// 02 · RED TEAMING

Red teaming

Red teaming is a simulation of a specific adversary that goes up against your entire defense: people, processes, and technology. The goal isn’t to list vulnerabilities but to reach an agreed objective and find out at which stage your defense catches us. An operation has two layers, cyber and physical, and they can be ordered separately or together.

// 01

What a red team operation looks like

We start by agreeing on the objective. Not “test us,” but “get into the manufacturing system,” “download the patient database,” or “make a payment above CZK 1 million.” With it come the rules of engagement: what is off-limits, who in management knows about the operation, and the phone number we call when something goes wrong.

Next comes open-source intelligence (OSINT). Names and roles from LinkedIn, the format of company email addresses, forgotten subdomains, technology readable from headers and certificates, credentials from public leaks. From that we build a scenario that is believable for your company specifically. Not a generic invoice from a supplier you’ve never worked with. Which categories of public sources get combed through is covered by a separate glossary entry.

The deliverable is a report that describes the path to the objective, evidence included, and a set of measures ordered by how many paths they close to an attacker. We don’t write recommendations as “implement zero trust” but as specific steps: disable NTLM where it’s no longer needed, separate administrative accounts into their own tier, tighten delegation in the domain.

// 02

The two layers of an operation and how they combine

The layers can be combined, but each measures something different. The cyber layer starts remotely, typically with a targeted message or a forgotten service on the perimeter, and measures how fast your monitoring notices us. The physical layer starts at your reception desk and measures who gets let in.

There are two reasons to start with the cyber part. The vectors attackers actually use to get in are remote, according to public data: Verizon DBIR 2026 puts breaches that start with the exploitation of a software vulnerability at 31%, and Mandiant M-Trends 2026 puts exploits at 32% of intrusions and lists this vector as the most common for the sixth year in a row. The second reason is practical: the result feeds straight into detection rules. The course of the operation and the shape of the attack timeline are described on the page for the cyber layer.

The physical part pays off where getting into the building has a direct impact on operations or on data: manufacturing, healthcare, data centers, offices shared with other tenants. How a physical test runs and what rules it follows is described on its own page.

Both layers can be ordered together as one operation, and there’s a practical reason: they hand off to each other. The physical layer hands over to the cyber layer the moment network access or an unlocked workstation is available, and that is exactly the access a cyber operation starts from. Ordered separately, the layers measure two halves of the path; ordered together, they measure the whole path from the door to the data, including the crossover between physical and cyber defense. The scenario then starts outside the building and ends at the data we reached from a network socket in a meeting room.

The physical layer runs inside the window of the cyber operation, not after it. The days on site fall within the period the operation is running anyway, so the two durations don’t stack. It does cost time, though: preparation, reconnaissance, and rules of engagement are separate for each layer, which is exactly why you need to say you want both at the start, not halfway through the operation.

// 03

When red teaming makes sense and when it doesn’t

The difference from a pentest fits in two sentences: a penetration test looks for as many vulnerabilities as possible within a defined scope. A red team goes after one objective and measures if your defense notices. We’ve written up a detailed comparison of duration, scope, deliverables, and cost in a separate article.

The dividing line doesn’t run along company size but along how far you’ve gotten with your defense. If you patch in bursts and your last test is more than two years old, red teaming is an expensive way to learn you have an outdated VPN concentrator. It pays off once you have central log collection, your own or an outsourced monitoring team, and you want to know the time between an attacker’s entry and the first alert.

In practice we combine the two. If you want a shorter operation, we offer an assume breach variant, where the operation starts from a foothold we’re handed inside the network; we cover it on the cyber layer page.

// 04

Types of tests

Scope, methodology, and deliverables depend on what is being tested. Each type has its own page with the details.

// 05

How we classify findings

Vulnerability severity classification
SeverityCVSS
Critical9.0 – 10.0
High7.0 – 8.9
Medium4.0 – 6.9
Low0.1 – 3.9

// 06

Frequently asked questions

Go by the maturity of your defense. A company without central log collection, alert monitoring, and an established patching routine gets more value from a penetration test. A red team would only confirm, at a higher price, what the company hasn’t fixed yet. Red teaming starts to make sense where a defense exists and you need to know how fast it reacts to an attacker who is trying not to be seen.

No, and it’s better if they don’t. Otherwise there’s nothing to measure. A group of two or three people knows about the operation: the managing director, the CISO, and possibly the head of IT. This group keeps a line to our operation lead and can stop the test at any time. Before launch we exchange phone numbers and agree on a code phrase to confirm the activity is ours if your team declares an incident.

Not if the rules of engagement are followed. We don’t encrypt data, we don’t delete it, and we don’t send your real customer database out. Instead we plant a verifiable artifact with our identifier and verify exfiltration on a test sample. Interventions in industrial systems, service restarts, and physical entries have their own approval and a window agreed in advance.

Three things: a written authorization to test from an officer authorized to sign for the company, an agreed objective with rules of engagement, and one person who can be reached outside business hours. What we don’t want from you is technical materials: no credentials, network diagrams, or system inventories. The moment we get those, it stops being a simulation of an attacker and becomes a test with a head start.

// INCLUDED WITH EVERY ENGAGEMENT

Free one-time data leak check

With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.

How continuous leak monitoring works

// NEXT STEP

We’ll go over the scope together.

Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.