is a legal requirement, not a procurement option.