CORIE (Cyber Operational Resilience Intelligence-led Exercises) is a program of exercises aimed at mimicking the Tactics, Techniques and Procedures (TTPs) of real-life adversaries. CORIE helps organisations stay resilient and provides a comprehensive and holistic view of the organisation’s ability to identify and respond to real-world threats.
Whilst CORIE is issued by the Australian Council of Financial Regulators (CFR) and will likely become an enforced regulation for financial institutions (FIs), it is quickly being adapted by other industries as the gold standard for attack simulation.
Intelligence-led means leveraging industry-specific attacks, online chatter and other sources of intelligence to identify the most likely threats to your organisation and tailoring your Red Team to simulate these exact threats.
Australian organisations are under constant attack by sophisticated, resourceful and motivated adversaries looking to cause financial harm by disrupting critical business processes, or by causing reputational damage. To avoid or prevent these worst-case scenarios, organisational resilience should be proactive and not reactive. Australia’s FIs will have to undergo CORIE once it becomes a regulation.
CORIE Red Teams simulate these adversaries in an exercise that is an objective-based simulation, targeting organisational ‘crown jewels’ or critical business services. CORIE Red Team tests the security posture of the people, processes and technology and their ability to identify, mitigate and respond to a realistic and targeted attack.
CORIE was created for FIs, but is the Australian gold standard for attack simulation across all industries.
CORIE and CORIE-aligned Red Team engagements both follow the same methodology and requirements.
We understand critical business services, scenarios and regulatory requirements.
Threat Intelligence is gathered and assessed to identify realistic real-world adversaries to emulate their modus operandi.
Sekuro simulates the threats and performs a coordinated attack simulation to assess the people, process and technology resilience controls.
Sekuro prepares a report including remediation planning and the creation of a step-by-step attack diagram and timeline.