Skip to content

Conducting a Capability Review

Conducting a Capability Review provides a consistent way to establish an evidence-based view of organisational capability and identify where capability should be strengthened. The review is intended to reflect how the organisation operates in practice and the level of capability appropriate to its operating context.

Applying the Pretext8 Capability Review process

Start by defining the workflows, sensitive actions, roles, and operating conditions in scope.

Review each of the capability domains against the capability scale based on current organisational behaviour in practice, particularly under pressure, during exceptions, and at points of weakness.

Full alignment with every behaviour listed at a point on the scale is not required. Different workflows or operating conditions within the same capability domain may align with different points on the scale. Review findings should preserve those differences rather than forcing the entire domain into a single rating.

The review should be supported by observable evidence where available, including approvals, exception logs, incident records, exercise outcomes, access reviews, and behaviour observed during simulated adversarial activity.

An initial Capability Review can use existing organisational evidence and does not require a completed SECA. Evidence from SECA can inform the review where it is already available.

Most organisations will not demonstrate the same capability across every capability domain, workflow, or operating condition. Different workflows and domains may align with different points on the capability scale at the same point in time. Capability Review results should therefore not be averaged, as strength in one area does not offset a material weakness in another.

A capability weakness may be considered lower priority where the affected workflow is not material to the organisation’s threat exposure and would have low consequence if compromised. The weakness should still be recorded for improvement, and the reason it is considered non-material should be documented. If it is unclear whether a workflow is material, treat it as material until the uncertainty is resolved.

Response & Trust Recovery is reviewed using incident records and exercised behaviour. Where no recent incident provides evidence, exercise outcomes should be used. An absence of incidents does not make the domain non-material, and an unexercised recovery capability should only be described to the extent supported by available procedures and records.

Required capability should reflect the organisation’s threat exposure, operating context, and the consequence of compromise within its highest-risk workflows. Greater capability may require greater investment and may not be necessary across every capability domain or workflow.

Required capability is determined separately for relevant domains and workflows. It should describe the behaviour and operating conditions that need to hold in practice, with the capability scale used as shorthand where useful. Established capability may be sufficient where verification and escalation reliably hold under pressure, while Integrated or Adaptive capability may be appropriate where consequence, exposure, or assurance requirements justify greater integration and adaptivity.

Required capability and current capability are separate. An organisation may intentionally require a lower point on the capability scale where greater capability is not justified by its operating context.

For each capability finding where required capability is not met or has not been demonstrated, identify:

  • the observable gap between current and required behaviour
  • the workflows, controls, governance arrangements, or cultural conditions contributing to the gap
  • the change required to improve and sustain performance
  • the evidence that would demonstrate improvement

A capability finding identifies a capability weakness rather than a failed control. The appropriate response depends on the affected workflow, the causes behind the observed behaviour, and the operating conditions that allow the weakness to persist.

Two organisations may therefore identify the same capability gap but require different improvement activity. Diagnosis should precede control selection through SECA, and implementing a control does not by itself demonstrate improved capability.

Capability should be reviewed periodically and following significant changes to the organisation’s systems, technology, business processes, operating environment, threat profile, key supplier relationships, or workforce.

A significant social engineering incident or near miss should also trigger targeted review of the capability domains most affected.