Get a red team assessment
Is your organization subject to DORA articles 24-27 and preparing for TIBER-NL or TIBER-EU? Does your board require demonstrable cyber resilience against targeted attacks? Do you want to know whether your SOC detects a real APT attacker before critical data is lost? For mature security organizations, a Red Team Assessment is the most realistic validation of your overall resilience.
DongIT performs Red Team Assessments based on the MITRE ATT&CK framework and the Cyber Kill Chain. Our OSCP, OSEP and OSED-certified ethical hackers simulate realistic Advanced Persistent Threat (APT) scenarios on your critical systems, data and processes. The goal is not to find as many vulnerabilities as possible, but to concretely establish whether your detection, resistance and response capacity survive a targeted attack.
Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe. DongIT has been ISO 27001:2022-certified since 2015.
What is a red team assessment?
A Red Team Assessment is a targeted simulation of a real cyberattack, performed without announcement to your defensive teams. Instead of searching for as many vulnerabilities as possible (as a pentest does), a red team focuses on one or a few concrete objectives: access to crown jewels, exfiltration of sensitive data or manipulation of critical processes.
Red team versus pentest
- Objective. Pentest: find vulnerabilities. Red team: achieve objectives.
- Scope. Pentest: technical and bounded. Red team: technical + physical + human.
- Announcement. Pentest: announced to IT. Red team: known only to C-level.
- What is tested. Pentest: security controls. Red team: detection and response capacity.
What we simulate
- Reconnaissance. OSINT, LinkedIn profiling, leaked credentials, subdomain enumeration.
- Initial access. Spear phishing, watering hole attacks, supply chain vectors.
- Post-exploitation. Persistence, privilege escalation, lateral movement.
- Physical component. Tailgating, badge cloning, on-site social engineering (optional).
Our approach: six phases of adversary emulation
We follow a structured approach based on MITRE ATT&CK and the Cyber Kill Chain. Every phase is tailored to the threat actors that actually target your sector.
Threat modeling and scope definition
We work with your C-level to determine which crown jewels are in scope, which threat actors are relevant to your sector (state-sponsored, ransomware groups, hacktivists) and which tactics, techniques and procedures (TTPs) we simulate. Rules of engagement are recorded in writing.
Reconnaissance
OSINT phase: publicly available information about your organization, employees and infrastructure is mapped. We build the same picture that a real attacker would compile in the weeks before an attack.
Initial access
Targeted spear phishing, exploitation of external services, watering hole attacks or supply chain vectors. We do not test 100 employees at once as a phishing simulation does, but focus on one or two key individuals with tailored scenarios.
Persistence and lateral movement
After initial access we operate as a silent attacker. Command and control channels are set up, credentials are harvested via Kerberoasting or DCSync, and we move laterally toward your crown jewels. Your SOC gets the chance to detect us.
Objective achievement
Achieving pre-agreed objectives: access to production environment, exfiltration of test data, manipulation of critical transactions or takeover of administrative accounts. All under strict safety agreements.
Purple team debriefing
Immediately after completion, a structured session with your Blue Team. We show exactly how we operated, which detections worked and where visibility was missing. Your SOC learns directly from the attack and can adjust detection engineering.
Duration: typically 8 to 16 weeks from intake to Purple team session. For TIBER-NL engagements the timeline is aligned with DNB planning.
Who is a red team assessment suitable for?
Red teaming only delivers value at a certain maturity of security organization. We would rather refer you to a pentest when that fits better.
Suitable for
- Organizations with an operational SOC or MDR service
- Financial entities under DORA (articles 24-27)
- Banks and systemically important institutions (TIBER-NL candidates)
- NIS2 essential entities with a mature security program
- Organizations after multiple successful pentests
- Board requests for cyber resilience validation
- Sectors with elevated APT risk: government, energy, healthcare
Less suitable for
- Organizations without their own SOC or managed detection
- Organizations that have never had a pentest performed
- Situations where known vulnerabilities are not mitigated
- Smaller organizations without budget headroom (indication €80,000+)
- Compliance purposes without a detection focus (choose a pentest)
Our advice: for less mature security programs, pentests deliver more value per euro. We transparently advise which product fits your situation.
Compliance context for red teaming
For three compliance frameworks, red teaming is either a concrete obligation or a strong recommendation:
DORA and TIBER-NL
DORA articles 24-27 mandate Threat-Led Penetration Testing (TLPT) for large financial entities in the EU. TIBER-NL is the Dutch implementation under DNB supervision. Our red team assessments are methodologically aligned with TIBER-EU and can serve as preparation for formal TLPT.
NIS2 and Dutch Cybersecurity Act
For NIS2 essential entities, article 21(2)(f) (evaluation of security measures) is a concrete obligation. Red teaming goes beyond pentesting and assesses not only technical but also organizational resilience against realistic threats.
Board and cyber insurance
Boards increasingly demand demonstrable cyber resilience. Cyber insurers require concrete adversary emulation results for high coverage levels. Our reporting is intentionally board-readable and directly shareable with stakeholders.
What does a red team assessment cost?
Red team assessments are always scoped bespoke. The price depends on scope size, duration, number of objectives, physical component and compliance context (for example TIBER-NL alignment). For clearly defined engagements we use indicative budget ranges:
- Compact Red Team, indicative from €80,000
- Standard Red Team, indicative €120,000 to €180,000
- TIBER-aligned Red Team, indicative €200,000+
- Enterprise multi-entity engagements, tailored quotation
These figures are indications, not quotations. A concrete quotation always follows after a discovery call with your C-level.
Strategic discovery call
For every red team engagement we start with a complimentary discovery call with your CISO or Head of Security. Objective: determine whether red teaming is the right step and which scope delivers the most value.
Frequently asked questions about red teaming
Below are the most frequently asked questions about Red Team Assessments. For a complete overview please visit our FAQ page.
What is the difference between a pentest and a red team assessment?
A pentest looks for as many vulnerabilities as possible within a bounded scope. A red team assessment simulates a real attacker who wants to achieve one specific objective (such as access to a production environment or data exfiltration), without announcement to defensive teams. Red teaming tests your detection and response capacity; a pentest tests your security controls.
Who within my organization may know about the red team engagement?
By default only C-level (CISO, CIO, CEO) and a small number of designated stakeholders. Your Blue Team and SOC know nothing, so we can realistically test their actual detection capacity. Rules of engagement are documented in writing with a small trusted agent team.
Can you perform a TIBER-NL engagement?
Our red team methodology is aligned with TIBER-EU, under which TIBER-NL falls. We can serve as preparation partner for your formal TIBER-NL engagement, and for smaller financial entities that do not fall under TIBER but do want DORA-compliant red teaming. For formal TIBER-NL under DNB supervision we cooperate with TIBER Threat Intelligence Providers.
How is safety handled during the attack?
Strict safety agreements. Our objective is never to disrupt production or destroy data. At every critical moment (for example successful initial access) we validate with the trusted agent group before escalating. Immediate stop capability via a pre-agreed escalation procedure.
How long does a red team assessment take?
Typically 8 to 16 weeks from intake to Purple team session. For smaller scopes 6 to 8 weeks, for extensive TIBER-like engagements 20+ weeks. Active testing time is usually 3 to 6 weeks; the remainder is scoping, threat intelligence and reporting.
What if you do not achieve your objective?
That is an excellent outcome. A red team engagement in which your SOC detects and effectively blocks us proves that your defensive investments are paying off. We still report extensively on all attempted tactics, where detection occurred and where visibility was missing.
What does a Purple team session deliver?
Immediately after completion, Red Team and Blue Team sit together. We show exactly which TTPs we used, which detection rules worked and which log sources lacked visibility. Your SOC receives detection engineering advice that can be applied directly to your SIEM/EDR configuration. This is often the most valuable output of the entire engagement.
Do you work without subcontractors?
Our red team consists of our own OSCP, OSEP and OSED-certified ethical hackers. We work under the four-eyes principle with a minimum of two red teamers per engagement. For specialized components (for example hardware implants or specific OT environments) we transparently cooperate with known partners, always with your approval.
Does our data stay in Europe during the assessment?
Yes. Our Security Reporter platform runs on European infrastructure. All assessment data, harvested credentials (test) and findings are processed within the Netherlands. Under Schrems II and NIS2 a concrete advantage for international organizations with European data processing requirements.
Ready for realistic validation of your cyber resilience?
Are you preparing for DORA or TIBER-NL? Is your board asking for demonstrable resilience against APT scenarios? Do you want to know whether your SOC investment pays off in practice? Start with a discovery call with our red team lead. No obligation, confidential and without sales pressure. Response within one business day.
Nederlands