Quick answer: Assumed breach is when a security test starts not with the question can the attacker get in but with the attacker is already inside, now what happens. In this scenario the test team is given limited internal access from the start (like a compromised employee account), and from there how far the attacker can advance is measured. Why this approach? Because in modern reality the question is no longer will there be a breach but how long will we hold when there is one. This test, without getting stuck at the outer wall, directly tests internal defense, detection capability and response speed. The result shows how open the path to the organization's most valuable assets is and how early an attack would be noticed.

Traditional security tests usually focus on pushing the outer wall: can the attacker get in? But this question does not fully reflect today's reality. A sufficiently determined attacker sooner or later finds a way; a phishing email, a stolen password or a supplier flaw. The truly critical question is: what happens after getting in? The assumed breach scenario is designed to answer exactly this question. This article explains what this approach is, why it is increasingly important, and how it differs from classic tests.

Changing the assumption

The core idea of the assumed breach approach is to change an assumption. A classic test starts with the assumption the attacker is outside, trying to get in. Assumed breach starts with the assumption the attacker is already inside and focuses all the test's energy on the next question: how far can this attacker go from here? This is done by giving the test team limited internal access from the start; as if an employee's account was compromised. This way the test focuses directly on the real issue, internal resilience, without spending time bypassing the outer wall.

Why this approach is gaining importance

Classic test Assumed breach
Question: can they get in? Question: what happens after they get in?
Focuses on the outer wall Focuses on internal defense
Time spent in the external phase Time evaluated in the internal phase
Tests detection capability little Directly tests detection and response

The reason this approach stands out is simple: breaches are no longer a question of whether but a question of when. Organizations that accept this reality build their defenses not only on preventing entry but also on limiting damage and fast detection when there is an entry.

What it measures

An assumed breach test directly tests three things. First, the strength of internal defense: how far can an attacker starting from limited access advance through privilege escalation and lateral movement? We covered these steps in the privilege escalation and lateral movement article. Second, detection capability: does the organization notice these movements, or does the attacker advance quietly? Third, response speed: when an anomaly is noticed, how fast and correctly does the team react? These three together show an organization's real resilience.

Relationship with red team and purple team

Assumed breach is a frequently used starting point for red team work. While the red team imitates a real attacker, the blue team (defense) tries to detect it; the purple team approach, where the two work together with open communication, provides the most learning. We detailed these teams' roles and differences in the red team, vulnerability assessment and purple team difference article. Assumed breach lets this work skip the external phase and focus directly on the valuable part.

Who it is suitable for

Assumed breach is not the first step for every organization. For an organization whose basic security hygiene is not yet in place, starting with classic assessments first is more sensible. But for organizations that have reached a certain maturity, have a strong external defense and really want to measure their internal resilience, this approach gives the most valuable information. You can clarify which test type your organization is ready for with a penetration test preparation and scoping effort.

The KAOS and DSET approach

DSET helps organizations answer not only can they get in but also how long will we hold when they do. Our local AI engine KAOS maps privilege escalation and lateral movement paths starting from limited internal access, shows the paths to the organization's most valuable assets, and reports every step with a working proof, without being destructive. The goal is to make the internal paths an attacker would find visible before they find them, and to measure the organization's detection and response capability realistically.

Frequently asked questions

Does assumed breach not test my outer wall? Directly no, but this is not a shortcoming, it is a deliberate choice. Assumed breach skips the outer wall bypass phase and focuses all the test's energy on internal defense; because the truly critical question is no longer whether entry is prevented but what happens after entry. You can assess the external surface with a separate classic test; the two together give a full picture.

Is this approach suitable for every organization? No. For an organization whose basic security hygiene is not yet in place, classic assessments first are more sensible. Assumed breach gives the most valuable information for organizations that have reached a certain maturity, have a strong external defense and really want to measure internal resilience. Clarifying which test you are ready for with a preparation effort is the right start.

What do I learn from this test? Three critical things: how far an attacker can advance from inside, whether the organization notices this movement, and how fast a response comes when an anomaly is seen. These three together show your organization's real resilience, that is how long it will hold when there is a breach; this is far more valuable than just knowing whether the wall is solid.

Sources

To measure your organization's real resilience against a breach, contact DSET. We provide red team and assumed breach assessment from our Ankara Hacettepe Teknokent laboratory.