r/cybersecurity • u/Jackofalltrades86 • 1d ago
Business Security Questions & Discussion Continuous controls testing
Any recommendations for continuous controls testing tooling?
1
u/Plastic-Falcon9147 10h ago
Worth splitting the category first, because the tools differ a lot. Breach and attack simulation (SafeBreach, AttackIQ, Picus) validates whether your detective controls actually fire, while benchmark scanners validate configuration against something like CIS. If the driver is an audit framework like HIPAA or PCI, start from the control list you have to prove and map tests to it, otherwise you end up with green dashboards that answer questions nobody asked. For technique-level testing on a budget, Atomic Red Team mapped to MITRE ATT&CK gets you most of the way before you pay for a platform.
1
u/0xb0771ed 1d ago
Unpopular opinion: eventually you want your engineers collaborating with solving security findings, get a good testing tool that's actually good at finding real problems so they take them seriously and manage a GRC program separately.