People & premises

Red team engagement

An objective-based engagement against your whole organization at once: we agree what an attacker would be after, then find a way to it across every surface, and measure what your defenders saw along the way.

8
areas covered
5
stages, scoping to retest
In-house
testers, never subcontracted
portal.cyberlysecure.com/acme-health/coverage
Acme Health — Test coverage4 practices · 15 services · one team
In-house
Web app
API
SaaS
Mobile
Client-side
External
Internal
Segment test
Wireless
Cloud config
Hardware & IoT
AI & LLM
Social eng.
Physical
Red team
ApplicationsNetworkCloud & devicesPeople & premises
6 in scope · one team · one report
In-house testers 0 subcontracted
Every surface one team
What this is

What the test covers.

A pentest asks whether a system is vulnerable. A red team asks whether your organization can be beaten — and whether anyone would notice in time.

We work to an objective you define, using whatever combination of phishing, external access, physical entry and lateral movement reaches it, under strict rules of engagement. The most valuable output is usually the timeline: what we did, when, and what your team saw.

MITRE ATT&CK TIBER-EU principles PTES NIST SP 800-115

What we test

  • An objective you define — a system, a dataset, a transaction or an identity
  • Initial access across every authorized route: phishing, external exposure, physical or supply chain
  • Command and control with realistic operational security
  • Persistence, privilege escalation and lateral movement toward the objective
  • Data exfiltration simulated safely, never with your real data
  • Your detection and response capability, measured against each stage
  • Full mapping to MITRE ATT&CK for comparison over time
  • Purple-team debrief with your defenders once the engagement closes
How it runs

From scoping call to retest, here’s what happens.

Typically four to eight weeks, shaped by the objective and how quietly you want it done.

1

Agree the objective

We define what success looks like, what is out of bounds, who is informed and how we stand down if needed.

2

Plan and prepare

Reconnaissance and infrastructure are built to fit your environment, not a template.

3

Execute quietly

We work toward the objective at a realistic pace, logging every action with a timestamp.

4

Compare notes

Our timeline is set against your detections to show what was caught, what was missed and where the gap was.

5

Debrief and improve

A joint session with your defenders turns the engagement into concrete detection and response improvements.

What it surfaces

The kind of thing this test tends to find.

Real examples of what this engagement uncovers — anonymized, and never every time. What matters is that you find out before somebody else does.

A full path to the objective that no single control would have stopped

Alerts that fired correctly and were closed as noise

Detection coverage that is strong at the endpoint and thin everywhere else

Response processes that work in the daytime and stall overnight

The real time between first foothold and objective — usually shorter than expected

Getting started

What you get, and what we need from you.

What you get

  • Technical report — Every finding, the evidence behind it and clear guidance your engineers can act on.
  • Executive summary — Your risk explained in plain language for leadership and the board.
  • Attestation letter — Signed confirmation of testing to hand your auditors.
  • Readout call — A walkthrough with the people who tested your systems.
  • Retest — Confirmation your fixes worked, documented for whoever needs to see it.

What we need from you

  • An executive sponsor and a small group who know the engagement is running
  • A defined objective and written rules of engagement
  • Emergency contacts and an agreed stand-down procedure
  • Agreement on which surfaces are authorized — cyber, human, physical or all three

Missing something on this list? Bring it to the call — we scope around what you have.

Free attack-surface snapshot

Give us a domain. See what an attacker sees.

Not sure where to start? One of our testers reviews your internet-facing footprint and sends you a short summary of what an attacker would see — free. Nothing you don’t own is ever touched, and there’s no sales sequence.

  • Internet-facing hosts
  • Exposed services
  • Leaked credentials
  • TLS certificate hygiene

Request your snapshot

Free. No obligation.

We only ever test assets you own, with your written authorization.