Frameworks
The part of the map your tools cannot see.
MITRE ATT&CK and the NIST Cybersecurity Framework give defenders, auditors, and boards a shared map of adversary behavior and defensive obligation. Most security tooling covers the right side of that map, inside the victim's network. Mythic covers the left side: the tactics an adversary executes on their own ground, before and during the breach.
Coverage where the matrix goes dark.
Most of the ATT&CK matrix is written from inside the victim's network, and that is where most detection operates. The earliest tactic columns describe what the adversary does on infrastructure they control, which is exactly what endpoint and network tooling cannot observe. Those columns are where Mythic's collection begins.
Reconnaissance
T1590 · T1598
Before a campaign launches, actors gather victim network information and phish for access. Mythic tracks the actors doing the gathering, so targeting is visible while it is still preparation.
Resource Development
T1583 · T1584 · T1608
Acquiring domains, compromising infrastructure, staging capabilities. This is the tactic column no product inside your network can observe, and it is where Mythic lives: watching adversary infrastructure as it is registered, stood up, and armed.
Command and Control
T1071 · T1568
When victim networks begin talking to tracked infrastructure over application layer protocols or dynamically resolved domains, Mythic observes the exchange directly, from the infrastructure side.
Exfiltration
T1041 · T1048
Exfiltration over the C2 channel is not inferred from volume anomalies. Mythic records the observed exchange, including what was taken, from which machine, and when.
Independent evidence for four of the six functions.
The Cybersecurity Framework organizes a security program into six functions. Mythic is not a control set and does not replace one. What it contributes is something a framework assessment values and internal tooling cannot produce: evidence gathered outside the organization, from the adversary's side of the exchange.
GV.OC · GV.RM · GV.SC
Boards and risk committees need external, independent input to oversee cyber risk, and CSF 2.0 makes supply chain risk management a governance obligation. Mythic gives both an evidence stream that does not depend on the instrumentation, or the candor, of the organizations being overseen, your own suppliers included.
ID.RA
Risk assessment informed by live adversary targeting rather than vulnerability inventories alone: which actors are building toward you, and which of your suppliers are already in contact with their infrastructure.
DE.CM · DE.AE
CSF 2.0 asks for continuous monitoring and adverse event analysis. Mythic extends both beyond the perimeter, adding a monitoring plane your internal telemetry cannot reach and adverse events confirmed by observation rather than correlation.
RS.MA · RS.AN · RS.CO
Incident analysis with timestamped, empirical evidence of what was reached and what was taken, and incident reporting support when the determination carries a regulatory clock, including SEC cyber disclosure.
PROTECT and RECOVER remain the province of your internal controls and continuity planning. Mythic complements them; it does not claim them.
Evidence for the clocks your regulators run.
Beyond the SEC's four-day disclosure rule, most regulated industries carry their own breach clocks and their own evidentiary burdens. Each one ultimately asks the same two questions: what happened, and when did you know. Mythic exists to answer both with observation rather than estimate.
ISO/IEC 27001:2022
A.5.7 · A.5.25 · A.5.26 · A.8.16
Threat intelligence and monitoring
The 2022 revision added A.5.7, a control that requires organizations to collect and analyze threat intelligence and act on it. Mythic satisfies the spirit of that control at its strongest: intelligence specific to your organization, drawn from adversary infrastructure, feeding the event assessment and incident response controls beside it.
HIPAA
45 CFR 164.308 · 164.400 et seq.
Security and breach notification rules
The breach notification rule turns on a risk assessment: whether there is a low probability that protected health information was compromised. Mythic replaces conjecture in that assessment with observation, showing whether data actually moved to adversary infrastructure, what moved, and when the exchange occurred.
GDPR
Articles 33 · 34
72-hour supervisory notification
Controllers must notify their supervisory authority within 72 hours of becoming aware of a personal data breach, and affected individuals when risk is high. The clock and the risk determination both depend on knowing what happened. Empirical evidence of exfiltration compresses days of forensic uncertainty into an answer.
NIS2 / DORA
Early warning 24h · Notification 72h
EU operational resilience
Essential entities under NIS2 owe an early warning within 24 hours; financial entities under DORA must classify and report major ICT incidents on similarly short timelines. Mythic gives European security and compliance teams the earliest possible awareness, often before internal detection, and the evidence to classify severity quickly.
NYDFS
23 NYCRR 500
Cybersecurity event notice
Covered financial institutions must notify the New York Department of Financial Services within 72 hours of a qualifying cybersecurity event. Confirmed, timestamped breach intelligence determines whether the threshold is met and documents the basis for the answer either way.
Mythic informs and accelerates these obligations; the legal determinations they require remain with your counsel and compliance teams.
When the assessor asks the hard question.
Framework conversations turn difficult at a predictable moment: when an assessor, underwriter, or acquirer asks how continuous monitoring extends beyond the perimeter, or what independent evidence supports an incident timeline. Internal telemetry answers with logs the organization generated about itself. Mythic answers with observation from the other side of the exchange.
That distinction matters most when the framework language meets a clock or a signature: a materiality determination on a four-day disclosure timeline, an insurance application warranty, a representation in a purchase agreement. In each case the question is not whether a control exists, but whether the organization can demonstrate what actually happened. Empirical, timestamped, third-party observation is the strongest form that demonstration takes.
See your framework posture from the attacker's side.
MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. NIST and the Cybersecurity Framework are the work of the National Institute of Standards and Technology. Neither organization endorses Vigilocity; the mappings above describe where Mythic's intelligence applies within each framework's structure.
