What an operation looks like
Adversary simulation is planned around a realistic threat to your sector and geography, mapped to MITRE ATT&CK, and executed quietly. Typical phases:
- Reconnaissance — open-source intelligence on your organisation, staff, suppliers and technology; identification of plausible initial-access routes.
- Initial access — phishing or other social-engineering pretexts, exposed services, credential exposure, supplier trust — whichever is realistic and in scope.
- Foothold and escalation — persistence, privilege escalation and lateral movement, with attention to what your controls log and alert on.
- Objective — proof of reaching the agreed target: a marker file, a screenshot, a controlled action — never real damage.
- Debrief — replay of the key steps with your defenders and a joint list of detection and process improvements.
Rules of engagement
Every operation is governed by signed rules of engagement stating the objectives, scope, permitted techniques, deconfliction procedure, safety and stop conditions and named contacts on both sides, supported by documented authority from the relevant asset, premises, system, data and employer owners. Techniques are non-destructive and impact is simulated with agreed methods; personal data is minimised, and reporting about individuals follows the rules of engagement and applicable employment and privacy safeguards — by default we report patterns, not names.
Discretion
Red-team buyers expect it and we work that way: a small trusted contact group, no public case studies, and evidence handled under agreed data-handling terms and deleted after the engagement, subject to any legal, contractual or legal-hold retention exceptions stated in the agreement. A standard red-team exercise is not automatically DORA threat-led penetration testing (TLPT).