By Michael Henry, CEO, Accelerynt
Recently, a new customer called us after their website was hijacked, and the first thing we had to tell them was that there were no logs to examine. Since no one had written a log requirement for the site, and the hosting provider charged extra for logging, the marketing team decided not to keep any.
Many incidents we work on have some version of that event: the first hours go to questions about the company’s own environment instead of the attacker. There wasn’t any security readiness score on last quarter’s board slide to account for this, because those scores measure capability. Measure readiness instead by what you can’t currently prove.
A CSF tier, a Secure Score, and a clean tabletop exercise all describe some capability. Readiness should be a narrower claim about the next incident: that the automation will fire the way it did in March, and that the person who approves containment will pick up the phone. The only evidence for that claim is proof you could check today.
Prove What the Response Depends On
The information you need to prove comes from what your response depends on, and Boyd’s Observe, Orient, Decide, Act (OODA) loop already lays it out. Observing takes telemetry, orienting takes an accurate picture of your own environment, deciding takes someone with authority who knows it is them, and acting takes levers that still work. Each one is a dependency you either proved before the incident or will prove during it, while your team is on the clock and the attacker is at large.
The hijacked website was an Observe failure. Unit 42’s 2025 incident response report describes the enterprise version of this: an initial compromise sat in network logs nobody monitored, and detection came late enough for the attackers to take data and deploy ransomware (Palo Alto Networks, 2025).
Acquisitions are the classic Orient failure. As a buyer, you own the risk on day one. The first incident doesn’t always wait on the integration plan. One of our customers had an incident within a week of closing an acquisition. In that case, the team spent no time learning the acquired company’s configuration, because we had mapped it the day the deal closed. We built a capability for that job after too many integrations where the incident arrived before the inventory.
Decide and Act go stale through ordinary work. The response plan still lists an owner, and that person now works somewhere else. A Conditional Access exclusion added for a project outlives the project. In one engagement we handled, a new IT operations partner put automated work back in human hands. Their team was measured on tickets closed, and automation left them fewer tickets to count. We had solved the problem. Apparently, that was a problem.
A Proof Has to Be Able to Fail
A proof counts only if it could have failed. It tests the real thing, whether that’s a system or the person who holds the authority, and it leaves a record someone else can check. Everyone in this business has sat through the kind of tabletop where twenty minutes after sign-in, most of the room is on their phones, waiting for the session to end. The exercise was marked complete. By that standard, my gym membership makes me an athlete.
A test that finds a gap proves the gap, and that dependency counts against readiness until someone retests the fix. A known failure also overrides a current test, which is a rule nuclear plants write into their technical specifications (U.S. Nuclear Regulatory Commission [NRC], 2021).
Readiness Proof Expires
Current means the date stamp is inside an interval set by how critical the dependency is, and a change underneath the proof voids it early. Configuration drift voids it. So does any code release, new system, new vulnerability, architecture change, reorganization, or new partner that touches it. For configuration, the proof gets renewed when the change board reviews the diff, a practice I argue for in Guarding the Wrong Door.
Other disciplines worked this out long ago. An airline pilot with a valid license still can’t carry passengers without three takeoffs and landings in that aircraft type in the last 90 days (Pilot Qualification: Recent Experience, 2026). A commercial airliner can fly with a broken component, but the deferral has a repair timeline that’s not easy to reset (Federal Aviation Administration [FAA], n.d.). Refineries track overdue inspections and missed emergency drills as leading indicators (American Petroleum Institute [API], 2021). Your compliance teams already track how old their evidence is for the auditor. In most cases we’ve seen, nobody uses this to report readiness.
Let Technology Deliver the Proof
Proof costs money, and most programs already spend theirs on the annual review and the tabletop exercise. While the cost of machine proof has fallen by orders of magnitude, human proof has gone the other way. Between late 2022 and late 2024, the price of running an AI model at a fixed capability fell 280-fold (Maslej et al., 2025), while the labor hours to test a single SOX control rose by a third, and the share of controls that run automatically went down (KPMG, 2025). Protiviti’s surveys show hours moving in the same direction (Protiviti, 2023).
The cost gap matters more now because attackers work at machine speed. Unit 42 found data leaving the network within the first hour in one in five cases (Palo Alto Networks, 2025). Proof assembled during the incident, at human speed, arrives after the data has already left the building. Every hour a person spends proving what a machine could prove is an hour taken from the work only a person can do. Automate proof for everything a machine can check, prove the checks still run, and put people on the rest, starting with the path to containment.
Start With Your Next Incident
After your next incident or a real exercise, go back through the timeline, the incident channel, and the bridge notes, and mark every question the team had to answer about itself, and how long each one took. We track this on every incident we work, and it’s the first number we try to shrink with a new customer.
The questions become a list for your team to work down, and the list feeds a readiness measure, which is the count of critical dependencies without current proof. That measure belongs in the risk register as the indicator for one risk, an incident that takes longer to contain than the business can tolerate. The board sees that indicator, and the share of each response spent on your own environment, improve quarter over quarter. Shorten the list, and the next incident’s first hours go where they belong: to the attacker.
References
American Petroleum Institute. (2021). Process safety performance indicators for the refining and petrochemical industries (API Recommended Practice 754, 3rd ed.). https://api.org/oil-and-natural-gas/health-and-safety/refinery-and-plant-safety/process-safety/process-safety-standards/rp-754
Federal Aviation Administration. (n.d.). Minimum equipment lists and configuration deviation lists. In Flight standards information management system (Order 8900.1, Vol. 4, Chap. 4). U.S. Department of Transportation. https://drs.faa.gov/browse/excelExternalWindow/DRSDOCID148233969720260410131133.0001
KPMG. (2025). The 2025 SOX survey. https://kpmg.com/kpmg-us/content/dam/kpmg/pdf/2025/the-2025-sox-survey.pdf
Maslej, N., Fattorini, L., Perrault, R., Gil, Y., Parli, V., Kariuki, N., Capstick, E., Reuel, A., Brynjolfsson, E., Etchemendy, J., Ligett, K., Lyons, T., Manyika, J., Niebles, J. C., Shoham, Y., Wald, R., Walsh, T., Hamrah, A., Santarlasci, L., . . . Oak, S. (2025). The AI index 2025 annual report. AI Index Steering Committee, Institute for Human-Centered AI, Stanford University. https://hai.stanford.edu/ai-index/2025-ai-index-report
Palo Alto Networks. (2025). 2025 Unit 42 global incident response report. https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report
Pilot qualification: Recent experience, 14 C.F.R. § 121.439 (2026). https://www.ecfr.gov/current/title-14/chapter-I/subchapter-G/part-121/subpart-O/section-121.439
Protiviti. (2023, September 12). New Protiviti survey finds companies prioritizing enabling technology for SOX compliance [Press release]. https://www.protiviti.com/us-en/press-release-new-protiviti-survey-sox-compliance
U.S. Nuclear Regulatory Commission. (2021). Standard technical specifications: Westinghouse plants (NUREG-1431, Rev. 5, Vol. 1). https://www.nrc.gov/reading-rm/doc-collections/nuregs/staff/sr1431/v1/index
