ARMORARMOR

About

Why ARMOR

The problem ARMOR was built to address

The Gap

Over the past several years, I have spoken with hundreds of CISOs and security leaders across organizations of every size, from small businesses to global enterprises. Despite differences in budget and technology, they share a common challenge: most are not using offensive security results to drive tactical, operational, and strategic decisions.

That gap is not from neglect. It is the result of how our industry has evolved. For decades, frameworks and compliance programs have taught us to treat offensive security as validation, not as a continuous discipline. Penetration testing has become our annual report card. Teams work hard all year to strengthen defenses, only to test them once, patch what is found, and repeat the cycle.

Think of athletics. If teams only trained in the gym but never practiced the game, they would be strong in theory but untested in execution. That is where cybersecurity finds itself today. We build strong networks and write detailed procedures, yet rarely test them under real pressure.

What ARMOR Is

ARMOR was created to change that, helping organizations move from periodic testing to continuous, adaptive resilience. It is not a product or a tool, and it is not owned by any vendor. It is a vendor-agnostic model built to turn testing into an ongoing discipline that strengthens detection, response, and organizational confidence.

The model provides a structured, honest language for where a program actually stands and what needs to change. It evaluates both the technical practice of offensive security and the organizational infrastructure built to act on what testing reveals, because most programs that struggle are not failing at one of those things. They are failing at both, in different ways, at the same time.

The Author

ARMOR was created by Greg Anderson, an offensive security practitioner with experience across organizations ranging from early-stage companies to large enterprises. Over many years of program assessments and leadership conversations, Greg has worked with organizations at every stage of the journey, from those building the earliest foundations of an offensive security capability to those advancing into continuous red-teaming, active threat modeling, and recurring cross-functional tabletop exercises. The model reflects the patterns, gaps, and inflection points observed across that full spectrum.

Greg Anderson

Greg Anderson

Creator, The ARMOR Model