Skip to main content

Testing & Assurance / Red Teaming

Your controls passed the audit.
Would they stop an attacker?

Penetration testing tells you where your vulnerabilities are. A red team exercise tells you what happens when someone uses them: how far they get, how long before you notice, and whether your response holds.

Different questions. Different answers.

Penetration testing and red teaming are complementary, not interchangeable. The difference decides which one fits your maturity and what you need to know.

Penetration testing
Time-bounded, defined scope
Identifies and validates vulnerabilities
Blue team typically aware
Deliverable: vulnerability report
Best for: compliance, specific risk concerns
Good starting point for most organisations
Red teaming
Extended duration, broader objectives
Tests detection and response capabilities
Blue team unaware (or purple team)
Deliverable: full attack narrative and response assessment
Best for: mature security programmes, regulated organisations
Right when you need to know if defences work

People find the path. The platform measures the controls.

A red team exercise is run by our testers, by hand. They choose the route an attacker would take, adapt when a control stops them, and decide what matters to your objectives. Our testers hold OSCP, OSCE, OSWE and OSWP from OffSec, and CRT and CPSA from CREST.

Inside the engagement we use the Picus platform to run known attack techniques, mapped to MITRE ATT&CK, against your prevention and detection controls. That shows which techniques your tools block, which they log without alerting and which they miss, so the testers spend their time on the paths that matter.

Picus is a Cliffside technology partner. We say so here because it is one of our eight commitments: commercial relationships are disclosed where relevant. The platform supports the red team; it does not replace it.

Our eight commitments →

A realistic, structured attack simulation.

01
Objective setting & scoping

We define attack objectives (e.g. access sensitive data, disrupt operations, achieve persistent access) and establish rules of engagement, including any systems that are strictly off-limits.

02
Initial access & reconnaissance

Using the same techniques a real attacker would employ, phishing, public exposure, credential attacks, to gain an initial foothold in the environment.

03
Persistence & lateral movement

Establishing persistent access, moving laterally through the environment, escalating privileges, observing and documenting what your defences detect (and what they miss).

04
Objective achievement

Attempting to achieve the defined objectives, data exfiltration, ransomware simulation, or other scenarios relevant to your threat model.

05
Debrief & reporting

Full attack narrative, timeline, detection gaps, response assessment, and prioritised recommendations, for both the security team and the board.

Red teaming is not the first test.

Red teaming is best suited to organisations with an established security programme. If you have not yet tested your external perimeter and key applications, a penetration test will tell you more for less, and we will say so.

For regulated organisations, the question often comes from the rules. APRA's CPG 234 identifies red team testing as an expected approach to testing controls under CPS 234, and responsible entities under the SOCI Act must maintain a critical infrastructure risk management programme and report on it to their board each year.

Common questions.

What is the difference between red teaming and penetration testing?
A penetration test finds and validates as many vulnerabilities as it can within a defined scope, usually with your team aware. A red team exercise pursues agreed objectives, such as reaching sensitive data, over a longer period and usually without your defenders being told, to test whether you detect and respond.
Is red teaming legal, and is it safe to run against production?
It runs under written rules of engagement, agreed before any activity starts, that set the objectives, the limits and the systems that are strictly off-limits.
Do you use automated tools?
Yes, inside the engagement. We use the Picus platform to test your controls against known attack techniques, mapped to MITRE ATT&CK. The attack path itself is run by our testers.
What is purple teaming?
A purple team exercise runs the same attacks with your defenders informed and working alongside the testers, so detection gaps are closed during the exercise rather than read about afterwards.
What do we receive at the end?
A full attack narrative, timeline, detection gaps, response assessment, and prioritised recommendations, written for both the security team and the board.

Know if your defences
actually work.

Red teaming is best suited to organisations with an established security programme. Tell us what you are trying to prove, and we will help you decide whether this is the right engagement for your current maturity.