Adversary Simulation

Not a test of your systems. A test of your defence.

A penetration test asks whether you have vulnerabilities. A red team engagement asks a better question: if a competent attacker came after you for three weeks, would anybody notice?

Recon detected Access not seen Escalate not seen Move detected Objective not seen Detection coverage 3 of 5 stages passed unnoticed
ATT&CKTechnique mapped
ObjectiveBased scoping
PurpleTeam option
DetectionTimeline reported

When a red team is the right thing to buy — and when it is not

Red teaming is oversold. Most organisations that ask for one would get considerably more value from a thorough internal penetration test, because a red team engagement is deliberately narrow: it pursues one objective by the quietest route available and ignores everything else. If your Active Directory has never been assessed, a red team will find one path to domain admin and stop. A penetration test would have found eleven and told you about all of them.

The engagement is worth buying when you have a security function that is meant to detect and respond, and you want to know whether it does. Not whether the tooling is licensed and the dashboards are green — whether anybody acts, at 2am on a Saturday, on the third alert of the evening. That is not a technology question, and it is the only way to answer it honestly.

We scope red team work against objectives that mean something to your business: reach the customer database, authorise a payment, obtain the source code, access the production environment from a standard user account. Then we work towards it the way an adversary would, and we record exactly what your defences saw at each step.

Coverage

What an engagement can include

Scoped tightly, agreed in writing, with rules of engagement covering what is permitted and what is explicitly out of bounds.

External compromise

Reaching an initial foothold from the internet through exposed services, weak authentication or an application flaw.

Social engineering

Targeted phishing and pretext contact against agreed populations, run to test process and response rather than to embarrass individuals.

Assumed breach

Starting from a standard user workstation, which removes the initial-access lottery and concentrates the engagement on the part that matters most.

Lateral movement and escalation

Moving through the estate towards the objective, with each step recorded against MITRE ATT&CK.

Detection and response evaluation

What your tooling generated, what reached your analysts, what they did, and how long each stage took.

Data objective

Demonstrating reach to the agreed target — proof of access, never exfiltration of real data.

Physical entry

Where scoped and legally authorised: reception access, tailgating and unattended network ports.

Purple team collaboration

The alternative delivery model — running techniques openly alongside your defenders to build detection as we go.

Approach

How a red team engagement runs

Typically three to six weeks, with a small number of named people on your side aware that it is happening.

  1. 01 · Objectives and rules

    What would constitute success for an attacker, what is strictly out of bounds, who the control contacts are, and what triggers an immediate stop.

  2. 02 · Reconnaissance

    Public information about the organisation and its people, exactly as an adversary would gather it before committing to anything.

  3. 03 · Initial access

    Gaining a foothold by the agreed vectors, or starting from an assumed-breach position if that is the model chosen.

  4. 04 · Operate

    Working towards the objective at a realistic pace, recording every technique used and every defensive response observed.

  5. 05 · Objective and evidence

    Demonstrating reach to the target, with proof captured and nothing removed.

  6. 06 · Debrief and replay

    A full walkthrough with your defenders, replaying the timeline against what they saw, then building the detections that were missing.

Run against recognised standards

  • MITRE ATT&CKTechnique mapping throughout
  • TIBER-EU principlesThreat-led engagement structure
  • PTESExecution standard

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

Attack narrative

The full story, in order, with timestamps — readable by an executive and detailed enough for an engineer.

ATT&CK coverage matrix

Every technique used, marked against whether it was prevented, detected, or passed unnoticed.

Detection timeline

What your tooling generated versus what your team acted on, and the gap between the two.

Prioritised improvements

The specific detections and controls that would have stopped us, ranked by how much of the chain each one breaks.

Purple team replay

A working session re-running key techniques with your defenders to validate the new detections.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • You have a SOC or a managed detection service and have never independently tested it.
  • Penetration testing findings have been closed for two years running and you want a harder question.
  • Your board or regulator has asked for threat-led testing.
  • You want to justify security investment with evidence rather than argument.
  • You are confident in your defences. That is usually the right moment.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Red Team Assessment — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

What is the difference between red teaming and penetration testing?

A penetration test is breadth-first and openly conducted: find as many exploitable weaknesses as possible in a defined scope, within a defined window, with your team aware it is happening. A red team engagement is objective-first and covert: pursue one goal by the quietest available route, and measure whether your defences detect and respond. Penetration testing improves your systems; red teaming improves your security operations. Most organisations need the first several times before the second is worth buying.

Should we tell our security team?

Only a very small number of named people, usually the CISO and one control contact. The point of the engagement is to observe genuine response behaviour, which disappears the moment the team knows a test is running. Those named contacts hold a written authorisation letter so that if anybody escalates to law enforcement or a supplier, it can be stopped immediately.

Is social engineering always included?

No, it is scoped explicitly and can be excluded entirely. Where it is included, we agree the target population and the pretexts in advance, and we report results in aggregate. We do not name individuals who fell for a phishing email — that turns a control test into a disciplinary exercise and destroys the willingness to report incidents that you actually depend on.

What is purple teaming?

The collaborative version. Instead of operating covertly, we run adversary techniques openly and in real time alongside your defenders, checking after each one whether it generated telemetry, whether it alerted, and whether the alert was actionable. It builds detection capability far faster than a covert engagement, and for teams that are still maturing it is usually the better investment.

Could this damage our production systems?

The rules of engagement define what is permitted before anything starts, and destructive activity is excluded by default. We operate deliberately and slowly, we maintain a log of every action taken so anything can be traced and reversed, and there is a named contact on both sides with the authority to stop the engagement immediately at any hour.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.