field notes / artifacts · Repo
DFIR Hierarchy of Needs
I reference this non-stop when it comes to measuring and prioritizing cybersecurity efforts.
The first time I went to Blue Hat, Microsoft, I saw this in a presentation and have not stopped referencing it since.
The IR/DFIR Hierarchy of Needs is something that has helped me communicate how to measure effective cybersecurity and prioritize cybersecurity maturity efforts. It has made me a better consultant, and it will make you one too.

A Quick Breakdown
When it comes to my purposes of consulting, I focus on the first four levels.
- I tell companies that we need to start with getting an asset inventory - understanding what’s in scope, and what we need to protect.
- Then we focus on getting some telemetry or some visibility into those assets that we’ve identified as in-scope.
- If something went wrong, would we be able to detect it? How are our alerting capabilities?
- And then, especially as a pen tester, the problem isn’t whether or not you could detect that I did something bad. Instead, the question becomes, “Can you stop me?” - and that’s where triaging comes into play.
I strongly focus on these first four levels, and this allows me to provide organizations with a measuring stick to help identify where they are in their cybersecurity maturity and what we should work on next.