Do you see what your systems miss?
Your systems aren't raising an alarm. But does that mean nothing unwanted is running? The short self-assessment shows you in a few questions how big the gap between your current visibility and actual network activity might be — factually, in 2 minutes.
Free. No login. You see your result immediately.
From which perspective are you answering?
Choose an option to start the self-assessment — the following questions are tailored to your role.
Achim Kraus — Co-Founder and CTO of AEGYS DATALYTICS AG. Achim Kraus has delivered complex security projects for leading cybersecurity companies and develops detection approaches at AEGYS DATALYTICS that work in practice.
Methodically supported by the advisory board of AEGYS DATALYTICS AG — with expertise from international threat research (incl. former Symantec, Acronis), critical infrastructure (NATO Digital Capability), and industrial security (KIT / FZI).
Why a self-assessment is useful — and where it ends
No alert doesn't mean no incident. A SIEM only reports what it's configured for — everything else runs silently past. An average enterprise SIEM covers only about 21% of known attack techniques. That's the finding of the annual CardinalOps analysis of real-world SIEM environments, measured against the MITRE ATT&CK framework with its 600+ documented techniques. The rest stays structurally undetected — not because the SIEM is bad, but because rules only find what they already know.
On average, a breach stays unnoticed for around six months before it's even identified. The IBM Cost of a Data Breach Report 2025 documents it: an average of 181 days to identification, 241 days until a breach is identified and contained. Months in which activity can run without triggering a single alert.
A SIEM can't audit itself. What it doesn't detect, it doesn't know it isn't detecting. That's why an outside assessment pays off — as a first step, the self-test on this page is enough. More on the blind spots in detail in the article on SIEM detection gaps.
What the self-test does — and what it doesn't
The self-test is an assessment, not a measurement. It doesn't look into your network; it helps you judge in a few questions how large the gap probably is between your current visibility and actual network activity. It blocks no attacks, gives no complete picture, and replaces no consulting.
The next step: seeing instead of guessing
Whether your assessment is right, only a look into the real network shows. That's exactly what AEGYS Pulse does: passive visibility at the network level that shows what's actually running — right now. The architecture behind it is described under AEGYS Pulse and SIEM alternative. If you want to do more than assess — if you want to see — you can try AEGYS Pulse in your own network free for 21 days.
If you're wondering how this differs from a classic compromise assessment: A compromise assessment works with agents on endpoints and forensic depth — a multi-week project. AEGYS Pulse works passively at the network level, without agents and without organizational overhead. For organizations that want the question "is undetected activity running on the network?" answered quickly, it's the pragmatic option.
Common questions about the network check
Continuous network visibility and autonomous pentesting — analysis where you choose.
