Red Team
Assessment

Full-scope adversary simulation combining digital, social, and physical vectors — emulating a real threat actor over weeks to test not just your controls, but your people’s ability to detect and respond under pressure.

Overview

Test how you respond, not just what you have.

A penetration test asks "can this be broken?". A red team asks "would we even notice?". It is a goal-oriented, multi-vector simulation of a specific threat actor, run over weeks, designed to test detection and response as much as defences.

We emulate a chosen adversary profile across digital, social, and physical vectors — aligned to MITRE ATT&CK — working toward agreed objectives such as access to crown-jewel data. For physical and covert operations we partner with ex-intelligence professionals.


Scope

What a red team covers.

A single, goal-oriented adversary campaign across every vector.

Methodologies: MITRE ATT&CK PTES Threat-led scenarios Ex-intelligence partners

FAQ

Red team assessment FAQ

The questions we're asked most about scope, cost, and timing.

How much does a red team assessment cost?
A red team engagement typically costs €15,000–35,000 over 15–30 days, depending on objectives, threat profile, and vectors in scope. Contact us for a scoped figure.
What is the difference between a red team and a penetration test?
A penetration test finds as many vulnerabilities as possible in a defined scope. A red team is goal-oriented and stealthy — it emulates a specific adversary to test whether your people and tooling detect and respond. Red teaming suits more mature organisations.
How long does a red team engagement take?
Typically 15 to 30 days of operations, plus planning and reporting.
Do you offer purple teaming?
Yes — collaborative exercises with your defenders to maximise detection improvement, standalone or as a debrief phase after the red team.
Is our security team told in advance?
Usually only a small control group knows, so the response is realistic. Scope, objectives, and safety rules are agreed with that group beforehand.
What do you need to scope a red team?
Your objectives (the "crown jewels"), the threat profile to emulate, in-scope vectors (digital/social/physical), and any no-go areas.
How is a control group involved?
A small, trusted group authorises and oversees the engagement so your wider team’s detection and response stay realistic.
Do you provide an attack narrative?
Yes — a full timeline of actions, what was detected, what was missed, and exactly where to improve.
Can we run it as assumed-breach?
Yes — starting from a foothold focuses budget on detection and response rather than initial access.
Is a red team right for us?
It suits organisations with an existing security function; less mature teams usually get more value from penetration testing first.

Related services

Explore more.

Ready to test your response?

A 30-minute scoping call costs nothing. A real adversary costs considerably more.

Book a meeting Send an email