شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Assess & test

Red teamMeasure your detection and response against a realistic adversary

We simulate a full attack with defined objectives, from initial access to the final goal, to show you what your SOC sees and what it does not.

At a glance

Frameworks

  • MITRE ATT&CK
  • SAMA CSF
  • NCA CSCC
  • NCA ECC

Deliverables

  • Objectives, scenarios and rules-of-engagement document
  • Timestamped technical attack narrative
  • Detection-gap map against MITRE ATT&CK
  • Proposed detection rules for the SOC
  • Executive briefing for management

The challenge

The NCA Critical Systems Cybersecurity Controls (CSCC) and the SAMA Cyber Security Framework (CSF) go beyond vulnerability testing to testing the ability to detect and respond. SAMA in particular expects financial institutions to run intelligence-led attack simulations.

Passing a penetration test does not mean your SOC will notice a patient attacker moving slowly through legitimate accounts. A red team answers a different question: if an adversary got in, would you know, and how long would it take?

We plan the exercise with a single coordinator on your side, run it without the defenders' knowledge, then sit with the blue team to compare every attack step with what was and was not detected.

How we work

  1. 1

    Planning and objectives

    We define objectives (such as reaching a critical system or specific data), scenarios based on threat actors targeting your sector, rules of engagement and immediate stop mechanisms.

  2. 2

    Execution

    External reconnaissance, initial access through phishing, vulnerabilities or physical entry, then persistence, lateral movement and privilege escalation to the objective, with every step timestamped.

  3. 3

    Comparison and improvement

    A purple-team session comparing the attack timeline with your detection logs, then a detection-gap map and proposed rules to close each gap.

What is included

  • Intelligence-led simulation

    Scenarios drawn from tactics of threat actors active in the region, mapped to MITRE ATT&CK techniques.

  • Multi-vector initial access

    Spear phishing, exploitation of exposed services, leaked credentials and physical access to premises within the agreed scope.

  • Lateral movement and Active Directory

    Exploitation of trust paths, Kerberos abuse and weak AD configuration to reach critical systems.

  • Detection evasion

    Techniques that bypass EDR and SIEM rules in a controlled way to measure coverage depth, not to cause harm.

  • Purple teaming

    Joint exercises with your defenders where techniques are run one by one and detection rules are built in the same session.

  • Response testing

    Measuring how the response team behaves once the attack is spotted: did it contain correctly, preserve evidence, escalate to management?

  • Three-level reporting

    A management summary, a technical attack narrative, and a detection-gap map with recommendations for both the SOC and infrastructure teams.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • MITRE ATT&CK
  • SAMA CSF
  • NCA CSCC
  • NCA ECC

Frequently asked questions

How is a red team different from a penetration test?

A penetration test looks for as many vulnerabilities as possible in a defined scope, with everyone aware. A red team pursues one objective by any route, without the defenders knowing, to measure detection and response rather than just vulnerabilities.

Do we need a mature SOC before this is useful?

It helps to have basic detection capability in place. If not, we suggest starting with penetration testing and purple-team exercises to build coverage first.

How do you avoid harming production?

Signed rules of engagement, an immediate stop word, a coordinator who knows about the exercise throughout, and no destructive actions or real data exfiltration.

Can the results serve as compliance evidence?

The report documents scenarios, results and improvements in a way that serves SAMA CSF and CSCC expectations for attack simulation; acceptance of the evidence remains with the regulator or auditor.

What affects the cost and effort of a red team exercise?

The number and difficulty of the objectives, the attack vectors in scope (phishing, exposed services, physical entry) and the size of the environment the team has to move through. The length of the exercise window agreed with your coordinator, and whether a purple-team session follows, also shape the effort. We set this out in a written proposal after the planning session.

What approvals and preparation does a red team exercise need?

Written authorisation from senior management, and a small control group (the white team) who know about the exercise and can stop it at any time. Rules of engagement are signed before starting, covering objectives, permitted techniques, exclusions and the stop procedure. Social engineering and physical entry also need agreement from legal and HR, an authorisation letter carried by testers on site, and confirmation from any hosting or cloud provider whose terms require it.

How does a red team exercise relate to SAMA's FEER framework?

SAMA's Financial Entities Ethical Red-Teaming (FEER) framework applies to the financial institutions SAMA regulates, expects each to be tested at least once every three years, and runs in four phases: preparation, scenario, execution and lessons learned. SAMA's Green Team approves the choice of provider, so whether an exercise counts under FEER is decided through SAMA's process, not by the provider. Outside FEER, our red team exercises follow a comparable path from planning to execution and a lessons-learned review.

  • Assess & test

    Penetration testing

    Application, network and infrastructure testing with recognised methodologies and an actionable report.

  • Detect & respond

    Managed SOC

    24/7 monitoring, analysis and response under an NCA licence.

  • Detect & respond

    Managed Detection & Response (MDR)

    Endpoint and identity detection and response run by analysts.

  • Detect & respond

    Incident response

    Contain, investigate and recover from incidents with documented procedures.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.