Red Teams
The main event! At Bulletproof we have designed a robust, phased-based delivery approach. We always want to deliver the best results we can within the budgets and timelines of our clients wherever possible. We get it, not everyone has the budget for a full low-and-slow 3-month engagement focusing on novel attacks and complete realism. We will, however, do everything we can to manage expectations and deliver what we feel is best for you, even if that is not a Red Team. We can deliver what we call "Guided Red Teams" these follow the full end to end process of a Red Team test starting externally but have a larger amount of clear and direct fall back or dechaining checkpoints. This ensures that a Red Team engagement continues to move through the phases and delivers results across the attack chain on a more compressed timeline. A few examples of these would be:
- Falling back to assumed breach after a pre-defined amount of time.
- If the attacking team is unable to maintain persistent access to the network by a pre-defined time the engagement will move to a collaborative purple team styled final delivery in order to assess the ability of the defences to prevent and detect the attack.
These of course would usually also be a part of larger less compressed engagements but using a stricter timeline with a smaller set of very clear objectives can reduce costs. Again, it's all about managing complexity, maturity, and objectives and to a degree realism to correctly size an engagement. We are confident of this due to the planning and delivery approaches we have in place, which have been designed from experience delivering complex engagements over the years. This structured approach is always something I would recommend you look for in your providers regardless of who they are. Not a strict robotic check list but a clear understanding of the complexities and expectations from these operations is key.