Red Team & Adversary Simulation

An objective-based adversary simulation that tests your detection and response capabilities end-to-end. We emulate real-world threat actors using their actual tactics, techniques, and procedures, exercising your people, processes, and technology against the kind of attack you would actually face.

§ Service Overview

Test your defences against the kind of adversary you would actually face.

Where vulnerability assessment finds known weaknesses and penetration testing exploits them, red team and adversary simulation goes further. It tests whether your detection and response capabilities are ready for a determined adversary.

A red team and adversary simulation engagement uses threat intelligence and offensive tradecraft to simulate a real-world adversary attacking your organisation. The objective is not to enumerate vulnerabilities. It is to test whether your detection and response capabilities are ready when an actual attacker is in your environment.

Our consultants operate stealthily through the full kill chain, from reconnaissance and initial access through to the agreed objectives, exercising your security operations, incident response procedures, and security controls under conditions that mirror an actual intrusion. The engagement is informed by current threat intelligence and tactics, techniques, and procedures mapped to MITRE ATT&CK.

Each engagement concludes with a detailed simulation report, kill-chain narrative, evidence pack, and a debrief with your technical and executive stakeholders to walk through what happened and provide prioritised recommendations to strengthen your defences.

§ Why Choose Next Security

The Next Security Advantage

We combine elite offensive cybersecurity expertise with institutional backing to deliver red team engagements that actually drive business resilience.

01

Elite Technical Expertise

Our consultants bring deep offensive cybersecurity experience from top-tier global consulting firms, backed by the industry's most rigorous red team certifications including CRTM, CRTL, CRTO, CRTE, and CRTP, alongside OSCE³, OSEP, OSWE, OSCP, and HTB CAPE. Red team engagements are run by the same elite practitioners who define our methodology, with the tradecraft to operate stealthily and the discipline to do it without disrupting your operations.

02

Senior-Led Execution

No junior bait-and-switch and no offshore hand-offs. The senior consultants who scope your engagement are the ones running the simulation, walking you through findings, and supporting your team through the recommendations and remediation work. You get the same expert from kickoff through closure.

03

Institutionally Backed & Trusted

Adversary simulation requires absolute trust. You are granting us weeks of stealth access to your most sensitive environment. We are proudly supported by the HKSTP Incubation Programme and the CityU HK Tech 300 Seed Fund, making us a vetted Hong Kong cybersecurity partner with institutional accountability.

04

Actionable Business Intelligence

We don't deliver scanner reports or technical-only findings. Every red team engagement produces an executive narrative, a kill-chain attack story mapped to MITRE ATT&CK, and prioritised recommendations to strengthen your defensive capability, translated for both your engineers and your board.

§ Who This Service Is For

For organisations where detection and response must be exercised, not assumed.

Clients engage us when finding vulnerabilities is no longer enough, when detection and response capabilities have to be exercised, and when the outcome has to hold up to auditors, regulators, customers, and the board.

01

Mature security programmes

Organisations ready to test their detection and response capabilities under realistic adversary conditions, not just identify vulnerabilities point in time.

02

Post-pentest validation

Organisations that have completed penetration testing and want to verify whether attacks would actually be caught and contained by their security operations.

03

Regulatory & supervisory mandates

Organisations subject to intelligence-led testing requirements under HKMA C-RAF 2.0 iCAST, Hong Kong's Critical Infrastructure (Computer Systems) framework, HKIA GL20, or equivalent regulatory mandates.

04

Critical asset assurance

Validating defences around defined high-value assets, customer data, intellectual property, or systems considered critical to business continuity.

05

SOC & IR capability validation

Exercising security operations team detection coverage, escalation procedures, and incident response playbooks under realistic adversary conditions.

06

M&A and due diligence

Acquirers and investors evaluating the cyber resilience of target organisations prior to transaction close, particularly where integration of sensitive systems or data is planned.

Commonly engaged by teams in
Banking & Financial Services Insurance FinTech & Digital Payments Asset & Wealth Management Healthcare Government & Public Sector Critical Infrastructure & Utilities Telecommunications Logistics & Supply Chain E-commerce & Retail Education
§ Objectives & Scope

What each engagement is designed to achieve.

Every engagement is scoped collaboratively to ensure assessment objectives align with business priorities, threat profile, and regulatory context.

Assessment Objectives

  • Test the effectiveness of detection and response capabilities against realistic adversary tradecraft, not just point-in-time vulnerability findings.
  • Exercise your security operations team, incident response procedures, and escalation protocols under conditions that mirror an actual intrusion.
  • Identify gaps in detection coverage, response time, and containment workflow that vulnerability-finding services do not surface.
  • Demonstrate compliance with intelligence-led testing expectations under HKMA C-RAF 2.0 iCAST, the Hong Kong Critical Infrastructure (Computer Systems) framework, and equivalent global frameworks.
  • Provide an independent, evidence-backed view of cyber resilience suitable for board, audit, and regulatory submission.

Rules of Engagement

  • Defined trophy or objective(s) the engagement is contracted to reach.
  • Approved attack vectors selected during scoping (cyber, social engineering, physical, wireless).
  • Operational windows, blackout periods, and engagement timeframe.
  • Communication and escalation protocols with your designated contacts.
  • Out-of-scope assets, prohibited actions, and abort conditions.
§ Coverage

Comprehensive coverage. Real adversary tradecraft.

Coverage is structured around the MITRE ATT&CK Enterprise framework, informed by current threat intelligence and the tactics, techniques, and procedures of the adversaries our clients actually face.

01

Reconnaissance & Resource Development

Open-source intelligence gathering on your organisation, infrastructure and personnel profiling, and preparation of the attack infrastructure required for the engagement, including delivery domains, payloads, and command-and-control.

02

Initial Access & Execution

External entry vectors including phishing campaigns, exploitation of public-facing services, and abuse of valid credentials, followed by execution of the payload on compromised hosts.

03

Persistence & Privilege Escalation

Establishing long-term access that survives reboots and credential changes. Elevating to administrative control of compromised hosts through process injection, DLL hijacking, and exploitation of misconfigurations or kernel-level vulnerabilities.

04

Stealth & Defense Impairment

Operating below detection thresholds through obfuscation, sandbox evasion, and indicator removal, paired with active disabling of endpoint protection, EDR, and logging where the engagement objective requires it.

05

Credential Access

Harvesting credentials from memory, authentication services, password stores, scripts, and configuration files, including Kerberos abuse, NTLM relay, and password attacks against directory services.

06

Discovery, Lateral Movement & Collection

Internal reconnaissance of the network, hosts, and Active Directory environment, lateral movement across the network using built-in administration protocols and credential reuse, and identification and staging of high-value data.

07

Command & Control, Exfiltration & Impact

Establishing covert command-and-control channels through encrypted web traffic, DNS tunnelling, and proxy chains, followed by exfiltration of staged data and, where in scope, simulation of impact actions such as ransomware and business process disruption.

Threat-Led

Adversary Emulation

Where intelligence-led testing is required, our consultants emulate the specific tactics, techniques, and procedures of a named adversary, ransomware group, or sector-relevant threat actor, mapped end-to-end to MITRE ATT&CK and validated against current threat intelligence.

§ Methodology

A five-phase engagement framework.

A structured, repeatable methodology that delivers consistent quality, with clear entry and exit criteria at each phase and defined responsibilities on both sides.

01
Scoping

Scope & Planning

Define objectives, trophy, in-scope vectors, rules of engagement, communication and escalation protocols with your designated contacts, blackout windows, and abort conditions.

02
Intelligence

Threat Intel & Reconnaissance

Open-source intelligence gathering against your organisation, threat actor selection or scenario design where intelligence-led, and development of attack scenarios mapped to MITRE ATT&CK and validated against your environment.

03
Execution

Adversary Simulation

Stealth execution of agreed scenarios across the kill chain, from initial access through to objectives. Activity logged with timestamps and evidence. Operationally sensitive issues escalated to your designated contacts in real time.

04
Reporting

Findings & Analysis

A detailed simulation report with executive summary, kill-chain narrative mapped to MITRE ATT&CK, detection observations, evidence pack, and prioritised recommendations.

05
Debrief

Walk-through & Recommendations

Technical and executive debrief sessions where we walk through the engagement with your team, covering scenarios executed, attack paths taken, observations during the engagement, and recommendations for strengthening your defensive capability.

§ Deliverables

What you receive at the end of the engagement.

Every engagement produces a comprehensive simulation testing report designed to serve both technical remediation and executive decision-making.

01

Executive Summary

A non-technical narrative of the engagement, attack outcomes, business-risk implications, and strategic recommendations, written for leadership, risk, and board-level stakeholders.

02

Engagement Approach & Scenarios Executed

Documentation of the agreed scope, attack vectors selected, scenarios designed, threat intelligence sources, and the methodology applied during the engagement.

03

Attack-Path Narrative & Kill-Chain Mapping

Step-by-step story of how the engagement progressed, mapped to the MITRE ATT&CK matrix, showing what worked, what was bypassed, and where attack paths converged on objectives.

04

Detailed Technical Findings

Each finding documented with technical description, affected systems, evidence, observed impact, and references to relevant standards and CVE/CWE identifiers where applicable.

05

Activity Log & Evidence Pack

Timestamped log of every action taken during the engagement, with screenshots, command output, video evidence where applicable, and indicators of compromise (IoCs) for blue team detection rule development. Suitable for internal reproduction, audit, and regulatory submission.

06

Recommendations & Defensive Improvements

Prioritised recommendations across detection rules, control hardening, process improvements, and security team training, informed by the engagement findings and observations made during execution.

§ Standards & Compliance

Aligned with global frameworks and Hong Kong regulatory expectations.

Our methodology is built on internationally recognised adversary simulation frameworks and mapped to the regulatory regimes most relevant to Hong Kong-regulated organisations.

Testing Standards

FrameworkMITRE ATT&CK FrameworkLockheed Martin Cyber Kill Chain FrameworkNIST SP 800-115 FrameworkOSSTMM

Compliance Alignment

Hong KongHKMA C-RAF 2.0 iCAST Hong KongHK CI Bill Hong KongHKIA GL20 Hong KongSFC Cybersecurity Guidelines GlobalPCI DSS GlobalISO/IEC 27001
§ Credentials
Delivered by consultants holding the world's most respected cybersecurity credentials.

Red Team Operations

CRTM
CRTMCertified Red Team Master
CRTL
CRTLCertified Red Team Lead
CRTO
CRTOCertified Red Team Operator
CRTE
CRTECertified Red Team Expert
CRTP
CRTPCertified Red Team Professional
CARTP
CARTPCertified Azure Red Team Professional
CRTA
CRTACertified Red Team Analyst

Offensive Security & Penetration Testing

OSCE3
OSCE³OffSec Certified Expert³
OSEP
OSEPOffSec Experienced Penetration Tester
OSWE
OSWEOffSec Web Expert
OSED
OSEDOffSec Exploit Developer
OSCP
OSCPOffSec Certified Professional
OSCE
OSCEOffSec Certified Expert (Legacy)
OSWP
OSWPOffSec Wireless Professional
CPTS
HTB CPTSHTB Certified Penetration Testing Specialist
HTB CWES
HTB CWESHTB Certified Web Exploitation Specialist
HTB CWEE
HTB CWEEHTB Certified Web Exploitation Expert
HTB CAPE
HTB CAPEHTB Certified Active Directory Pentesting Expert
eCPTX
eCPTXeLearnSecurity Certified Penetration Tester eXtreme
eWPTX
eWPTXeLearnSecurity Web Application Penetration Tester eXtreme
eMAPT
eMAPTeLearnSecurity Mobile Application Penetration Tester
Burp Suite Certified Practitioner
BSCPBurp Suite Certified Practitioner
C|EH Master
CEH MasterCertified Ethical Hacker Master

Cloud Security & Infrastructure

AWS Security Specialty
AWS Security SpecialtyAWS Certified Security — Specialty
AWS Solutions Architect Associate
AWS Solutions ArchitectAWS Certified Solutions Architect — Associate
Azure Security Engineer
Azure Security EngineerMicrosoft Certified: Azure Security Engineer Associate
Azure Administrator Associate
Azure AdministratorMicrosoft Certified: Azure Administrator Associate
Azure Solutions Architect Expert
Azure Solutions ArchitectMicrosoft Certified: Azure Solutions Architect Expert
Microsoft Security, Compliance and Identity Fundamentals
Azure Security Fund.Microsoft Certified: Security, Compliance & Identity Fundamentals
Google Cloud Professional Cloud Architect
GCP Cloud ArchitectGoogle Cloud Professional Cloud Architect
CCNA
CCNACisco Certified Network Associate
CND
CNDCertified Network Defender

Governance, Risk & Compliance

CISM
CISMCertified Information Security Manager
CRISC
CRISCCertified in Risk and Information Systems Control
CISA
CISACertified Information Systems Auditor
BSI ISO/IEC 27001 Internal Auditor
ISO 27001 Internal AuditorBSI ISO/IEC 27001:2022 Internal Auditor (Practitioner)
§ Frequently Asked Questions

Answers to questions we hear most during scoping.

How does a red team assessment differ from a penetration test?

A penetration test focuses on identifying and exploiting vulnerabilities in a specific asset or environment within a defined scope. A red team assessment is fundamentally different. It simulates a determined adversary, end-to-end, against your organisation. The goal is not to enumerate vulnerabilities. It is to test whether your detection and response capabilities are ready when an actual attacker is in your environment. Red team operations are stealthy by design, multi-vector, and objective-based, exercising your people, processes, and technology together rather than evaluating any one of them in isolation.

Will our blue team know about the engagement?

No. The value of a red team engagement comes from testing your security operations under realistic conditions, which means your blue team and broader security organisation are not informed during execution. Knowledge of the engagement is restricted to a small group of designated contacts who hold authority to authorize activity, escalate issues, abort the engagement, or extend scope. Your blue team is debriefed after the engagement concludes, typically through a collaborative walk-through where the attack path is reconstructed and recommendations are discussed.

What happens if your activity gets detected?

Detection during an engagement does not end it. The standard practice is to continue testing rather than abort. Our consultants will continue with alternative tradecraft to test the breadth of your detection capabilities, or where the engagement objective requires testing later kill-chain stages, pause and resume from an agreed point further along the kill chain with your designated contacts. This ensures the engagement continues to deliver value across the full set of objectives. Detection events are useful data points in their own right, captured in the activity log and discussed during the debrief.

Do you perform physical security testing?

Where in scope, yes. Physical security testing can include badge cloning, tailgating, lock bypass, USB drop campaigns, and unauthorized entry attempts to validate physical access controls. Physical testing is high-risk and is only conducted with explicit written authorization, defined operational windows, signed authorization letters carried by consultants, and a clear escalation protocol with your designated contacts. Many engagements run cyber and social engineering only without physical access; the right scope is agreed during the scoping call.

Do you perform social engineering?

Where in scope, yes. Social engineering can include phishing campaigns, voice and video pretexting, and other human-element attack vectors. Social engineering scenarios are designed and reviewed with your designated contacts before execution to ensure they reflect realistic adversary behaviour without crossing into prohibited territory such as targeting specific individuals personally or causing psychological distress. Where social engineering is out of scope, the engagement focuses on technical and infrastructure-based attack paths.

What's the difference between a red team and a purple team engagement?

A red team engagement is adversarial. We operate stealthily, your blue team is not informed during execution, and the goal is to test detection and response under realistic conditions. A purple team engagement is collaborative. The red and blue teams work together in real time, executing TTPs and discussing detection coverage as they go, often as a focused exercise to improve detection rules around specific tactics. Our service described on this page is red team and adversary simulation. Purple team is offered as a separate engagement type.

How long does a typical engagement take?

A typical red team engagement runs 3 to 6 weeks of active operations, with an additional 1 to 2 weeks for scoping and threat intelligence preparation up front, and 1 to 2 weeks for reporting and debriefing at the end. Total engagement duration is typically 5 to 10 weeks. Larger or multi-vector engagements that include physical and extensive social engineering can extend further. Compressed engagements of shorter duration are possible for scoped scenarios such as Assumed Breach.

How soon can an engagement start?

Most red team engagements kick off within 2 to 4 weeks of scoping sign-off, accounting for the threat intelligence and scenario design work performed up front. Where a regulatory deadline or board-mandated milestone requires a faster start, we will do our best to accommodate and confirm feasibility during the scoping call.

How do you measure the outcome of a red team engagement?

A red team engagement produces value in several ways that go beyond a count of vulnerabilities. The primary outcome is a clear picture of where your defences held against realistic adversary tradecraft and where they were bypassed. The engagement also produces traditional findings on exploitable weaknesses where they were used, an attack-path narrative showing how an actual attacker could progress through your environment, and observations on where security tooling intervened during execution. These provide your team with the input needed to evaluate detection and response performance and prioritise improvements.

Will you actually exfiltrate real production data?

Not in the literal sense. Where the engagement objective involves data exfiltration, we typically demonstrate the capability against canary files, synthetic data, or pre-agreed marker assets that prove access without actually exposing real sensitive content. Where access to real data is unavoidable for evidencing an objective, the data is handled under strict confidentiality, captured only to the extent necessary to evidence the finding, and confirmed destroyed in writing after engagement closure.

Will testing affect our production environment?

Adversary simulation is conducted carefully and under controlled conditions to avoid disrupting production. Before execution, we agree on the engagement window, blackout periods, prohibited actions (e.g. denial-of-service, destructive payloads, exploits known to risk service stability), and abort conditions. Higher-risk techniques are coordinated in advance with your designated contacts, and any operationally sensitive issue is escalated in real time so the engagement can be paused or rerouted.

How do you handle sensitive data encountered during testing?

Any sensitive data, credentials, or system information encountered during the engagement is handled under strict confidentiality. We do not extract, retain, or reproduce sensitive data beyond what is strictly necessary to evidence a finding, and where possible, data is anonymised in the final report. Recovered credentials are not used outside the agreed engagement scope. Credentials provided by you for authorized access are held in access-controlled secrets management throughout the engagement, used only for the agreed scope and duration, and confirmed destroyed in writing after engagement closure. All engagement artefacts are stored in access-controlled environments, transmitted over encrypted channels, and securely destroyed after the agreed retention period.

Do you provide a Letter of Attestation?

Yes. On request, we issue a formal Letter of Attestation summarising the engagement scope, operational period, methodology followed, and high-level outcome. The attestation is suitable for audit, regulatory submission, and third-party assurance purposes, including HKMA C-RAF 2.0 iCAST, the Hong Kong Critical Infrastructure (Computer Systems) framework, PCI DSS, SOC 2, ISO/IEC 27001, and similar obligations.

Ready to test if your defences would hold up against a real adversary?

Schedule a scoping call with our specialists to define the right engagement scope for your environment, threat profile, and timeline. We will walk you through methodology, deliverables, and next steps.