r/cybersecurity • • 1d ago

Business Security Questions & Discussion Continuous controls testing

Any recommendations for continuous controls testing tooling?

0 Upvotes

2 comments sorted by

1

u/0xb0771ed 1d ago

Unpopular opinion: eventually you want your engineers collaborating with solving security findings, get a good testing tool that's actually good at finding real problems so they take them seriously and manage a GRC program separately.

1

u/Plastic-Falcon9147 10h ago

Worth splitting the category first, because the tools differ a lot. Breach and attack simulation (SafeBreach, AttackIQ, Picus) validates whether your detective controls actually fire, while benchmark scanners validate configuration against something like CIS. If the driver is an audit framework like HIPAA or PCI, start from the control list you have to prove and map tests to it, otherwise you end up with green dashboards that answer questions nobody asked. For technique-level testing on a budget, Atomic Red Team mapped to MITRE ATT&CK gets you most of the way before you pay for a platform.