Red Team Assessment
Objective-based red team exercise
We act as a real attacker to assess whether your organization notices and stops us before the objective is reached.
Rather than the number of vulnerabilities, we look at whether an agreed objective can be reached and how prevention, detection, reporting and response connect along the way. You can choose to run it with only executives and a small approved group aware.
Would the organization notice and stop an attacker going after an agreed objective? Reviewed
Whether the objective was reached, and the evidence on the response, assessed together.
When it fits
- You don't know whether you'd notice a real attack
You have security tools, monitoring and response procedures, and need evidence that they notice and stop a real attack.
- You want to know how far one breach could spread
If one staff PC or account were compromised, would the attack reach critical systems, and where along the way could it be stopped?
- Your yearly tests may not look like a real attacker
Rather than counting vulnerabilities, you want to see how an attacker chains weaknesses toward an objective, and how you respond on the way.
- Leadership wants a test close to the real thing
Your board or executives are asking how well you would hold up against a real attack. It can run without telling the security team, with only a few approvers aware.
What we assess
We see how far an attack gets, and record, stage by stage, how the organization notices and stops it. The response is observed as it happens and reviewed together afterwards.
If agreed, phishing and social engineering, supply chain, wireless and physical access can be included within the approved scope.
To fix detection together with the attack side, technique by technique, choose Purple Teaming & Detection Validation. Purple Teaming & Detection Validation
Objectives and conditions come first
Before starting, we settle these with an authorized approver.
- Objectives
What the assessment tries to reach, and how success and the response will be judged.
- Scope and limits
The systems, people and methods in scope, and what is off limits.
- Safety and stop conditions
Anything that could affect operations happens only with an agreed immediate-stop procedure in place.
- Who knows in advance
Announced, known to a few named people, or unannounced. We also agree who approves and how we stay in contact during the exercise.
How it runs
Agree objectives and conditions
With an authorized approver we set the objective, scope and limits, safety and stop conditions, and who knows in advance.
Prepare the scenario
We prepare attack scenarios for the agreed objective and methods, and confirm how we stay in contact during the exercise.
Run and record
Playing the attacker, we move toward the objective and record, at each stage, what we did and how the organization reacted.
Review together
Afterwards we go through the attack record and the response record with the teams involved.
Improve and re-check
We set out what to strengthen and, if agreed, check again after changes are made.
What you receive
A timeline of what happened, how your organization responded at each step, and what to strengthen next.
Attack scenario and timeline
The paths taken, how they unfolded over time, and whether the objective was reached or where the attack was stopped.
Detection and response assessment
What was actually blocked, detected and reported at each stage, and how your organization responded.
Improvements and follow-up checks
Where detection and response need strengthening, and what to check again after changes are made.