Preactive Security Exchange Rules of Engagement

AttackIQ’s Preactive Security Exchange (PSE) is founded on AttackIQ’s mission to make the world safe for compute by providing the critical missing ingredient: feedback on security control effectiveness. The term “Preactive Security” refers to the practice of being proactive about preventable failure. The Preactive Security Exchange (PSE) is a platform for both customers and partners to do precisely that.

For us, the mission is the most important thing. We accomplish this mission not just by working with customers of our software but by working collaboratively with providers to improve their products and services and to improve the quality of AttackIQ’s solutions, in service of our joint customers.

In order to do this effectively, AttackIQ must operate in the service of our mission with independence, discretion, and openness:

  1. Data-Driven Independence: We present our customers with data that is based upon our independent and objective assessment of the way that threat actors and emulated attacks exercise security controls. We are transparent in the way that we present the performance of every single security control.
  2. Neutral & Discrete: We do not publicly or privately endorse or criticize any particular partner’s products or services. While it is true that customers sometimes use AttackIQ’s products to benchmark competitors, we do not influence the customers’ evaluation, nor do we disclose anything that we have learned about our partners, either publicly or to another partner.
  3. Open & Adaptive: Subject to the limitations on independence and discretion, we operate openly, honestly, and responsively. We do not assume that we are right but welcome feedback on the effectiveness of our own testing. In turn, we seek to work with partners on the same basis.

We recognize that the cybersecurity industry is historically very competitive and adversarial and that some vendors may be confused about our mission and motivations at first. That’s fine. Different vendors may understand and appreciate the PSE mission quickly, while others may take more time to appreciate its advantages for them. Regardless, we are ready to engage and collaborate.

We also recognize that the principles above are fairly general. With time we expect to get feedback on these commitments and to run into situations that will require that we improve their clarity. We pledge to enhance these rules of engagement with transparency and to strive for consistency with our general principles of independence, discretion, and openness.

Frequently Asked Questions (FAQs) about the PSE