What adversarial testing is
A red team engagement tests whether your organization can prevent, detect, and respond to a targeted attack. We work toward objectives agreed with you, such as reaching a specific system or dataset, using techniques drawn from threat intelligence relevant to your sector.
It suits organizations with an established security program and a detection and response function, in house or through a provider. A small control team on your side knows about the test. Your wider staff and defenders do not, so their response can be assessed.
What can be in scope
Scenarios are built from the objectives and limits you agree with us.
Objective-based adversary simulation
Scenarios built around goals you set, such as access to a payment system, customer data, or a privileged account.
Initial access
External exposure, phishing, and other entry routes that the scenario calls for.
Lateral movement and privilege escalation
Movement from initial access toward the objective through identity, network, and cloud paths.
Social engineering
Phishing, phone-based pretexting, and similar techniques aimed at staff, run only where agreed and within the limits you set.
Physical access
Attempts to enter offices or sites and reach internal networks, run only if agreed in writing.
Detection and response
How your security operations team detects, investigates, and contains the activity, compared against the timeline of the test.
How an engagement runs
We agree objectives, scenarios, in-scope and excluded systems, people, and sites, permitted techniques, and the members of your control team. Social engineering and physical testing are included only if agreed. Everything is recorded in the rules of engagement, and an NDA is signed before you share details.
We carry out the scenarios and keep the control team informed at agreed checkpoints. The control team can pause or stop the test.
The executive report covers which objectives were reached, what was detected, and the main gaps. The technical report gives a timeline of actions, techniques mapped to MITRE ATT&CK, findings rated by severity, reproduction steps, and remediation guidance.
After your team addresses the findings, we retest them. Where detection was the gap, the retest can replay the relevant techniques so your team can confirm new detections work.
What you receive
Each engagement produces the same set of deliverables, sized to the objectives and scope you agree with us.
Agreed scope
- Written scope covering targets, environments, and accounts
- Rules of engagement with test windows, excluded actions, and contacts
- NDA signed before you share details
Findings
- Each finding rated by severity
- Timeline of test actions alongside what was detected
Reports
- Executive report for leadership and stakeholders
- Technical report with reproduction steps for each finding
- Remediation guidance your engineers can act on
Retest
- Retest of findings after your team applies fixes
- Updated status for each retested finding
Engagement types
Duration depends on scope.
| Type | What it tests | When it fits |
|---|---|---|
| Penetration test | Known systems in an agreed scope, for as many vulnerabilities as possible | You need coverage of specific applications or infrastructure. |
| Objective-based red team | Whether a scenario can reach agreed objectives, and whether it is detected | Your security program is established and you want to test detection and response. |
| Social engineering assessment | Staff responses to phishing or pretexting, within agreed limits | You want to measure awareness and reporting processes. |
| Threat-led penetration testing (TLPT) | Live production systems supporting critical or important functions, using scenarios based on threat intelligence | You are a financial entity required to carry out TLPT under DORA. |
Threat-led penetration testing for DORA
The EU Digital Operational Resilience Act (DORA) requires financial entities identified by their competent authority to carry out threat-led penetration testing (TLPT) at least every three years. The test covers live production systems supporting critical or important functions.
TLPT under DORA follows the regulatory technical standards on TLPT, which are aligned with the TIBER-EU framework. A test has a preparation phase, a testing phase with threat intelligence followed by red team testing, and a closure phase with reporting, replay of the test with your defenders, and remediation planning. The competent authority oversees the test.
We can discuss your TLPT requirements during scoping, including the critical or important functions in scope, how we work with your threat intelligence provider, and how the red team phase is run.
Standards and methods
Scenarios and reporting are mapped to MITRE ATT&CK. Threat-led engagements for financial entities are aligned with TIBER-EU and the DORA requirements on TLPT.
Testing methods follow NIST SP 800-115 and the Penetration Testing Execution Standard (PTES).
Common questions
Who on our side knows about the test?
A small control team, usually a senior sponsor and a security lead. They approve scenarios, receive updates at agreed checkpoints, and can pause the test.
Will testing affect production?
Red team activity runs in production. The rules of engagement exclude actions that could disrupt services, set limits on data access, and define how the control team and our team stay in contact during testing.
Is social engineering or physical testing always included?
No. Both are optional and included only if you agree to them. Limits on targets, methods, and locations are recorded in the rules of engagement.
Do we need to be regulated under DORA to run a red team?
No. Objective-based red teaming is available to any organization. TLPT under DORA applies to financial entities identified by their competent authority.
How are findings shared securely?
We sign an NDA before you share details of your environment. How reports and other sensitive material are exchanged is agreed with your team during scoping.
Can you provide a letter for our customers?
We can discuss it during scoping.
How to prepare
Agree an internal sponsor and name the control team. Choose objectives that matter to the business, such as access to a critical system or dataset, and identify any systems, people, or sites that must be excluded.
Confirm legal and HR approval for any social engineering, and approval from site owners for any physical testing. For TLPT, confirm the critical or important functions in scope and follow your competent authority's process for starting the test.

