Security leadership
Needs a defensible statement of investigative capability for the board, regulators or internal audit.
Fixed-scope engagement
The Forensic Horizon Assessment is a fixed-scope engagement that measures how far back your organization can investigate, validates that capability technically, and names the changes that extend it, measured against the attack scenarios that matter to your environment.
Delivered as
Who it is for
Needs a defensible statement of investigative capability for the board, regulators or internal audit.
Need to know which evidence will exist before an incident forces the question.
Need a prioritized basis for retention, coverage and telemetry decisions.
Scope
| Assessment area | Typical sources examined |
|---|---|
| Identity | Active Directory, Entra ID, PAM, MFA records |
| Endpoint | EDR / XDR detail, OS audit policy, process telemetry |
| Network | Firewall, VPN, proxy, DNS, DHCP, NetFlow |
| Cloud | Control-plane audit, workload and storage access logs |
| Message trace, mailbox auditing, transport rules | |
| Core infrastructure | Directory services, virtualization, backup platforms |
| Critical applications | Application and database audit records |
| OT / ICS | Where applicable to the environment |
Assessment covers, per source
Configuration claims are recorded, then tested. A source is only reported as available for a period once that period has been examined.
Threat scenarios
| Scenario | Representative investigative questions |
|---|---|
| Ransomware | When did initial access occur? What executed? Which systems were reached laterally? Was data staged or exfiltrated before encryption? |
| Privileged Account Compromise | Which identity was compromised? Was credential material extracted? Which privileged operations were performed? |
| Microsoft 365 Account Compromise | How was the account accessed? Were mail rules or delegations created? What data was accessed or downloaded? |
| Data Exfiltration | Which data was collected, from where, over which channel, and in what volume? |
| Persistent Compromise | How long was the attacker present? Which persistence mechanisms were established? Which of them remain? |
Method
Phase A: Evidence analysis
Phase B: Technical validation
Outputs
Typical engagement structure
Reporting
Two report layers are produced from one dataset: a technical report containing source-level records, executed validations and blind spot findings; and a management report stating measured investigative capability, the scenarios evaluated, and the prioritized changes with their projected effect.
Engagement
Scenarios, environments and validation depth are agreed before any measurement work starts.