PEN / PEN-08
Objective-based red team exercise
A coordinated adversary simulation to exercise prevention, detection and response against a defined business objective.

WHEN IT HELPS
A focused response
to a defined need.
CISO with an established security baseline and response capability; a need to exercise end-to-end defence.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Agreed objective and scenario
- rules of engagement
- technical and human interactions only where explicitly authorised
Deliverables
- Exercise timeline
- prevention and detection results
- joint debrief and improvement plan
Acceptance evidence
Objectives, detected events, missed events and safety stops are documented with defenders.
DELIVERY
How the work is structured.
Approach
Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.
Prerequisites & responsibilities
Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.
Scope factors
Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.
Questions to clarify
Which business objective? Who runs the control cell? What human, physical and technical boundaries apply?
IMPORTANT BOUNDARIES
This is not an exhaustive vulnerability inventory; scope, secrecy and techniques require written approval.
No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A group sets a simulated objective of reaching a decoy strategic file. Project: a supervised, progressive scenario. Target outcome: measure defence gaps and improve escalation without extracting real confidential documents.
Scenario 02
A mature company’s SOC detects the first stage promptly. Project: stop or adapt under agreed rules. Target outcome: recognise the effective control and examine authorised follow-up, rather than forcing an artificial offensive success.
Technology and reference context
Scenarios informed by MITRE ATT&CK; approved control cell and resources.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
