Red team operations
A goal-driven simulation of a real adversary against people, process and technology, to test whether an attack would be detected and stopped.
Adversary simulation
Controlled phishing, phone and messaging campaigns that measure how people and processes respond, with results by group and never by name.
Adversary simulation
Most intrusions still begin with a person: a convincing email, a call from someone who claims to be IT support, a message from a manager who is supposedly in a meeting. Technical controls filter a part of it. The rest depends on whether people recognise the attempt and whether the process gives them a way to report it.
We run campaigns built the way real attackers build them, with every scenario approved by you in advance, and measure what matters: not only who clicked, but who reported, how fast the report reached the security team and what the team did with it.
01Scope
02Approach
Scenarios are written and approved one by one. No scenario uses threats, personal hardship or health, and none targets private accounts or devices.
Domains and infrastructure are prepared for the campaign. You decide whether the test measures the people alone or the people together with the mail filters.
Messages and calls go out in waves. The control group in your organisation is informed of each wave.
Results are aggregated by group and by scenario. The report contains no names and no data that identifies an individual.
03
04
05Standards
Catalogue of adversary techniques used to plan operations and to report detection coverage.
The MITRE Corporation
Structure of threat-led red team tests: threat intelligence, red team phase, closure.
European Central Bank
Planning, rules of engagement and conduct of technical testing.
NIST
06Questions
No. Results are reported by group and scenario. The purpose is to improve the process, not to find someone to blame. Naming people destroys their willingness to report, and reporting is the most valuable control there is.
With the authorisation of the employer and within the labour and data protection law of your jurisdiction. In some countries employee representatives must be consulted. We raise the question during scoping; the legal assessment is made by your lawyers.
No. Submitted credentials are not stored and not used; the campaign records only that a submission took place. Where a bypass of MFA is in scope, it is demonstrated on test accounts created for the purpose.
08Request
Reference
Keep the reference: we name it in all further communication with you.
We never ask for payment, passwords or remote access in the first reply.