
The question is not which gaps you have. It is whether
somebody gets through.
A penetration test delivers a list. Red teaming delivers an answer: can an attacker reach their objective — and would you notice? Scenario-based, goal-driven, with your detection measured. Entry point: assumed-breach assessment from €9,900.
The difference is in the question
A penetration test is coverage-driven: it works through a system systematically and lists what is vulnerable. That is valuable — and it still does not answer the question leadership asks. Red teaming is scenario-driven: we define an objective that would genuinely hurt — access to design data, takeover of the administrator account, exfiltration of the customer base — and work towards it like a real attacker. Across system boundaries, with people and processes as part of the attack surface. And we measure what your defence notices along the way. The result is not a catalogue but a statement.
Our red team services
From a compact entry point to a multi-week campaign
Red teaming by the numbers
Realistic parameters instead of marketing promises
How a campaign runs
Controlled, documented, stoppable at any time
Objective definition
What damage would genuinely hurt? With a small, informed circle we define a concrete objective — not 'test security' but 'access to system X'.
Threat scenario
Who would attack you and with what means? A competitor, a ransomware group, a disgruntled insider — the scenario drives the methodology.
Rules and authorisation
Written engagement, clear boundaries, a defined stop condition, named contacts on both sides. No campaign starts without this.
Reconnaissance
Publicly available information, exposed systems, employee profiles, leaked credentials. The part that costs attackers the least effort — and that defenders underestimate the most.
Execution
Access, persistence, lateral movement, privilege escalation, objective. Every action logged with a timestamp — the basis for the later reconciliation.
Detection reconciliation
Our log against your logs and alerts: which steps were detected, which were not, and where detection would have been feasible at reasonable effort.
Debrief and measures
Joint review with your team, a walk-through of the attack path, prioritised measures. On request directly as a purple team session.
Honest parameters
Red teaming is often sold before the capacity and the maturity are there. We raise both upfront.
What we deliver
- Assumed-breach assessments as a plannable entry point
- Full campaigns — limited to a few slots per year
- Targeted social engineering and phishing by agreement
- Measurement and assessment of your detection capability
- Purple team sessions together with your team
- Complete documentation of every action performed
What we do not deliver
- TLPT under TIBER-DE or DORA — that requires accredited providers
- Attacks without written authorisation and defined boundaries
- Actions that deliberately disrupt production operations
- Short-notice campaigns 'next week' — lead time is part of the quality
- Physical intrusion testing without prior legal alignment
- Permanent attack simulation as a subscription
If your environment has never seen a penetration test, red teaming is the wrong first step — we would expensively demonstrate what a test would have shown for a third of the price. We will say so in the intro call rather than writing the larger order.
What you get out of it
Red teaming is expensive. These four things are what you buy.
An answer, not a list
You end up with a statement that is understandable without an IT background: the objective was reached — or it was not, and this is where it failed.
Measured detection
You learn not only whether you are attackable but whether your defence works. In practice the more valuable half: most organisations detect less than they assume.
Training on a real case
Your team experiences a real attack sequence in a controlled setting. That sticks better than any training slide — and exposes process gaps no audit finds.
Arguments for the budget
A clearly documented attack path is the most effective way to get security investment approved at board level. Considerably more effective than a risk matrix.
Red teaming pricing
Fixed packages to start, individual pricing for campaigns
Assumed-breach assessment
The plannable entry point
- Start from an assumed foothold
- Defined objective instead of open-ended search
- Lateral movement and privilege escalation
- Detection reconciliation against your logs
- Debrief with your team
- Report for engineering and leadership
Purple team session
Attack and defence together
- Controlled demonstration of attack techniques
- Live tuning of your detection
- Prioritised detection gaps
- Knowledge transfer to your team
- Also available as a follow-up to an assessment
Full campaign
Multi-week, scenario-based
- Reconnaissance and threat analysis
- Dedicated attack infrastructure
- Several attack paths in parallel
- Social engineering optional
- Full detection reconciliation
- Only a few slots available per year
Frequently asked questions on red teaming
What customers want to know before a first campaign
It makes sense once the basics hold: your key applications have been tested, known vulnerabilities are remediated, logging exists and somebody watches it. Then red teaming answers the next question — does this hold against a targeted attack? If nobody has ever examined your main application, start with a penetration test instead. It is cheaper and the insight per euro is considerably higher.
Let's talk about your realistic attack scenario
In 30 minutes we clarify what is genuinely worth protecting in your company, who would attack it — and whether red teaming is the right next step or still too early.