Red Team Assessment
Red team assessment across Europe: a goal-driven, multi-vector attack simulation that tests your detection and response. Fixed price, full debrief.
A red team assessment measures something a standard pentest never touches: not just whether you have holes, but whether you would notice a real, patient attacker walking through them toward a specific goal. We pick an objective that matters to your business, then reach it using whatever combination of technical, human and physical routes works, exactly as an actual adversary would.
A penetration test asks “what’s broken here?” and enumerates weaknesses in a defined scope. A red team assessment asks a harder question: “if a capable group decided to steal our customer database or move money, could they, and would anyone stop them?” The difference is objective-led thinking and stealth. We’re not trying to find every bug. We’re trying to win, quietly, the way the people you actually fear would.
What a red team assessment covers
The engagement is defined by a goal, not a scope list. You name the crown jewels: the finance system, the customer data, the source code, the ability to issue a payment. We then work every avenue toward that goal while your defenders try to catch us, and we measure both the path and the response.
Objective first, scope second
We start by agreeing what “success” means for the attacker and what’s genuinely off limits. Everything else stays open, because a real adversary doesn’t respect your network diagram. That freedom is the point: it surfaces the gaps between your neatly-scoped controls, which is exactly where real breaches happen.
Stealth is part of the test
Unlike a pentest, where noise is fine, a red team assessment is graded partly on staying undetected. We move slowly, blend into normal traffic, and use living-off-the-land techniques so that every alert we do or don’t trigger tells you something about your monitoring. Everything runs under a strict rules-of-engagement document and NDA.
How a red team engagement runs
We follow the same lifecycle a real threat actor does, and we borrow the structure of recognised frameworks such as TIBER-EU and the MITRE ATT&CK matrix so the results map cleanly onto how your defenders think.
Reconnaissance and threat modelling
We build a picture of your organisation the way an attacker would: exposed infrastructure, employee footprints on social media and in breach data, suppliers, physical sites. From this we model the most realistic threat actor for your business and plan the campaign around how they would actually operate, not around what’s easiest for us.
Initial access
Getting in is rarely the hard part. A targeted phishing campaign against a handful of well-chosen employees, an exposed service with a weak credential, or a tailgate through a side door during a smoke break: any of these gives the foothold. We use whichever fits the threat model and, where you allow it, more than one, because the goal is to reach the objective, not to demonstrate a single trick.
Command and control
Once inside, we establish quiet, resilient communication back to our infrastructure using modern C2 tooling configured to look like ordinary web traffic. How long that channel survives, and whether anything flags it, is one of the most valuable data points the engagement produces.
Actions on objective
From the foothold we escalate, move laterally and hunt for the path to the goal, exactly as covered in our internal-network and Active Directory work but with stealth as a constant constraint. When we reach the crown jewels we prove it, gather evidence, and stop. We never exfiltrate real sensitive data; a marker file or a redacted sample is enough to demonstrate the impact.
Reporting and debrief
The written report tells the full story from reconnaissance to objective, with every technique mapped to MITRE ATT&CK and a clear timeline of what your defenders saw and when. Then we sit down with your team for a debrief and, if you want it, a replay where we walk through each step so your SOC can tune its detections against real attacker behaviour.
What a red team tells you that a pentest can’t
The two are complementary, and the honest answer is that most organisations should do a pentest first. A red team assessment is what you commission once the basics are solid and you need to know whether your people and your monitoring actually work under pressure.
Whether your detection works in anger
You’ve bought the EDR, stood up the SOC, written the runbooks. The only way to know they function against a real intrusion is to run one. We tell you which of our actions raised an alert, which were investigated, which were escalated, and which sailed straight through unnoticed.
How fast your response actually is
Mean time to detect and mean time to respond are only theoretical until they’re tested. A red team assessment gives you real numbers against a real campaign: how long we sat on the network, how long from our first noisy action to a human looking at it, and whether the response contained us or just watched.
Where controls fall between the cracks
Each of your controls may be fine in isolation. The gaps are in the seams: the alert that fires but goes to an unmonitored inbox, the segmentation that stops the wrong traffic, the process that assumes someone else is watching. Objective-led testing lives in those seams.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Scenarios we commonly run
The right scenario mirrors the threat your organisation actually faces, drawn from real incidents in your sector. A few recur often enough to describe.
The phished employee
One person clicks, one credential is captured, and the question becomes how far that single mistake reaches. This scenario tests the whole chain: email filtering, MFA, endpoint detection, segmentation and the SOC’s ability to spot a foothold turning into lateral movement. It’s the most common real-world breach, so it’s the most instructive to rehearse.
The malicious insider or contractor
Here we start with the access a disgruntled employee or a compromised contractor already has, and see how much damage that trusted position allows. It exposes over-broad permissions and the absence of controls that assume the threat is always external.
The ransomware precursor
We follow the playbook a ransomware crew uses up to the point of deployment: initial access, credential theft, reaching the backup infrastructure and domain controllers. Reaching the backups without triggering a response is the finding that changes how most boards think about their recovery plan.
What you get
More than a document. A narrative, a defender’s roadmap, and a working session that leaves your team measurably better.
Attack narrative and executive summary
A readable story of the engagement for leadership and the board: what we set out to steal, whether we got it, how long it took, and what a real attacker doing the same would cost you. This is the version that gets budget approved.
Technical report and ATT&CK mapping
Every technique documented with evidence, mapped to MITRE ATT&CK tactics and techniques, cross-referenced against what your telemetry captured. Your blue team gets a precise list of detection gaps to close, ranked by how much they’d have mattered.
Debrief, retest and attestation
A live debrief and optional purple-team session, an attestation letter for regulators and clients, and a follow-up test after you’ve made changes to confirm the gaps are genuinely closed.
Compliance and regulatory frameworks
Red team testing is increasingly expected rather than optional, particularly in regulated European sectors, and we align each engagement to the relevant framework.
DORA and TIBER-EU
For financial entities, DORA introduces threat-led penetration testing as a formal expectation, building on the established TIBER-EU framework for intelligence-led red teaming. Our engagements are structured to support these requirements, with the threat intelligence, scenario design and reporting they call for.
NIS2, ISO 27001 and SOC 2
NIS2 raises the bar for essential and important entities to test their resilience, ISO 27001 Annex A vulnerability-management controls benefit from adversarial testing, and SOC 2 auditors increasingly ask for evidence that detection and response actually work. A red team report speaks to all three.
Pricing
A red team assessment is a larger commitment than a pentest because it runs for weeks, uses multiple attack vectors and includes intelligence and reporting depth a standard test doesn’t. Cost depends on the objectives, the number of vectors in play and the duration. Here is the shape of a typical European engagement.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Focused scenario | Single objective, one or two vectors such as phishing plus external, C2 and lateral movement, full report and debrief | 2–3 weeks | from €12,000 |
| Full red team | Multiple objectives and vectors including physical, stealthy long-haul operation, detection assessment and ATT&CK mapping | 4–6 weeks | €15,000–€40,000 |
| Purple team | Collaborative engagement with your SOC, live detection tuning and technique replay | 2–4 weeks | €14,000–€30,000 |
| Threat-led (DORA / TIBER-style) | Intelligence-led scenario design, threat modelling and reporting aligned to regulatory expectations | 6–12 weeks | from €35,000 |
| Custom / large estate | Multi-site or group-wide programme, scoped after a call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a follow-up test included. Get a fixed quote
FAQ
How much does a red team assessment cost?
How is a red team different from a penetration test?
How long does an engagement take?
Will you tell our security team it’s happening?
Do you actually steal our data to prove the point?
Do your red team testing services cover physical and social engineering?
Does this help with DORA or NIS2?
What do we get afterwards?
Related services
Organisations that have already done the fundamentals and now need to test people and process under a realistic attack: banks and financial entities facing DORA threat-led testing, mature security teams that want to prove their SOC and EDR work in anger, and boards that need honest evidence of how a determined adversary would fare against them.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.