Adversarial security testing

Objective-based red teaming and threat-led penetration testing that assess how your organization prevents, detects, and responds to a targeted attack.

On this page

What adversarial testing is

A red team engagement tests whether your organization can prevent, detect, and respond to a targeted attack. We work toward objectives agreed with you, such as reaching a specific system or dataset, using techniques drawn from threat intelligence relevant to your sector.

It suits organizations with an established security program and a detection and response function, in house or through a provider. A small control team on your side knows about the test. Your wider staff and defenders do not, so their response can be assessed.

What can be in scope

Scenarios are built from the objectives and limits you agree with us.

Objective-based adversary simulation

Scenarios built around goals you set, such as access to a payment system, customer data, or a privileged account.

Initial access

External exposure, phishing, and other entry routes that the scenario calls for.

Lateral movement and privilege escalation

Movement from initial access toward the objective through identity, network, and cloud paths.

Social engineering

Phishing, phone-based pretexting, and similar techniques aimed at staff, run only where agreed and within the limits you set.

Physical access

Attempts to enter offices or sites and reach internal networks, run only if agreed in writing.

Detection and response

How your security operations team detects, investigates, and contains the activity, compared against the timeline of the test.

How an engagement runs

We agree objectives, scenarios, in-scope and excluded systems, people, and sites, permitted techniques, and the members of your control team. Social engineering and physical testing are included only if agreed. Everything is recorded in the rules of engagement, and an NDA is signed before you share details.

What you receive

Each engagement produces the same set of deliverables, sized to the objectives and scope you agree with us.

Agreed scope

  • Written scope covering targets, environments, and accounts
  • Rules of engagement with test windows, excluded actions, and contacts
  • NDA signed before you share details

Findings

  • Each finding rated by severity
  • Timeline of test actions alongside what was detected

Reports

  • Executive report for leadership and stakeholders
  • Technical report with reproduction steps for each finding
  • Remediation guidance your engineers can act on

Retest

  • Retest of findings after your team applies fixes
  • Updated status for each retested finding

Engagement types

Duration depends on scope.

TypeWhat it testsWhen it fits
Penetration testKnown systems in an agreed scope, for as many vulnerabilities as possibleYou need coverage of specific applications or infrastructure.
Objective-based red teamWhether a scenario can reach agreed objectives, and whether it is detectedYour security program is established and you want to test detection and response.
Social engineering assessmentStaff responses to phishing or pretexting, within agreed limitsYou want to measure awareness and reporting processes.
Threat-led penetration testing (TLPT)Live production systems supporting critical or important functions, using scenarios based on threat intelligenceYou are a financial entity required to carry out TLPT under DORA.

Threat-led penetration testing for DORA

The EU Digital Operational Resilience Act (DORA) requires financial entities identified by their competent authority to carry out threat-led penetration testing (TLPT) at least every three years. The test covers live production systems supporting critical or important functions.

TLPT under DORA follows the regulatory technical standards on TLPT, which are aligned with the TIBER-EU framework. A test has a preparation phase, a testing phase with threat intelligence followed by red team testing, and a closure phase with reporting, replay of the test with your defenders, and remediation planning. The competent authority oversees the test.

We can discuss your TLPT requirements during scoping, including the critical or important functions in scope, how we work with your threat intelligence provider, and how the red team phase is run.

Standards and methods

Scenarios and reporting are mapped to MITRE ATT&CK. Threat-led engagements for financial entities are aligned with TIBER-EU and the DORA requirements on TLPT.

Testing methods follow NIST SP 800-115 and the Penetration Testing Execution Standard (PTES).

Common questions

Who on our side knows about the test?

A small control team, usually a senior sponsor and a security lead. They approve scenarios, receive updates at agreed checkpoints, and can pause the test.

Will testing affect production?

Red team activity runs in production. The rules of engagement exclude actions that could disrupt services, set limits on data access, and define how the control team and our team stay in contact during testing.

Is social engineering or physical testing always included?

No. Both are optional and included only if you agree to them. Limits on targets, methods, and locations are recorded in the rules of engagement.

Do we need to be regulated under DORA to run a red team?

No. Objective-based red teaming is available to any organization. TLPT under DORA applies to financial entities identified by their competent authority.

How are findings shared securely?

We sign an NDA before you share details of your environment. How reports and other sensitive material are exchanged is agreed with your team during scoping.

Can you provide a letter for our customers?

We can discuss it during scoping.

How to prepare

Agree an internal sponsor and name the control team. Choose objectives that matter to the business, such as access to a critical system or dataset, and identify any systems, people, or sites that must be excluded.

Confirm legal and HR approval for any social engineering, and approval from site owners for any physical testing. For TLPT, confirm the critical or important functions in scope and follow your competent authority's process for starting the test.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.