skip to content

Before your ATT&CK coverage heatmap goes into a customer questionnaire under your signature, what do you change?

level: principalimportance: nice to knowfreq 30%

answer

  1. a work list becomes a representation
  2. who reads it, and when they re-read it
  3. scope, basis, date per cell
  4. downgrade before, not after
  5. an owned blind spot beats a false green

basics

~10 s

Everything the internal version leaves implicit: what each colour asserts and when it was last shown true, which platforms it covers, and any cell you cannot support, downgraded to a dated, owned blind spot.

solid answer

~50 s

The artefact changes meaning when it leaves the SOC. Internally it is a work list where green means "stop looking here for now"; to a customer's reviewer it is a representation that you would detect the behaviour, it may be attached to a contract, and it will be re-read after any incident. So before signing: state the assertion level and validation date per cell, or remove the colour entirely; scope the claim to the platforms and the part of the estate the customer's data actually touches, not the whole company average; refuse to reduce it to one percentage; and downgrade every cell you cannot defend, converting the ones you will not fix into named, dated, owned accepted blind spots with the compensating control stated. A disclosed gap is defensible in a post-incident review. A green cell you cannot support, or one quietly recoloured afterwards, is the thing that turns an intrusion into a credibility problem.

go deeper

for a junior

Understand that a heatmap built for internal planning is not automatically fit to send outside, because the reader cannot ask how the colours were assigned.

for a middle

Be able to say what has to travel with an external cell - the assertion level, the log sources it depends on, the validation date and the platform scope - and why a bare colour cannot be defended by anyone but its author.

for a senior

Show how you would scope the claim to the estate the customer's data touches, downgrade cells you cannot evidence, and version the artefact so a superseded claim can be produced later rather than edited away.

for a principal

Own the tradeoff under commercial pressure: a dated, owned, disclosed blind spot is worth more than a green cell you cannot support, and you are the one who has to say that to a sales team and a customer who both want a better-looking grid.

## The same grid means two different things on two sides of the door Inside the SOC, a coverage heatmap is a planning artefact. Green means "we have done what we are going to do here for now"; red means "work item"; the colours are shorthand among people who know how they were assigned and who will happily argue about any of them. It is allowed to be rough because everyone who reads it can ask its author a question. The moment it goes to a customer under a signature, all of that context is stripped. The reader is an assurance or procurement analyst with no access to the person who coloured it. They will read green as "they would detect that", file it, and possibly reference it in a contract schedule. And if there is ever an intrusion involving one of those techniques, the same document is read backwards, by people asking what you claimed and when. So the question is not whether the heatmap is *accurate*. It is whether every cell is a claim you would defend a year later with the person who made it gone. ### What to change, concretely **State the basis per cell, or take the colour off.** Externally, a colour with no stated basis is the whole problem. Each cell that stays coloured should carry what the colour asserts - source collected, rule in production, behaviour executed and detected - and the date. A cell that cannot carry that loses its colour rather than keeping it on trust. **Scope it to the estate the customer actually touches.** A company-wide figure is not what they are asking for even when it is what they asked for. If their data lives in one tenant, one region, or on one platform, the claim should be about that population of hosts and that identity boundary. An aggregate that averages a well-instrumented endpoint fleet with an un-instrumented platform is misleading in exactly the direction that benefits you. **Refuse the single number.** One percentage cannot be true across platforms, and it invites the reader to compare it with another vendor's differently computed number. If a number is unavoidable, give it with its denominator, its date, and the count of cells excluded from it. **Downgrade what you cannot defend, deliberately.** This is the substance of the exercise. A cell you believe but cannot evidence goes down a level. A cell that depends on a log source you are not actually collecting across that population goes down further. Doing this before the document leaves is a decision; doing it after an incident is a retraction. **Convert what you will not fix into an accepted blind spot.** Some gaps will not close - the platform cannot be instrumented within the budget, or the cost is genuinely disproportionate to the risk. The honest form of that is not a colour. It is a named gap with the missing source, an accountable owner, the compensating controls at other layers, a decision date and a review date. That record is defensible in front of a customer and in front of an investigator, because it shows the organisation knew, decided, and was watching the decision. **Decide what you are not disclosing, and say so.** Some detail is genuinely sensitive - naming precisely which behaviours you cannot see is an aid to an attacker who reads the questionnaire. Withholding is a legitimate position. Colouring the cell green instead is not, because it converts a refusal into a false statement. A withheld cell, disclosed as withheld under whatever the contract permits, keeps the artefact honest. **Version it and agree who re-signs it.** Coverage decays: sensors get uninstalled, rules break on schema changes, the estate grows platforms. A signed claim with no expiry becomes a false claim by attrition. Attach a version, keep the superseded ones, and agree a cadence for re-attestation. ### The judgement the question is really testing The pressure here is never technical. Sales wants the grid greener; the customer wants one number; the SOC knows most cells are level-one claims. The position that survives is that a downgraded, dated, owned artefact is worth more to the organisation than a green one, because it is the version that still stands after an incident - and the person signing it is the one who has to say so to people who would rather hear something else. Interviewers ask this to find out whether you will hold that line when the artefact leaves your control, or whether you will let the audience choose the colours.

  • The customer's reviewer insists on one coverage number. What do you give them?
    A scoped one or none. If it is unavoidable, the number travels with its denominator, the platforms it was computed over, the count of cells excluded, and the date. Better is to answer the question behind it - which behaviours relevant to their data you would detect, at what assertion level - because a bare percentage is not comparable with anyone else's and cannot be defended later.
  • After an incident, is a downgraded cell or a quietly recoloured one more defensible?
    The downgrade, provided it is dated before the incident and has an owner. It shows the organisation knew and decided. Recolouring afterwards destroys the artefact's credibility and reads as concealment even when it was housekeeping, which is why the matrix should be versioned and superseded copies kept rather than edited in place.
  • Is it acceptable to withhold cells from an external coverage claim?
    Yes, within what the contract allows. Publishing precisely which behaviours you cannot see hands a reader a target list. Withholding and saying so keeps the document truthful; colouring the cell green instead converts a legitimate refusal into a false statement, which is the version that becomes a problem when the document is read back after an intrusion.

saying these in an interview costs you the question

  • Publishing one coverage percentage with no denominator or date
  • Recolouring cells quietly after an incident
  • Treating internal work-list colours as external assurance
  • Letting the commercial team set the scope of the claim
  • Signing a coverage claim with no expiry or re-attestation

context