office@safebyte.io București, România ISO 27001:2023 · ISO 9001:2023
Offensive testing

Red Team and TIBER-EU

We don't ask whether you have vulnerabilities — we ask whether your team would notice a real attacker exploiting them. A threat-led, objective-driven exercise, aligned with TIBER-EU and DORA's TLPT testing.

Français: această pagină nu e încă tradusă. Textul de mai jos e în English.

Red Team and TIBER-EU

A penetration test tells you what vulnerabilities you have. A red team answers a far less comfortable question: if someone actually got in, would you know? Many organisations with dozens of closed findings and a full SOC discover, during their first serious exercise, that an attacker reached the objective in days without generating a single alert that anyone acted on. That’s what we measure — not the presence of controls, but whether they work under pressure, against an adversary who doesn’t play by your checklist.

Threat-led, not checklist-driven

We don’t run “all techniques.” We build a scenario starting from the real adversaries of your sector — the groups that actually attack banks, energy or public administration — and replicate their operating model, from initial access to the declared objective (for example, a fraudulent transaction, access to a critical system or exfiltration of a data set). We work toward the objective, discreetly, without the defence team being informed.

TIBER-EU and DORA’s TLPT

Exercises can be aligned with the European TIBER-EU framework and its national implementations. For significant financial institutions, DORA requires a threat-led penetration test (TLPT) at least once every three years: based on threat intelligence, against live production systems, targeting critical functions, conducted over several months and potentially including social engineering and physical intrusion. We run the exercise to this standard and produce the evidence the supervisor requires.

How it runs

  • Threat intelligence — an intelligence provider builds the relevant adversary profile; the scenario starts there, not from imagination
  • Red team — we reach objectives like a real attacker: initial access, persistence, lateral movement, target achievement
  • Blue team — we measure what your defences detected, what they missed and how long it took someone to react
  • Purple team — a joint debrief, technique by technique, where we tune detection on the spot and turn the exercise into capability, not just a report

What you get

  • Complete attack narrative, with objectives reached, techniques used and the moments where you could have stopped the chain
  • Detection and response evaluation — the part a conventional pentest doesn’t give you
  • Remediation roadmap and detection improvement plan
  • Where required, a report suitable for submission to the regulator