Red Teaming
A goal-oriented, multi-vector engagement that tests whether your organisation detects and responds — not merely whether a vulnerability exists.
What you receive
- Objective-based scenario agreed with your board
- Physical, digital and human attack vectors
- Blue-team detection scorecard
- Purple-team replay workshop
When you need this
Three situations that call for it. If none of them is yours, it probably is not the right spend.
Your detection has never been tested quietly
Every alert your SOC has handled so far came from a real attacker who was clumsy or from a test that announced itself. A red team supplies the case you have never seen — a competent operator with time, deliberately working under your thresholds.
A regulator has asked for threat-led testing
Financial supervisors increasingly require intelligence-led testing against live production systems, run to a prescribed framework with the authority in the loop. That is a different engagement from an annual test, with governance settled long before anyone touches a keyboard.
The board reads a clean test as safe
A test with no critical findings says the tested scope held on the day it was examined. It does not say your response works at 03:00 on a Sunday, which is the question a red team answers with a timeline of what was detected, what was missed and how long each took.
How it runs
Scoping call
Thirty minutes with an engineer, not a sales development rep. We establish what you actually need and tell you plainly if it is not us.
Written proposal
Fixed scope, fixed price, named delivery team, and the rules of engagement in writing before anyone touches a system.
Delivery
Weekly written status and a direct channel to the delivery lead. Critical findings are escalated the moment they are confirmed, never held back for the report.
Readout and retest
A working session with your team, an executive summary for your board, and a remediation retest included in the original scope rather than quoted separately.
No lock-in
Scoping costs nothing and carries no obligation. If the answer is that you do not need this, that is a legitimate outcome of the call.
Who turns up
The engineer on your scoping call is on the delivery team. We do not hand you to a different group after signature.
Scope
What this does not cover
A red team proves one path to the objective. It is not coverage — a vulnerability absent from the report is not a vulnerability absent from the estate.
With no monitoring in place yet there is nothing to measure; testing and detection engineering come first, or you pay to learn what you knew.
Physical entry, lock bypass and pretexted site access are in scope only with written authority from someone with standing to grant it.
- TIBER-EU
- The ECB framework for intelligence-led red teaming against live production systems, overseen by the relevant authority.
- DORA Regulation (EU) 2022/2554, Art. 26
- Requires financial entities identified by their competent authority to carry out threat-led penetration testing at least every three years.
If the scope is wrong
Tell us on the call. Re-scoping before we start costs nothing; discovering it at the readout costs you the engagement.
Questions
The ones we are actually asked.
How is this different from a penetration test?
A penetration test asks what is broken inside an agreed scope, announced, with breadth as the point. A red team asks whether the organisation notices and recovers — unannounced to the defenders, going deep on one objective rather than wide across many.
Who inside our organisation has to know?
A small witting group holds the authorisation and the deconfliction line, usually the sponsor, a legal or HR contact and a control point who can stop the exercise. Everyone else must not know, or what you are measuring is a rehearsal.
What if your operator is caught on day two?
That is a result worth paying for, and it is recorded with the control that caught it and the time it took. The engagement then normally continues from an assumed-breach position, so the later stages are still exercised instead of the budget ending there.
See what an attacker sees
We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.
30 min
A scoping call, with an engineer rather than a sales rep.
What it costs
Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.
Under attack now?
Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.