Red Teaming

Your partner for comprehensive attack simulations to strengthen your cyber resilience.

Red Teaming

Red Teaming

Would you like to put the effectiveness of your defense systems to the test?


Do you need a comprehensive evaluation of your security mechanisms under realistic circumstances?


Our expertise is at your disposal.


CONTACT US

Holistic Attack Simulations

Cyber attacks pose a serious threat to companies, regardless of industry sector and company size. The consequences of a successful attack vary, ranging from the leakage of sensitive corporate and customer data to the disruption of critical business processes, and even to a complete stop of the IT and OT infrastructure.

In order to be well prepared for such emergencies and to sustainably enhance your company’s resilience, we offer cyber attack simulations against your company as part of our red teaming campaigns. During this campaign, established security mechanisms are tested to identify potential areas for improvement. In addition to finding security vulnerabilities in individual systems, we focus particularly on testing the technical and organizational cyber defense measures of your company.

Our Offer to You

Every company’s IT environment and security measures are unique. Therefore, attackers need to adapt accordingly, tailoring their cyber attacks to fit each specific organization. The following diagram provides an overview of various kinds of attacks – both from outside and within the company.

We offer various scenarios that reflect these attacker tactics. Each scenario sets the starting point for the campaign and outlines the methods the simulated attacker will use to infiltrate your corporate network:

Assumed Breach

This scenario assumes that an attacker has already gained access to internal IT systems or that an internal perpetrator is misusing their existing access. To simulate this scenario, you provide us with an internal point of access. Based on this, our red team will assess how such an attacker could expand their existing access rights and compromise further systems.

Examples:

  • We simulate that an employee's computer in the HR department was compromised through a phishing mail.
  • The computer of an employee in the finance department was compromised with a malicious USB stick, subsequently granting the attacker remote access.

Technical Breach

With this approach, we take on the role of an attacker conducting cyber attacks over the internet. Using various information gathering techniques, we identify vulnerabilities in the external perimeter and attempt to exploit them to infiltrate the corporate network.

Examples:

  • An outdated test system with known vulnerabilities is exposed on the internet. The attacker attempts to compromise this system.
  • Due to a misconfiguration, internal credentials are publicly available on the internet. The attacker leverages these credentials to gain access.

Physical Breach

We act like an attacker who tries to bypass the physical perimeter protection through targeted deception and install a prepared device on the company’s premises. The goal is to overcome on-site security measures and covertly gain access to the company network (e.g., by planting a mini-PC).

Examples:

  • Your company has multiple branches connected to the central company network. The attacker attempts to infiltrate the local infrastructure of a branch office and use it to gain access to the corporate network.
  • One of your company’s locations has various areas, some of which are public – ranging from the lobby and cafeteria to the offices and production facilities. An attacker tries to exploit access routes for guests, employees and suppliers and gains access to the production facilities.

Social Engineering

Social engineering focuses on exploiting human factors, aiming to entice employees in their respective roles to disclose sensitive information or to carry out certain actions. Starting from a successful compromise, the objective is to infiltrate the company’s infrastructure.

In addition to email phishing, alternative communication channels such as messaging services or social media are possible.

Example:

  • Relevant targets are identified through LinkedIn. Combined with a login page exposed on the internet, a tailored spear-phishing campaign is designed to obtain login credentials.
  • An attacker poses as someone who has a trusted relationship with the victim and invents a scenario to persuade the victim to hand over sensitive information.

Red Teaming Approach 

The objective of the red teaming campaign is to simulate the impact a cyber attack would have on the customer’s company under real-world conditions. To minimize potential effects on business processes and IT systems, close coordination between all parties involved is of high importance.

Involved Parties

The following parties from both the client and the contractor are involved in the execution of the campaign:

  • Blue Team – The blue team acts as the defender, protecting the infrastructure against attacks. This typically involves the target company’s IT department. To ensure the simulation is as realistic as possible, the blue team is generally not informed of the campaign.
  • Red Team – The experts of BDO Cyber Security GmbH operate according to the rules of engagement and represent the attackers as the red team.
  • White Team – The white team oversees the campaign and maintains regular communication with the red team. It consists of one or two individuals who are knowledgeable about the company's infrastructure. The primary responsibility of the white team is to ensure that any potential disruptions are resolved promptly and with minimal delay.

Red Teaming Campaign Process

The detailed vulnerabilities and pathways through which an attacker can infiltrate the company or advance further within the network are highly dependent on the specific organization. The overall process of the red teaming campaign can be divided into the following stages:


The individual stages are described in detail below:

Reconnaissance

During the reconnaissance phase, information about the target company is gathered. This information is obtained from publicly available sources through Open-Source Intelligence (OSINT) techniques. 

The aim is to obtain an overview of the situation and identify possible attack paths, which are essential for subsequent phases of the red teaming campaign.

Initial Access

Initial network access is obtained through the entry point agreed in advance. The following entry points may be used:

Persistence in the Corporate Network and Expanding Access (Post-Exploitation)

The post-exploitation phase is the core phase of the campaign and includes several recurring steps:

  • Implementing measures to ensure continued access to the compromised system (Persistence)
  • Collecting data about the system (Situational Awareness)
  • Analyzing the network environment, additional systems, users, or applications from the compromised system (Internal Reconnaissance) 
  • Elevating permissions by exploiting misconfigurations or vulnerabilities (Privilege Escalation)
  • Expanding access to other systems, users, or applications within the network (Lateral Movement)

Demonstrating the Achievement of the Campaign’s Objectives (Objectives)

The achievement of the campaign’s objectives is demonstrated to the White Team through jointly defined actions, such as:

  • Creating a user with elevated privileges
  • Gaining access to key servers
  • Exfiltrating sensitive company information

Methodology and Frameworks

There are many established methodologies and frameworks that guide a red teaming campaign, ensuring that the results are consistent and compliant with regulations such as the Digital Operational Resilience Act (DORA) or NIS-2.

  • The MITRE ATT&CK Framework (Adversarial Tactics, Techniques & Common Knowledge) outlines tactics, techniques and procedures based on real-world observations of cyber attacks documented by security experts.
  • Threat-Led Penetration Testing  is an evolution of the Threat Intelligence-based Ethical Red Teaming (TIBER) framework, which is used for Red Teaming campaigns in the financial and banking sectors and is applied in conjunction with the DORA regulation.
  • The Lockheed Martin Cyber Kill Chain details an attacker’s approach through a series of progressive stages, describing the consequences of actions taken during a cyber attack.
 

Contact us!

Dr. Antje Winkler

Dr. Antje Winkler

Partner | Offensive Security
View bio

FAQ Red Teaming at BDO Cyber Security GmbH

Red teaming is particularly suitable for organisations that have already established their basic security measures and now wish to know whether these can withstand a realistic, targeted attack. It is particularly worthwhile in the following situations:

  • A mature security organisation is in place: firewalls, monitoring, a Security Operations Centre (SOC) and regular penetration tests are already established, and the aim is now to check whether these measures, working together, can withstand a real-world attack.
  • Critical infrastructure or sensitive data: Organisations with high security requirements, such as those in the financial sector, benefit particularly from testing their resilience against complex, realistic attacks.
  • Regulatory requirements: Where legal requirements, such as the Digital Operational Resilience Act (DORA), mandate or recommend red teaming.
  • Following major changes: For example, after the introduction of new systems or processes (particularly in the field of IT security), following mergers or acquisitions, or when the threat landscape for the company or the sector has changed significantly.

For organisations whose security processes are still being established, however, a traditional penetration test or a security consultancy is usually the more sensible first step.

In various sectors, particularly the financial sector, red teaming is increasingly recommended or required by regulators:

  • Digital Operational Resilience Act (DORA): This EU regulation requires significant financial firms to carry out regular Threat-Led Penetration Tests (TLPT). TLPT is a form of red teaming in which real-world threat scenarios are simulated to test the resilience of critical systems. The Threat Intelligence-Based Ethical Red Teaming Framework (TIBER) is used as the methodological basis for this.
  • NIS2 Directive: Although red teaming is not explicitly mandated, NIS2 requires operators of critical infrastructure to demonstrate effective risk management and security measures. Red teaming assessments are a suitable means of providing such evidence.

Whilst organisations outside regulated sectors are generally not directly obliged to carry out red teaming, they also benefit from the insights gained – particularly if they form part of critical supply chains or must themselves meet high security requirements.

A red-teaming assessment typically comprises the following phases:

  1. Preparation: In collaboration with the organisation, objectives (e.g. access to sensitive data) and rules of engagement are defined, and technical requirements and communication channels are discussed.
  2. Reconnaissance: Information about the organisation is gathered, for example from freely available sources using open-source intelligence (OSINT). The aim is to obtain a picture of the situation and identify potential attack vectors.
  3. Initial Access: Depending on the agreed scenario (e.g. Assumed Breach or Technical Breach), the Red Team first gains access to the organisation.
  4. Persistence within the organisation and expansion of access (Post-Exploitation): Having gained initial access, the Red Team then moves step by step towards the defined objective – for example, by escalating privileges, moving laterally within the network and deliberately bypassing security mechanisms.
  5. Achieving the campaign objectives: Once the pre-defined objectives have been achieved, the evidence agreed with the White Team is collected.
  6. Documentation (Reporting): Subsequently, all findings are documented: achieved (sub-)objectives, attack vectors used, vulnerabilities uncovered, and an assessment of detection and response capabilities. The results are discussed with the organisation in a joint debriefing session. 

Following completion of the red teaming assessment, a joint purple teaming exercise may be carried out at the company’s request, in which the attacker and defender teams jointly analyse detection gaps and identify measures for improvement.

The aim of red teaming is to target a specific, business-critical objective and, under realistic conditions, to test whether this attack is detected and whether internal processes respond appropriately. Typical objectives include:

  • Access to sensitive data, such as customer, financial or personnel data
  • Compromising critical systems, e.g. production-related infrastructure or domain administration
  • Reviewing the processes and workflows of the Security Operations Centre (SOC) to test whether alerting, escalation and collaboration function effectively in an emergency
  • Assessing detection and response measures – that is, whether an attack is detected at all and how quickly and effectively it is responded to
  • Simulation of realistic attacker groups to replicate the behaviour and methods of specific attackers as authentically as possible (e.g. based on the MITRE ATT&CK Framework)

In a Red Team assessment, different teams take on clearly defined roles:

  • Red Team: The Red Team is the attacker team. It simulates a realistic attack on the organisation and attempts to achieve a predefined objective without being detected.
  • Blue Team: The Blue Team is the defence team, usually the IT security department or the Security Operations Centre (SOC). Unlike in a penetration test, it is not informed about the Red Team assessment and must independently detect and respond to the attack whilst operations are ongoing.
  • White Team: A small, select group of internal personnel who are aware of the Red Teaming exercise. The White Team works with the Red Team to define the parameters of the exercise and can intervene if necessary without the Blue Team being aware of it.

Purple Teaming refers to close, collaborative work between an attacker team (Red Team) and a defender team (Blue Team), for example following or as an alternative to a Red Teaming assessment. Unlike in traditional Red Teaming, where the Blue Team is supposed to remain as unaware as possible of the ongoing attack, both teams here work together in a deliberately transparent manner.

The aim is to jointly analyse whether and why certain attack techniques go undetected. This gives the Blue Team the opportunity to learn directly from the tactics employed by the Red Team, to tailor detection rules specifically and to close detection gaps immediately. Purple Teaming is therefore primarily a method for deriving maximum, shared learning benefits for the defence from a Red Teaming assessment.

‘Assumed Breach’ and ‘Technical Breach’ are two fundamental attack scenarios in red teaming, which differ in their starting point:

  • Assumed Breach: At the outset, the Red Team is granted an initial point of access, as if an attacker had already penetrated the network. This scenario simulates an attacker gaining access to a client on the network (e.g. via phishing) or an employee misusing their existing access. The focus is on bypassing security mechanisms on the affected client and spreading within the corporate network (lateral movement). 
  • Technical Breach: The Red Team starts with no access whatsoever and must first gain access themselves, for example via exposed systems. This scenario models an external attacker attempting to find an initial point of entry into the organisation.

There is no one-size-fits-all answer, as the frequency depends on the risk profile, industry and regulatory requirements. Regulated financial firms subject to DORA are generally required to carry out TLPT assessments every three years. 

Regardless of legal requirements, it is advisable to carry out red teaming regularly – for example, annually or following significant changes to the company’s infrastructure, security teams or security solutions – in order to identify new vulnerabilities at an early stage.