Red team assessments
We attack your organisation the way a determined adversary would: quietly, over weeks, towards an objective you choose. Your defenders see what they would see in a real incident. You find out how far we got.
Would you notice?
A penetration test asks what is vulnerable. A red team asks whether you would notice an attack in progress, and what you would do about it. It tests detection and response as much as prevention, across technology, people and physical security.
Each engagement is built around the threats that matter to you. We profile the groups targeting your sector and emulate their techniques, mapped to MITRE ATT&CK, so the result shows how you would fare against a realistic attacker rather than a generic one.
What an engagement can include
Reconnaissance
Research into your organisation, people and suppliers, as an attacker would do it.
Initial access
Phishing, exposed services, stolen credentials, supplier routes or physical entry, as agreed.
Persistence and movement
Establishing a foothold and moving towards the objective without being caught.
Objectives
Agreed goals such as access to payment systems, a specific dataset or a senior executiv’s mailbox.
Detection testing
Which of our actions your monitoring saw, and how quickly and well it responded.
Purple team replay
Optionally, replaying the attack step by step with your defenders to improve detections.
How the engagement runs
Objectives and rules
We agree objectives, boundaries and a small control group, the white team, who know the test is happening.
Threat-led planning
We build scenarios from the threat actors relevant to your sector and the reconnaissance we gather.
Covert operation
We run the attack over several weeks, keep the white team informed, and stop if anything risks your operations.
Debrief
An attack narrative, the detection gaps we found and a prioritised plan, with a replay for your defenders if you want one.
What you get
- An attack narrative showing each step and whether it was detected.
- Techniques mapped to MITRE ATT&CK for your detection engineers.
- Detection and response gaps, each with a specific improvement.
When to commission it
- When your security monitoring is mature enough to be tested, usually after several rounds of penetration testing.
- Before or alongside regulator-led threat-led testing such as DORA TLPT or CBEST.
- After investing in a SOC or managed detection service, to find out whether it works.
- When leadership asks “could this happen to us?”
Questions we get asked
How is a red team different from a penetration test?
Who in our organisation knows about it?
How long does it take?
Is it safe?
Related
Threat modelling
Threat modelling for new systems and whole organisations: what could go wrong, who would do it, and which controls matter most, validated against real attacks.
Read more →Social engineering
Social engineering assessments that test how your people and processes respond to phishing, phone pretexting, impersonation and physical intrusion.
Read more →DORA resilience testing
Testing and evidence for the EU Digital Operational Resilience Act, for financial entities and their ICT suppliers.
Read more →SavountEmulating the Enemy – How Adversary Emulation is Elevating Offensive Security
How adversary emulation moved offensive security beyond the annual penetration test, and how to use real attacker behaviour to test your defences.
Read the article →