The challenge: why this was critical
A large commercial bank operated under pressure from rapidly evolving threats, requiring immediate validation of detection rules. Additionally, regulatory mandates under EU DORA (including Threat-Led Penetration Testing - TLPT) and UK FCA/PRA Operational Resilience frameworks required continuous, evidence-based validation of security controls and ICT risk management.
However, the teams responsible for cybersecurity testing were concerned about the risk of “shelfware” - a situation where a deployed tool, despite high costs and expectations, gradually stops being actively used. Deploying a global platform that requires significant effort quickly loses real value without proper organizational support.
Previous BAS deployments were hindered by rigid vendor support models – where Tier-1 helpdesk scripts and ticket escalations delayed critical rule validation and detached vendor support from the bank's operational reality.
Additionally, communication friction emerged due to language differences, lack of shared operational context, and limited understanding of the banking environment’s specifics.
The bank needed a solution that was easy to deploy and simple to use in daily operations - without multi-month projects and extensive training with every team change. It was crucial that new analysts could quickly enter the process and, in case of blockers, have a clear and short path to engineering support. With threats evolving week by week, time, shared context, and efficient collaboration were key - not multi-step escalations and lengthy ticket workflows.
Key challenges
- need for fast, technical, and reliable validation of SIEM/EDR rule effectiveness
- risk of integrating a tool that would not be fully adopted (shelfware)
- alignment with the local banking environment
- team frustration with traditional support models (L1 Helpdesk)
- requirement for guaranteed SLA on engineering response time
- ensuring continuity of knowledge transfer despite IT team turnover
- need for continuous updates of testing scenarios
What was implemented and how it worked in practice
The bank deployed IOC Simulator – a Breach & Attack Simulation (BAS) platform enabling continuous, non-disruptive validation of SIEM, EDR, and XDR detection coverage through automated threat scenarios. The solution provided immediate access to up-to-date, customized attack scenarios, as well as an open testing environment where security teams can independently design, test, and automate their own response strategies.
IOC Simulator operates in a non-intrusive model - it focuses on deterministic reproduction of attacker behavior without the risk of uncontrolled offensive activity. It can be run in test, lab, and mirrored endpoint environments, without impacting production systems, and an automatic cleanup mechanism removes all artifacts after tests are completed.
The implementation produced audit-ready telemetry of continuous security validation, satisfying DORA Chapter IV (TLPT & digital resilience) alongside UK NIS regulations and ISO 27001 risk management standards.
By bypassing traditional L1/L2 helpdesk queues, the support model provided direct access to senior threat response engineers, delivering guaranteed SLAs for rule tuning and scenario customisation.
The implementation was based on two transparent communication channels:
- Helpdesk system (SLA): handling ongoing operational requests within defined engineering hours, ensuring full control over priorities and response times
- Dedicated online calendar: used for booking engineering sessions and onboarding, allowing the bank to quickly schedule consultations with experts without unnecessary email exchanges
Thanks to engineering sessions included in the license, the bank’s team went through an efficient onboarding process, enabling immediate execution of real testing scenarios. Technical support focused on operational assistance, ensuring that the tool became an active part of the defense strategy from day one.
Results and day-to-day impact
Direct access to PREBYTES engineers significantly reduced the product’s time-to-value. Teams no longer wasted time explaining basic technical issues to first-line support and instead gained a partner for substantive technical dialogue. Engineers understood the specifics of detection testing, making their recommendations accurate and quickly translatable into concrete improvements in SIEM/EDR rules.
The bank successfully shifted from reactive incident response to proactive, continuous threat validation, contributing to improved MTTD and MTTR for emerging threat campaigns through the ongoing validation of detection rules and response procedures. Security teams gained the ability to regularly run attack scenarios without impacting the production environment. A model based on tasks, scenarios, and playbooks also enabled them to independently design and automate their own tests, which significantly increased their operational maturity and shortened the time required to verify changes to security controls.
Another key improvement was enhanced visibility into detection effectiveness. The bank obtained consistent and reliable data that made it easier to assess how security systems responded to individual scenarios and to identify areas requiring optimization. This translated into more informed risk management and the ability to continuously eliminate detection gaps - before they could be exploited by real attackers.
The deployment also supported the fulfillment of regulatory requirements - IOC Simulator provides evidence of continuous operational resilience testing, helping the organization address selected DORA (Chapter IV) requirements as well as compliance processes related to NIS2 and ISO 27001 in the area of risk management.
The ability to book sessions via an online calendar eliminated uncertainty regarding expert availability and improved planning of development activities. Meanwhile, the licensing model with a defined pool of engineering hours ensured cost predictability and guaranteed access to high-level technical support at critical moments.
As a result, IOC Simulator became a permanent operational component - the foundation for continuous validation of security effectiveness and real improvement of organizational resilience.
Post-implementation results:
- full operationalization of the system and elimination of “shelfware” risk
- 90% reduction in time required to verify resilience against new campaigns
- direct access to security engineers (bypassing L1 Helpdesk) and predictable SLA
- continuous access to up-to-date scenarios based on real threats, tailored to the banking sector
- support for Blue, Red, and Purple Teams within a single testing environment
- mapping to MITRE ATT&CK - critical for coverage analysis and audits
- non-intrusive testing with no impact on production environments (Windows) + automatic cleanup after each scenario
- fast deployment and immediate time-to-value
- Audit-ready compliance evidence (DORA, UK NIS, ISO 27001) backed by measurable detection testing telemetry