Back to case studies
Banking 6 weeks
Red Team Operations
Red Team Exercise
A global bank commissioned a stealth-first red team to evaluate detection and response. Over six weeks we emulated a financially motivated actor from initial access through to a simulated funds-transfer workstation.
Engagement scope: Global workforce, 30k employees
18dTime-to-detect (before)
71%MTTD improvement
34Detections added
Engagement Objectives
- Evaluate blue-team detection and response
- Test email security and endpoint hardening
- Assume an objective of reaching a payment workstation
Approach
We began with a scoping workshop to align on in-scope assets, rules of engagement, and success criteria. Over the following weeks, our consultants applied a manual-first methodology aligned to Red Team Operations, validating every finding before reporting and coordinating closely with the client's engineering team.
Outcome
We reached the objective undetected for the first 18 days. The purple-team debrief produced a prioritized detection-engineering backlog that improved mean-time-to-detect by 71%.
What We Delivered
Executive summary for leadership
Technical report with reproducible PoCs
CVSSv3.1 scored findings
Remediation walkthrough with engineers
Attack-path visualization
Free retest to confirm closure