Red Team & Social Engineering
Objective-based adversary emulation including phishing and physical scenarios, measured against your defences.
A red team engagement asks a harder question than a penetration test: can a determined attacker reach a specific objective, such as your finance system or customer database, without being caught? We emulate realistic adversaries across technical, human and physical routes, and we measure how your detection and response perform along the way.
The value is in the debrief. You learn which controls worked, which were bypassed and where the detection gaps sit, with evidence rather than opinion.
- Engagements are built around your real risks, not a generic playbook.
- We work with your defenders afterwards to turn gaps into detection rules.
- Safety is engineered in, with deconfliction, kill switches and evidence handling agreed up front.
- A bank, airline or critical infrastructure operator with a mature security function that wants it tested against a realistic adversary.
- A group whose regulator expects threat-led testing.
- A company with a security operations centre that has never been measured against a live intrusion.
- Penetration tests keep coming back clean and the board wants to know whether that means anything.
- Detection tooling was bought and its coverage has never been proven.
- A peer in your sector was breached through a route you have not considered.
- Physical access to sites and offices has never been tested.
What is included.
- 01
Objective definition
Crown jewels, scenarios and rules of engagement agreed with a small trusted group.
- 02
Reconnaissance
Open-source intelligence on the organisation, people and technology.
- 03
Attack execution
Phishing, credential attacks, exploitation and lateral movement toward the objective.
- 04
Physical and social scenarios
Site access attempts, pretext calls and device drops where in scope.
- 05
Detection assessment
Timeline of what your defenders saw, when and how they responded.
- 06
Debrief
Technical narrative for the security team and an executive summary for leadership.
Four steps, no surprises.
- 01
Plan
Objectives, scenarios, scope and safety controls agreed.
- 02
Recon
Intelligence gathering across people, technology and premises.
- 03
Execute
Attack chain carried out toward the objective with continuous logging.
- 04
Debrief
Narrative, detection timeline and hardening recommendations.
From first meeting to steady state.
- 01Weeks 1 to 2
Plan
Objectives, scenarios, scope, safety controls and deconfliction agreed with a small trusted group.
- 02Weeks 3 to 4
Reconnaissance
Open-source intelligence on the organisation, people, technology and premises.
- 03Weeks 5 to 7
Execute
Attack chain carried out toward the objective with continuous logging and kill switches in place.
- 04Week 8
Debrief
Attack narrative, detection timeline, executive debrief and a purple team session with your defenders.
- Time from initial access to detection and from detection to response.
- Objectives reached against objectives stopped.
- Detection gaps converted into rules after the purple team session.
- Controls that held against controls bypassed, across technical, human and physical routes.
- Red team lead
- Offensive security operators
- Social engineering specialist
- Physical security specialist
- Engagement director
- Attack narrative with timeline.
- Detection gap analysis.
- Executive debrief.
- Technical remediation recommendations.
- Purple team session with your defenders.
Red team engagements are fixed scope and typically run four to eight weeks including planning and debrief. Standalone phishing and social engineering campaigns are shorter and scoped separately. We recommend a penetration testing baseline before a first red team exercise.
Security Awareness Training
Role-based training and phishing simulations that reduce human risk and prove it.
CybersecurityManaged Detection & Response (MDR/XDR)
Continuous monitoring, alert triage and response across endpoints, identity and cloud.
CybersecurityPenetration Testing (Web, API, Mobile)
Manual, adversary-style testing of applications and their business logic, with a retest included.
Red Team & Social Engineering, in plain terms.
If you have detection and response in place and want to know whether it works, yes. If you have never had a penetration test, start there.
A small group who can stop it if needed. Everyone else responds as they would to a real attack, which is the point.
Yes, where in scope and legal, with authorisation letters carried by the team.
You get a detailed account of how, what was missed and what to change. Success for us is a clear picture, not an embarrassment.