Red team assessment
A penetration test asks how much is wrong. A red team assessment asks one question instead: can we reach a specific thing you care about, and will anyone stop us on the way? The output is not a findings count. It is a timeline of what we did next to what you saw.
What is included
- An objective you define: a dataset, a system, a transaction, a privilege level
- A realistic starting position agreed in advance
- Quiet operation with tooling and timing chosen to avoid obvious signatures
- A full activity log with timestamps, so every action can be reconciled
- Detection reconciliation against what your team actually saw
What you get
- Narrative timeline of the operation, hour by hour
- Side-by-side comparison of our actions and your alerts
- The specific gaps that let each stage go unnoticed
- Remediation split into what to fix and what to detect
- Live debrief with both the engineering and the detection side
- Attestation letter for auditors and customers, on request
- Remediation attestation after the retest, as a standalone document
Shape of the engagement
- Scoped individuallyFixed in writing before testing starts. Two to four weeks, typicallyTypical window. Built around your deadline if you have one. How pricing works
This is the wrong engagement for most companies
Worth saying plainly, because it is usually the more expensive option and it is often not the one that helps. A red team assessment measures your detection and response. If you already know that detection coverage is thin, or you have not had a penetration test in the last year, you will learn more per dollar from finding and fixing what is actually broken first.
Red teaming earns its place when you have a functioning detection capability and you need to know whether it works against someone trying not to be caught. If that is not you yet, say so on the call and we will scope the engagement that is.
Rules of engagement come first
Objective, permitted techniques, prohibited techniques, in-scope identities and systems, the window, the emergency contact, and the stand-down procedure are all agreed in writing and signed before anything begins. A named person on your side knows the test is running even if the wider team does not, and there is a phone number that stops it immediately.
What it is not
No destructive action. No real data exfiltrated: reaching the objective is proven with a canary file or a hash, not by taking your customer records off the network. No physical intrusion and no untargeted phishing of staff outside the agreed list. Every one of those is available as separately scoped work if you want it.
Questions
Coverage against objective. A penetration test enumerates as much as possible inside a scope and reports everything found. A red team assessment picks one goal and takes the quietest available route to it, which means it deliberately leaves most of your estate untested.
That is your call and it is recorded in the rules of engagement. Most value comes from the wider team not knowing, with at least one named person who does, so the exercise can be stopped and so a real incident is never confused with the test.
By agreement, usually a canary file placed in advance, a hash of a record rather than the record, or a screenshot with the sensitive content redacted at capture time. Nothing leaves your environment that we have not agreed can leave it.
Two to four weeks is typical, because operating quietly means waiting rather than rushing. The window is fixed in the proposal.
Individually. The objective, the starting position, and the length of the window drive it more than any headline scope figure would, so it is scoped on the call and fixed in writing.
Scope it properly before you buy it.
Thirty minutes on the call, a fixed price in writing within 24 hours, and an honest answer if this is not the engagement you need.