Reconnaissance
Open-source intelligence on your estate, staff, technology and suppliers — the same footprinting a real operator performs before touching anything you own.
A penetration test asks whether vulnerabilities exist. A red team asks a harder question: if a competent attacker wanted your customer data, would they get it — and would anyone notice?
A penetration test is breadth-first and openly announced: your team knows it is happening, and the goal is to enumerate as much as possible inside a scope.
A red team is depth-first and quiet. We agree a concrete objective with a small number of people in your organisation — read the production customer database, authorise a payment, obtain domain administrator — and then pursue only what gets us there. Your defenders are not told, because their response is part of what is being measured.
That makes it the right exercise once you already have a security programme worth testing, and the wrong one if you have never had a penetration test. If you are unsure which you need, say so on the scoping call and we will tell you honestly — including when the answer is the cheaper engagement.
Scope
Open-source intelligence on your estate, staff, technology and suppliers — the same footprinting a real operator performs before touching anything you own.
Externally exposed services, exposed credentials, and — only with prior written consent — phishing against an agreed population.
Command and control over realistic channels, with persistence that mirrors how genuine intrusions survive a reboot and a password change.
Privilege escalation and lateral movement toward the objective, taking the quietest available path rather than the fastest.
The agreed goal is reached and evidenced — without exfiltrating real customer data. Proof is a screenshot and a record, never a copy of your production database.
Optional and strongly recommended: we walk your defenders through the full timeline, replaying each step so they can tune detections against a real attack they just experienced.
FAQ
No — that is the point. A small group of authorised people (usually the CISO or an equivalent) know, hold the rules of engagement, and can call a halt at any moment. Everyone else responds as they would to a real intrusion.
Only with explicit written consent, an agreed target population, and rules about what we will and will not do with anything we obtain. Credentials captured are used strictly inside the agreed scope and destroyed afterwards.
Rules of engagement define forbidden actions, and there is a named contact plus a kill switch available for the whole exercise. We stop the moment we are asked, and we will not take an action likely to disrupt production without approval.
Typically three to six weeks of elapsed time. Much of that is deliberately slow — moving quietly is most of the exercise, and rushing it would test something other than your real defences.
Next step
Tell us what you have built. You get a reply within one business day, an NDA, and a free 30-minute scoping call with the person who will do the testing.