Real Insight in Real Time: How AI is Changing the Way We Manage Cyber Risk
Across the tech-sphere it has become abundantly clear that Artificial Intelligence is now a driving force, even more-so across the cybersecurity landscape. With this great leap in technology, AI is being leveraged on both sides of the battle. But how? AI is now being used both as a tool for defence and, increasingly, as a […]
Why bother with Physical Breach Tests?
A physical red team (breach) test is a real-world simulation of a physical breach. Think: tailgating into a secure office, picking locks, planting rogue devices, or accessing server rooms without authorisation. Unlike standard security audits, red teamers think and act like real adversaries – covertly probing for the weakest link in physical security protocols, policies, […]
Why Not Test in Dev?
We frequently get asked by clients if we can do our red team tests in their DEV or UAT environments instead of production. We are told its identical to production – same systems, dummy but similar data, same security controls, same user accounts, etc. Etc. We get it, DEV and UAT environments are there to […]
The Cost of a Breach
IBM’s 2024 Cost of a Data Breach report, identified that the average cost of a data breach in the UK reached £3.58 million, and that this cost had increased 5% since 2023. Verizon’s 2025 Data Breach Investigation report, suggested there was a 37% increase in ransomware attacks being reported, with a median payout of $115,000 […]
AI and Red Teaming
Red teaming is still fairly young as far as cybersecurity disciplines go – most of us in this part of the industry have come in from being penetration testing consultants, or have some sort of background in IT security with a good mix of coding and scripting skills to develop tools. Our work often requires […]
Data Hygiene
Most organisation’s that are breached and compromised are done so not because they are lax with security, have poor patching, or are gambling that they will never be a victim; instead they usually suffer from poor data hygiene. Users store data on desktops, in shared folders, in online repositories (such as Jira, SharePoint, Confluence, etc.), […]
DORA TLPT Guidance Update
Today the EU provided the long awaited updated guidance in relation to DORA’s TLPT: DORA TLPT Guidance Update This 30 page document further clarifies the necessity for Threat-Led Penetration Tests (TLPTs) under DORA. We will be posting a more in-depth post about this in the very near future, but the key points that should be […]
TIBER-BE Insights
The TIBER-EU framework is designed to help organisations improve their Cyber resiliency. It has multiple stages: initiation (scoping, procurement, planning), threat intelligence, penetration testing (red teaming), purple teaming (attack replays, additional untested control tests, variances in attack methodologies working alongside the Blue team), and closure (reporting, remediation plans, attestation). As a framework, TIBER can be […]
The Cyber Security and Resilience Bill – April 2025
In the King’s Speech it was announced that further details would follow about the CSR Bill, and it looks like we now have the confirmed and proposed measures: Cyber Security and Resilience Bill: policy statement – GOV.UK These have been proposed by both MPs and the Department for Science, Innovation and Technology (DSIT) and backed […]
Capitalising on the Investment of a Red Team Engagement
Cybersecurity red teams are designed to evaluate an organisation’s ability to detect and respond to cybersecurity threats. They are modelled on real life breaches, giving an organisation an opportunity to determine if they have the resiliency to withstand a similar breach. No two breaches are entirely alike, as each organisation’s organic and planned growth of […]