Skip to content

Red Teaming

Test your entire defense – not just individual systems


A Red Team engagement goes far beyond a classic penetration test. We simulate a realistic, targeted attack on your organization – across all layers: technology, people, and processes. This reveals how well your defense truly performs under real-world conditions.

What is Red Teaming?


Red Teaming is a comprehensive security assessment where a specialized team (the Red Team) attempts to achieve defined objectives – just like a real attacker. Unlike a penetration test that focuses on specific systems, Red Teaming tests your organization's entire defense chain.

Penetration Test vs. Red Teaming

Criteria Penetration Test Red Teaming
Scope Defined systems / applications Entire organization
Objective Find vulnerabilities Achieve defined objectives (e.g., access CEO mailbox)
Duration Days to weeks Weeks to months
Stealth Not required Covert approach
Awareness IT team informed Only management aware

Our Methodology


01
OSINT & Reconnaissance

Collection of publicly available information about your organization.

02
Initial Access

Initial access via phishing, exploits, or physical methods.

03
Lateral Movement

Spreading through the network and escalating privileges.

04
Objective Achievement

Achieving agreed objectives and demonstrating impact.

05
Debrief & Report

Detailed report with attack paths and recommendations.

What We Test


People

Social engineering, phishing, vishing – how do your employees react to targeted attacks?

Technology

Networks, endpoints, cloud infrastructure – do your technical controls withstand a targeted attack?

Processes

Incident response, escalation processes, monitoring – does your team detect the attack and respond correctly?

Physical Security

Access controls, server rooms, badge cloning – can we physically infiltrate your buildings?

From Our Engagements


Anonymized engagement example

A Swiss financial services firm. 3 weeks. Lateral movement to the ERP system — undetected.

Joint debrief with the SOC team. Result: eight new detection rules implemented, alerting thresholds corrected, endpoint configuration hardened. Follow-up test: attack detected within four hours.

3 weeks undetected ERP access achieved 4 of 12 techniques detected
Industry: Financial services
Scenario: Targeted attack
Duration: 3 weeks

A Swiss financial services firm with an existing SOC wants to test whether a targeted attack can be detected and stopped. Objective: access the ERP system. The SOC team is not informed in advance.

Key Findings
  • Critical Initial access via a targeted spear-phishing email to accounting. Payload is not detected by endpoint protection.
  • Critical Lateral movement went undetected for 3 weeks. ERP system access achieved. SOC only detects the exfiltration simulation.
  • High SIEM rules cover only 4 of 12 ATT&CK techniques used

Framework-Based Reporting


Our Red Team reports are aligned with the MITRE ATT&CK framework. Each attack step is mapped to the corresponding tactics and techniques. This gives you not just a vulnerability report, but a structured analysis that helps your Blue Team improve detection and defense measures in a targeted way.

Who Is This For?


Red Teaming is designed for organizations that have already implemented basic security measures – such as regular penetration tests, a SOC, or an incident response team – and now want to take the next step. If you want to know how your entire defense performs under a realistic attack scenario, a Red Team engagement is the right approach.

Your Deliverables


Executive Summary

Management-ready summary of the attack simulation with overall risk assessment and strategic recommendations.

MITRE ATT&CK Mapping

Complete mapping of all attack techniques to the MITRE ATT&CK Framework with detection and defense recommendations.

Technical Report

Detailed documentation of each attack path with evidence, screenshots, and reproduction steps.

Remediation Roadmap

Prioritized remediation roadmap to close identified gaps, ordered by risk and effort.

from CHF 15,000

Typical duration: 2–4 weeks

Inquire Now

Frequently Asked Questions


A penetration test specifically checks technical systems for vulnerabilities within a defined scope. Red teaming goes further: it simulates a realistic, goal-oriented attack on the entire organization – including social engineering, physical access attempts, and bypassing security measures. The goal is to test your defense's detection and response capabilities.

Typically, only a small circle is informed – usually the executive management and the CISO (the so-called 'White Team'). The IT team and SOC are deliberately not informed to get a realistic picture of detection capabilities. We define clear escalation paths in advance in case the engagement is discovered.

A typical red team engagement takes 4 to 8 weeks. This includes an extended reconnaissance phase (OSINT), development of tailored attack scenarios, the active attack phase, and reporting and debriefing. The duration depends on the size of the organization and the agreed-upon objectives.

Yes, social engineering is an essential component of many red team engagements. This can include phishing campaigns, vishing (phone-based social engineering), physical access attempts, or placing manipulated USB devices. The type and scope are jointly defined and contractually agreed upon in advance.
Request a Quote