Testing & Assurance / Red Teaming
Your controls passed the audit.
Would they stop an attacker?
Penetration testing tells you where your vulnerabilities are. A red team exercise tells you what happens when someone uses them: how far they get, how long before you notice, and whether your response holds.
Red teaming vs penetration testing
Different questions. Different answers.
Penetration testing and red teaming are complementary, not interchangeable. The difference decides which one fits your maturity and what you need to know.
How the work is done
People find the path. The platform measures the controls.
A red team exercise is run by our testers, by hand. They choose the route an attacker would take, adapt when a control stops them, and decide what matters to your objectives. Our testers hold OSCP, OSCE, OSWE and OSWP from OffSec, and CRT and CPSA from CREST.
Inside the engagement we use the Picus platform to run known attack techniques, mapped to MITRE ATT&CK, against your prevention and detection controls. That shows which techniques your tools block, which they log without alerting and which they miss, so the testers spend their time on the paths that matter.
Picus is a Cliffside technology partner. We say so here because it is one of our eight commitments: commercial relationships are disclosed where relevant. The platform supports the red team; it does not replace it.
Our eight commitments →How it works
A realistic, structured attack simulation.
We define attack objectives (e.g. access sensitive data, disrupt operations, achieve persistent access) and establish rules of engagement, including any systems that are strictly off-limits.
Using the same techniques a real attacker would employ, phishing, public exposure, credential attacks, to gain an initial foothold in the environment.
Establishing persistent access, moving laterally through the environment, escalating privileges, observing and documenting what your defences detect (and what they miss).
Attempting to achieve the defined objectives, data exfiltration, ransomware simulation, or other scenarios relevant to your threat model.
Full attack narrative, timeline, detection gaps, response assessment, and prioritised recommendations, for both the security team and the board.
Before you commission one
Red teaming is not the first test.
Red teaming is best suited to organisations with an established security programme. If you have not yet tested your external perimeter and key applications, a penetration test will tell you more for less, and we will say so.
For regulated organisations, the question often comes from the rules. APRA's CPG 234 identifies red team testing as an expected approach to testing controls under CPS 234, and responsible entities under the SOCI Act must maintain a critical infrastructure risk management programme and report on it to their board each year.
Common questions.
What is the difference between red teaming and penetration testing?
Is red teaming legal, and is it safe to run against production?
Do you use automated tools?
What is purple teaming?
What do we receive at the end?
Know if your defences
actually work.
Red teaming is best suited to organisations with an established security programme. Tell us what you are trying to prove, and we will help you decide whether this is the right engagement for your current maturity.
