Closed-loop security: should one provider test and defend?
Closed-loop security, also called test-and-defend, is a model where one provider runs both offensive testing (penetration testing, red team) and defensive operations (SOC, MDR, incident response) against the same environment, so findings from testing feed detection tuning instead of sitting in a report. Buyers should treat that continuity, not just accreditation or price, as a core criterion when evaluating any provider. Three questions separate a closed loop from two services sold side by side: does one team deliver both, do the offensive and defensive teams share findings on a defined cadence, and can they show a specific test finding that became a detection rule.
Why fragmented security leaves gaps.
Most organisations buy testing from one vendor and monitoring from another, and the two never speak. A penetration test finds an exploitable path; the report is emailed, filed, and never reaches the detection backlog. The SOC, meanwhile, tunes its own rules against its own assumptions, with no outsider ever validating the blind spots. Nothing is technically broken, but the loop between finding a weakness and defending against it is open at both ends.
The SOC gets no context on what was tested, so a known-weak path is watched no more closely than anything else.
Without a shared record, the next test re-finds issues the last one already raised, and pays to do it again.
A red team finding and a live alert live in separate systems, so no one connects the two during an incident.
Make continuity a buying criterion.
Every shortlist is scored on price, accreditation, and SLA. Integrated test-and-defend continuity belongs on that list too, and almost no buyer asks for it. Apply the checklist below to whoever you are evaluating, including any provider already on your shortlist. It is written so it would still make sense if you used it to press a competitor.
How to evaluate a test-and-defend provider
- 01
Both disciplines, one accredited firm
Is the same company accredited for testing and for the SOC, or is defence subcontracted to an unaccredited partner? Ask who signs each contract. Two different subcontracted companies is not one provider.
- 02
Finding-to-detection turnaround
When a test finds an exploitable gap, does it feed straight into detection rule tuning, or does it sit in a PDF until the next renewal? Ask for the mechanism, not a promise.
- 03
One shared timeline
Can the provider show a single incident timeline that spans a test finding and a live alert, or are the two teams on separate ticketing systems that never reconcile?
- 04
A named escalation path and a real SLA
Is there a named analyst paged on a critical alert with a stated response time, or a generic "24/7 SOC" claim with no number behind it?
- 05
Data residency and staff vetting
Is the SOC UK-based with DBS-checked analysts, or offshored to an undisclosed subcontractor? This matters for regulated sectors and for who can lawfully see your data.
- 06
Does the loop cost more, and is it justified?
The honest answer is sometimes yes on a like-for-like basis. Weigh the integration value (no re-scoping, no lost context) against a possible premium, rather than assuming the closed loop is always cheaper.
Fragmented vs the closed loop.
Two honest models. The fragmented model is not wrong for everyone: it can be marginally cheaper, and it suits an organisation with the in-house capacity to coordinate two vendors. The closed loop earns its place when that coordination is the thing you do not have.
| Fragmented (two vendors) | Closed loop (one provider) | |
|---|---|---|
| Findings handoff | FragmentedReport emailed once and filed; the SOC has no context on what was tested | Closed loopFindings feed the detection backlog during the engagement |
| Blind-spot discovery | FragmentedThe SOC's own configuration assumptions go untested by an outsider | Closed loopThe offensive team tests the actual detection coverage |
| Retest | FragmentedNew scoping call, new quote, a different tester | Closed loopThe same team that found the issue verifies the fix |
| Accountability | FragmentedTwo vendors, two contracts, finger-pointing on gaps | Closed loopOne provider accountable for the full loop |
| Cost | FragmentedOften marginally cheaper on paper | Closed loopOften marginally higher; integration is priced in |
| Best fit | FragmentedOrganisations with mature in-house capacity to coordinate two vendors | Closed loopOrganisations without spare capacity to run the handoff themselves |
How Precursor closes the loop.
Scored against the same checklist above, here is Precursor's answer. One accredited UK team runs both sides, so a test finding and a live alert share one record.
One accredited team, both disciplines
Precursor is CREST accredited across penetration testing from £2,500, vulnerability assessment, and SOC operations. The same firm tests and defends, so findings feed detection tuning inside the engagement instead of being handed to a separate vendor. It does not subcontract defence to an unaccredited partner.
A named responder, in the UK
The managed SOC in Newcastle runs from a physical UK facility with UK-based, DBS-checked analysts and no offshoring. Critical alerts get human analyst investigation within 10 minutes of firing, with a named L3 incident response lead paged for any Critical or High severity.
Explore both halves of the loop.
Offensive testing finds the gaps; the defensive SOC watches and responds to them. Each is a full service in its own right, and they are stronger run together.
Close the loop with one UK team.
Test and defend from a single triple-CREST-accredited provider, so a finding never sits in a report waiting to be exploited. Get a scoped quote across both sides.
Common questions
Closed-loop security, also called test-and-defend, is a model where one provider runs both offensive testing (penetration testing and red team) and defensive operations (SOC, MDR and incident response) against the same environment. The point is continuity: a weakness found by testing feeds directly into detection tuning, and the defensive team is validated by a real attacker simulation, rather than the two functions running in isolation.
The value is coordination and speed. When one team tests and defends, findings reach the detection backlog during the engagement instead of after a contract renewal, and there is a single point of accountability for gaps. That said, an organisation with mature in-house capacity to coordinate two separate vendors can run the fragmented model successfully. It stops scaling when there is no spare internal capacity to own the handoff.
Ask three things: does one accredited team deliver both testing and the SOC, or is defence subcontracted; do the offensive and defensive teams share findings on a defined cadence with a real mechanism, not a PDF; and can they show one specific example of a test finding that became a detection rule, including how long it took. A provider that can only confirm they sell both services has not closed the loop.
Not necessarily. On a like-for-like basis the integrated model can be marginally higher, because the coordination and the finding-to-detection handoff are priced in. The saving shows up in avoided re-scoping, retained context between test and defence, and faster remediation, rather than a lower headline figure. Weigh the integration value against any premium rather than assuming the closed loop always costs less.
Yes. Precursor is triple-CREST accredited across penetration testing, vulnerability assessment and SOC operations, and delivers both sides from one UK team. Testing runs from £2,500 and the managed SOC from £900 per month. The SOC operates from a physical facility in Newcastle with UK-based, DBS-checked analysts and no offshoring, and critical alerts get human analyst investigation within 10 minutes of firing, with a named L3 incident response lead paged for any Critical or High severity.
No. Precursor is CREST accredited for penetration testing, vulnerability assessment and SOC operations, and holds ISO 27001 and Cyber Essentials Plus. It does not deliver the formal CBEST, STAR-FS, NCSC CHECK or TIBER-EU schemes, which are run by providers registered under those specific frameworks. For work that requires a formal CHECK deliverable, Precursor delivers ITHC as a CREST member firm.