The challenge
The NCA Critical Systems Cybersecurity Controls (CSCC) and the SAMA Cyber Security Framework (CSF) go beyond vulnerability testing to testing the ability to detect and respond. SAMA in particular expects financial institutions to run intelligence-led attack simulations.
Passing a penetration test does not mean your SOC will notice a patient attacker moving slowly through legitimate accounts. A red team answers a different question: if an adversary got in, would you know, and how long would it take?
We plan the exercise with a single coordinator on your side, run it without the defenders' knowledge, then sit with the blue team to compare every attack step with what was and was not detected.
How we work
- 1
Planning and objectives
We define objectives (such as reaching a critical system or specific data), scenarios based on threat actors targeting your sector, rules of engagement and immediate stop mechanisms.
- 2
Execution
External reconnaissance, initial access through phishing, vulnerabilities or physical entry, then persistence, lateral movement and privilege escalation to the objective, with every step timestamped.
- 3
Comparison and improvement
A purple-team session comparing the attack timeline with your detection logs, then a detection-gap map and proposed rules to close each gap.
What is included
Intelligence-led simulation
Scenarios drawn from tactics of threat actors active in the region, mapped to MITRE ATT&CK techniques.
Multi-vector initial access
Spear phishing, exploitation of exposed services, leaked credentials and physical access to premises within the agreed scope.
Lateral movement and Active Directory
Exploitation of trust paths, Kerberos abuse and weak AD configuration to reach critical systems.
Detection evasion
Techniques that bypass EDR and SIEM rules in a controlled way to measure coverage depth, not to cause harm.
Purple teaming
Joint exercises with your defenders where techniques are run one by one and detection rules are built in the same session.
Response testing
Measuring how the response team behaves once the attack is spotted: did it contain correctly, preserve evidence, escalate to management?
Three-level reporting
A management summary, a technical attack narrative, and a detection-gap map with recommendations for both the SOC and infrastructure teams.
Frameworks and regulations
We align the service with the frameworks your organisation is subject to.
- MITRE ATT&CK
- SAMA CSF
- NCA CSCC
- NCA ECC
Frequently asked questions
How is a red team different from a penetration test?
A penetration test looks for as many vulnerabilities as possible in a defined scope, with everyone aware. A red team pursues one objective by any route, without the defenders knowing, to measure detection and response rather than just vulnerabilities.
Do we need a mature SOC before this is useful?
It helps to have basic detection capability in place. If not, we suggest starting with penetration testing and purple-team exercises to build coverage first.
How do you avoid harming production?
Signed rules of engagement, an immediate stop word, a coordinator who knows about the exercise throughout, and no destructive actions or real data exfiltration.
Can the results serve as compliance evidence?
The report documents scenarios, results and improvements in a way that serves SAMA CSF and CSCC expectations for attack simulation; acceptance of the evidence remains with the regulator or auditor.
What affects the cost and effort of a red team exercise?
The number and difficulty of the objectives, the attack vectors in scope (phishing, exposed services, physical entry) and the size of the environment the team has to move through. The length of the exercise window agreed with your coordinator, and whether a purple-team session follows, also shape the effort. We set this out in a written proposal after the planning session.
What approvals and preparation does a red team exercise need?
Written authorisation from senior management, and a small control group (the white team) who know about the exercise and can stop it at any time. Rules of engagement are signed before starting, covering objectives, permitted techniques, exclusions and the stop procedure. Social engineering and physical entry also need agreement from legal and HR, an authorisation letter carried by testers on site, and confirmation from any hosting or cloud provider whose terms require it.
How does a red team exercise relate to SAMA's FEER framework?
SAMA's Financial Entities Ethical Red-Teaming (FEER) framework applies to the financial institutions SAMA regulates, expects each to be tested at least once every three years, and runs in four phases: preparation, scenario, execution and lessons learned. SAMA's Green Team approves the choice of provider, so whether an exercise counts under FEER is decided through SAMA's process, not by the provider. Outside FEER, our red team exercises follow a comparable path from planning to execution and a lessons-learned review.
Related services
Assess & test
Penetration testing
Application, network and infrastructure testing with recognised methodologies and an actionable report.
Detect & respond
Managed SOC
24/7 monitoring, analysis and response under an NCA licence.
Detect & respond
Managed Detection & Response (MDR)
Endpoint and identity detection and response run by analysts.
Detect & respond
Incident response
Contain, investigate and recover from incidents with documented procedures.
Contact
Let's talk about what you need
We answer enquiries through the form, WhatsApp, a call or email.
Mobile (calls and WhatsApp)
+966 59 750 4669Email
info@datasec.sa

