// 02 · RED TEAMING
Red teaming
Red teaming is a simulation of a specific adversary that goes up against your entire defense: people, processes, and technology. The goal isn’t to list vulnerabilities but to reach an agreed objective and find out at which stage your defense catches us. An operation has two layers, cyber and physical, and they can be ordered separately or together.
// 01
What a red team operation looks like
We start by agreeing on the objective. Not “test us,” but “get into the manufacturing system,” “download the patient database,” or “make a payment above CZK 1 million.” With it come the rules of engagement: what is off-limits, who in management knows about the operation, and the phone number we call when something goes wrong.
Next comes open-source intelligence (OSINT). Names and roles from LinkedIn, the format of company email addresses, forgotten subdomains, technology readable from headers and certificates, credentials from public leaks. From that we build a scenario that is believable for your company specifically. Not a generic invoice from a supplier you’ve never worked with. Which categories of public sources get combed through is covered by a separate glossary entry.
The deliverable is a report that describes the path to the objective, evidence included, and a set of measures ordered by how many paths they close to an attacker. We don’t write recommendations as “implement zero trust” but as specific steps: disable NTLM where it’s no longer needed, separate administrative accounts into their own tier, tighten delegation in the domain.
// 02
The two layers of an operation and how they combine
The layers can be combined, but each measures something different. The cyber layer starts remotely, typically with a targeted message or a forgotten service on the perimeter, and measures how fast your monitoring notices us. The physical layer starts at your reception desk and measures who gets let in.
There are two reasons to start with the cyber part. The vectors attackers actually use to get in are remote, according to public data: Verizon DBIR 2026 puts breaches that start with the exploitation of a software vulnerability at 31%, and Mandiant M-Trends 2026 puts exploits at 32% of intrusions and lists this vector as the most common for the sixth year in a row. The second reason is practical: the result feeds straight into detection rules. The course of the operation and the shape of the attack timeline are described on the page for the cyber layer.
The physical part pays off where getting into the building has a direct impact on operations or on data: manufacturing, healthcare, data centers, offices shared with other tenants. How a physical test runs and what rules it follows is described on its own page.
Both layers can be ordered together as one operation, and there’s a practical reason: they hand off to each other. The physical layer hands over to the cyber layer the moment network access or an unlocked workstation is available, and that is exactly the access a cyber operation starts from. Ordered separately, the layers measure two halves of the path; ordered together, they measure the whole path from the door to the data, including the crossover between physical and cyber defense. The scenario then starts outside the building and ends at the data we reached from a network socket in a meeting room.
The physical layer runs inside the window of the cyber operation, not after it. The days on site fall within the period the operation is running anyway, so the two durations don’t stack. It does cost time, though: preparation, reconnaissance, and rules of engagement are separate for each layer, which is exactly why you need to say you want both at the start, not halfway through the operation.
// 03
When red teaming makes sense and when it doesn’t
The difference from a pentest fits in two sentences: a penetration test looks for as many vulnerabilities as possible within a defined scope. A red team goes after one objective and measures if your defense notices. We’ve written up a detailed comparison of duration, scope, deliverables, and cost in a separate article.
The dividing line doesn’t run along company size but along how far you’ve gotten with your defense. If you patch in bursts and your last test is more than two years old, red teaming is an expensive way to learn you have an outdated VPN concentrator. It pays off once you have central log collection, your own or an outsourced monitoring team, and you want to know the time between an attacker’s entry and the first alert.
In practice we combine the two. If you want a shorter operation, we offer an assume breach variant, where the operation starts from a foothold we’re handed inside the network; we cover it on the cyber layer page.
// 04
Types of tests
Scope, methodology, and deliverables depend on what is being tested. Each type has its own page with the details.
// 05
How we classify findings
| Severity | CVSS | Handling |
|---|---|---|
| Critical | 9.0 – 10.0 | Immediate escalation |
| High | 7.0 – 8.9 | Summary within 24 hours |
| Medium | 4.0 – 6.9 | Included in the final report |
| Low | 0.1 – 3.9 | Remediation recommendation |
// 06
Frequently asked questions
// INCLUDED WITH EVERY ENGAGEMENT
Free one-time data leak check
With every service we add a one-time leak check: we tell you whether your company email addresses and passwords sit in public leaks or on the dark web as of the day of the check. It is a snapshot of one day. If you want to know about a leak whenever one appears, you move to continuous monitoring.
How continuous leak monitoring works// NEXT STEP
We’ll go over the scope together.
Tell us what you want tested. We’ll get back to you and schedule a call to pin down scope, timing, and price.