What Defend means
Defend is the operational front line — the point where everything decided, discovered, and directed either holds up or doesn't. It covers both halves of what most frameworks split into separate stages: detecting that something's wrong, and doing something about it fast enough to matter. The two are inseparable in practice. Detection without a rehearsed response just means watching an incident unfold in real time with better visibility.
The honest test of Defend isn't whether a business has bought monitoring tools — it's whether anyone would actually notice a serious attack within a useful window, and whether the first hour of response is spent executing a plan or improvising one from scratch.
The board question
What your board should be able to answer at this stage
“Would we know if a serious attack was happening right now?”
In practice
What good looks like
- Monitoring covers the systems that actually matter, not just the ones that were easy to instrument
- A written incident response plan exists, and has been tested — not just filed
- Roles are clear: everyone involved knows what they're responsible for in the first hour
- Detection gaps are known and prioritised, not assumed away
Where this shows up