Home/Services/Red Team Assessment
security service

Red Team Assessment

Red team assessment across Europe: a goal-driven, multi-vector attack simulation that tests your detection and response. Fixed price, full debrief.

Manual, expert-ledEvidence-based findingsFree remediation retest

A red team assessment measures something a standard pentest never touches: not just whether you have holes, but whether you would notice a real, patient attacker walking through them toward a specific goal. We pick an objective that matters to your business, then reach it using whatever combination of technical, human and physical routes works, exactly as an actual adversary would.

A penetration test asks “what’s broken here?” and enumerates weaknesses in a defined scope. A red team assessment asks a harder question: “if a capable group decided to steal our customer database or move money, could they, and would anyone stop them?” The difference is objective-led thinking and stealth. We’re not trying to find every bug. We’re trying to win, quietly, the way the people you actually fear would.

What a red team assessment covers

The engagement is defined by a goal, not a scope list. You name the crown jewels: the finance system, the customer data, the source code, the ability to issue a payment. We then work every avenue toward that goal while your defenders try to catch us, and we measure both the path and the response.

Goal-based objectives agreed with you, not a generic checklist
Multi-vector entry: phishing, external exploitation and physical access
Stealthy command-and-control and long-haul persistence
Detection and response testing against your SOC or MDR
Lateral movement toward a defined crown-jewel objective
Full TTP mapping to MITRE ATT&CK for your blue team
Optional purple-team collaboration to tune detections live

Objective first, scope second

We start by agreeing what “success” means for the attacker and what’s genuinely off limits. Everything else stays open, because a real adversary doesn’t respect your network diagram. That freedom is the point: it surfaces the gaps between your neatly-scoped controls, which is exactly where real breaches happen.

Stealth is part of the test

Unlike a pentest, where noise is fine, a red team assessment is graded partly on staying undetected. We move slowly, blend into normal traffic, and use living-off-the-land techniques so that every alert we do or don’t trigger tells you something about your monitoring. Everything runs under a strict rules-of-engagement document and NDA.

How a red team engagement runs

We follow the same lifecycle a real threat actor does, and we borrow the structure of recognised frameworks such as TIBER-EU and the MITRE ATT&CK matrix so the results map cleanly onto how your defenders think.

Reconnaissance and threat modelling

We build a picture of your organisation the way an attacker would: exposed infrastructure, employee footprints on social media and in breach data, suppliers, physical sites. From this we model the most realistic threat actor for your business and plan the campaign around how they would actually operate, not around what’s easiest for us.

Initial access

Getting in is rarely the hard part. A targeted phishing campaign against a handful of well-chosen employees, an exposed service with a weak credential, or a tailgate through a side door during a smoke break: any of these gives the foothold. We use whichever fits the threat model and, where you allow it, more than one, because the goal is to reach the objective, not to demonstrate a single trick.

Command and control

Once inside, we establish quiet, resilient communication back to our infrastructure using modern C2 tooling configured to look like ordinary web traffic. How long that channel survives, and whether anything flags it, is one of the most valuable data points the engagement produces.

Actions on objective

From the foothold we escalate, move laterally and hunt for the path to the goal, exactly as covered in our internal-network and Active Directory work but with stealth as a constant constraint. When we reach the crown jewels we prove it, gather evidence, and stop. We never exfiltrate real sensitive data; a marker file or a redacted sample is enough to demonstrate the impact.

Reporting and debrief

The written report tells the full story from reconnaissance to objective, with every technique mapped to MITRE ATT&CK and a clear timeline of what your defenders saw and when. Then we sit down with your team for a debrief and, if you want it, a replay where we walk through each step so your SOC can tune its detections against real attacker behaviour.

3–6
weeks for a typical scenario-based engagement
100%
objective-driven, mapped to MITRE ATT&CK
Full
debrief and detection-tuning workshop

What a red team tells you that a pentest can’t

The two are complementary, and the honest answer is that most organisations should do a pentest first. A red team assessment is what you commission once the basics are solid and you need to know whether your people and your monitoring actually work under pressure.

Whether your detection works in anger

You’ve bought the EDR, stood up the SOC, written the runbooks. The only way to know they function against a real intrusion is to run one. We tell you which of our actions raised an alert, which were investigated, which were escalated, and which sailed straight through unnoticed.

How fast your response actually is

Mean time to detect and mean time to respond are only theoretical until they’re tested. A red team assessment gives you real numbers against a real campaign: how long we sat on the network, how long from our first noisy action to a human looking at it, and whether the response contained us or just watched.

Where controls fall between the cracks

Each of your controls may be fine in isolation. The gaps are in the seams: the alert that fires but goes to an unmonitored inbox, the segmentation that stops the wrong traffic, the process that assumes someone else is watching. Objective-led testing lives in those seams.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Scenarios we commonly run

The right scenario mirrors the threat your organisation actually faces, drawn from real incidents in your sector. A few recur often enough to describe.

The phished employee

One person clicks, one credential is captured, and the question becomes how far that single mistake reaches. This scenario tests the whole chain: email filtering, MFA, endpoint detection, segmentation and the SOC’s ability to spot a foothold turning into lateral movement. It’s the most common real-world breach, so it’s the most instructive to rehearse.

The malicious insider or contractor

Here we start with the access a disgruntled employee or a compromised contractor already has, and see how much damage that trusted position allows. It exposes over-broad permissions and the absence of controls that assume the threat is always external.

The ransomware precursor

We follow the playbook a ransomware crew uses up to the point of deployment: initial access, credential theft, reaching the backup infrastructure and domain controllers. Reaching the backups without triggering a response is the finding that changes how most boards think about their recovery plan.

What you get

More than a document. A narrative, a defender’s roadmap, and a working session that leaves your team measurably better.

Attack narrative and executive summary

A readable story of the engagement for leadership and the board: what we set out to steal, whether we got it, how long it took, and what a real attacker doing the same would cost you. This is the version that gets budget approved.

Technical report and ATT&CK mapping

Every technique documented with evidence, mapped to MITRE ATT&CK tactics and techniques, cross-referenced against what your telemetry captured. Your blue team gets a precise list of detection gaps to close, ranked by how much they’d have mattered.

Debrief, retest and attestation

A live debrief and optional purple-team session, an attestation letter for regulators and clients, and a follow-up test after you’ve made changes to confirm the gaps are genuinely closed.

Compliance and regulatory frameworks

Red team testing is increasingly expected rather than optional, particularly in regulated European sectors, and we align each engagement to the relevant framework.

DORA and TIBER-EU

For financial entities, DORA introduces threat-led penetration testing as a formal expectation, building on the established TIBER-EU framework for intelligence-led red teaming. Our engagements are structured to support these requirements, with the threat intelligence, scenario design and reporting they call for.

NIS2, ISO 27001 and SOC 2

NIS2 raises the bar for essential and important entities to test their resilience, ISO 27001 Annex A vulnerability-management controls benefit from adversarial testing, and SOC 2 auditors increasingly ask for evidence that detection and response actually work. A red team report speaks to all three.

Pricing

A red team assessment is a larger commitment than a pentest because it runs for weeks, uses multiple attack vectors and includes intelligence and reporting depth a standard test doesn’t. Cost depends on the objectives, the number of vectors in play and the duration. Here is the shape of a typical European engagement.

Engagement What’s included Timeline Price
Focused scenario Single objective, one or two vectors such as phishing plus external, C2 and lateral movement, full report and debrief 2–3 weeks from €12,000
Full red team Multiple objectives and vectors including physical, stealthy long-haul operation, detection assessment and ATT&CK mapping 4–6 weeks €15,000–€40,000
Purple team Collaborative engagement with your SOC, live detection tuning and technique replay 2–4 weeks €14,000–€30,000
Threat-led (DORA / TIBER-style) Intelligence-led scenario design, threat modelling and reporting aligned to regulatory expectations 6–12 weeks from €35,000
Custom / large estate Multi-site or group-wide programme, scoped after a call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and a follow-up test included. Get a fixed quote

FAQ

How much does a red team assessment cost?
A focused red team assessment starts from €12,000, with full multi-vector engagements typically €15,000 to €40,000 depending on objectives, vectors and duration. You get a fixed quote after a free scoping call rather than an hourly rate.
How is a red team different from a penetration test?
A pentest enumerates weaknesses in a defined scope. A red team assessment is goal-driven and stealthy: we pick an objective that matters to your business and reach it using any vector, while measuring whether your detection and response catch us. Most organisations should run a pentest first.
How long does an engagement take?
A focused scenario runs 2–3 weeks and a full red team 4–6 weeks, because staying stealthy means moving slowly. Threat-led engagements aligned to DORA or TIBER-style expectations can run several weeks longer for the intelligence and scenario phases.
Will you tell our security team it’s happening?
Usually only a small number of trusted people know, so the test measures a genuine response. Those people, the “white cell”, can stop the engagement at any time. The rules of engagement and safety controls are agreed with them before we start.
Do you actually steal our data to prove the point?
No. When we reach an objective we prove access with a marker file or a redacted sample and stop. We never exfiltrate real sensitive or personal data, and everything is handled under NDA and a strict rules-of-engagement document.
Do your red team testing services cover physical and social engineering?
Yes, where you include them. Red team testing can combine phishing, external exploitation, and physical access such as tailgating or badge cloning, because a real attacker uses whatever works. You decide which vectors are in scope.
Does this help with DORA or NIS2?
Yes. Engagements can be structured as threat-led testing to support DORA and the TIBER-EU framework, and the reporting also speaks to NIS2 resilience expectations, ISO 27001 and SOC 2. Tell us your regulator and we align the scenario and deliverables.
What do we get afterwards?
An attack narrative for leadership, a technical report mapped to MITRE ATT&CK against your own telemetry, a live debrief with your defenders, an attestation letter and a follow-up test after you close the gaps. Many clients add a purple-team session to tune detections on the spot.

Related services

Who needs this

Organisations that have already done the fundamentals and now need to test people and process under a realistic attack: banks and financial entities facing DORA threat-led testing, mature security teams that want to prove their SOC and EDR work in anger, and boards that need honest evidence of how a determined adversary would fare against them.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Red Team Assessment"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.