Red teaming
You give us an objective worth stopping. We spend weeks trying to reach it the way a funded attacker would, and you find out whether anyone noticed.
- duration
- 4–10 weeks
- team
- 3 operators, 1 lead, 1 safety officer
- retest
- Included, 90 days
objective
Agreed with you up front. Usually a specific record, system, or capability — not 'get domain admin'.
initial access
Phishing, exposed services, supply chain, physical entry. Whatever is open.
rules of engagement
Written, signed, and narrow. There is always a named person who can stop the operation in one message.
purple phase
The last week is run in the open with your team, replaying every step until they can catch it.
everything below, on every engagement
A penetration test asks whether a system can be broken. A red team asks whether your people and tooling would stop someone breaking it. Different question, different result.
penetration testing
Time-boxed, scoped testing of a system you already have, graded against exploitability rather than a scanner's opinion.
cloud security review
A read of your AWS, Azure or GCP estate as an attacker reads it: identity first, blast radius second, compliance a distant third.
application security
Design review, threat modelling and code-level testing embedded with the team building the thing.
scope a red teaming
Tell us what the system does and who relies on it. We will come back with a scope, a price and a date, usually within two working days.
