Empire Protection

Service

Penetration Testing (Red Teaming)

Red teaming: physical entry and cyber, to a scope you have signed.

Adversarial testing of what would actually happen: whether someone can get in, stay in, and take something out.

Every engagement requires written authority to test, signed by someone with the authority to give it, naming scope, dates, locations, methods and testers. There are no exceptions to this.

Physical and cyber testing are scoped together because attackers do not separate them. A badge cloned in a lobby and a credential phished over email lead to the same place, and testing only one half produces a report that reassures you about the wrong door.

A test measures three things: whether entry is possible, whether presence goes unnoticed once inside, and whether anything can leave. The second is usually the finding that matters: most organisations discover their detection and response is the gap, not their perimeter.

Testers carry the signed authority with them for the duration. Empire agrees the escalation path and the named contacts before anyone deploys, so a challenge by staff or by police resolves in minutes and the exercise ends the way it was designed to.

Common questions

What is red teaming, and how is it different from a penetration test?

A penetration test asks whether a defined thing can be broken into, within a defined scope. Red teaming asks what would actually happen if someone determined tried, across physical entry, people and systems together, against defenders who are not expecting it. The second answers the question a board is really asking.

Do you test physical entry as well as cyber?

Yes, and the combination is usually where the real finding is. Most organisations defend the two separately, and an adversary does not: a visitor pass and an unattended meeting room are frequently a faster route to data than the network is.

What authority do you need before testing?

Written authority to test, signed by someone with the standing to give it, naming scope, dates, locations, methods and the testers. There are no exceptions. Testing without it exposes both your organisation and the testers to criminal liability, and no commercial pressure changes that.

Will our staff know it is happening?

That is a decision made with you and it changes what the exercise measures. An announced test measures the controls. An unannounced one measures the controls and the people and the response together, which is more useful and needs more care about who is briefed: someone senior always knows, so a live test is never mistaken for a real incident.

What happens if you find something serious mid test?

Testing stops and you are told immediately, rather than at the end in a report. A finding severe enough to be exploited by someone else while the engagement runs is not a finding to sit on for a fortnight.

How a test runs

A test measures three things: whether entry is possible, whether presence goes unnoticed, and whether anything can leave. Everything before and after those exists to make them safe to measure.

  1. Written authority

    Signed by someone with the standing to give it, naming scope, dates, locations, methods and testers. There are no exceptions, and testers carry it for the duration.

  2. Scope both halves

    Physical and cyber together, because attackers do not separate them. A badge cloned in a lobby and a credential phished over email lead to the same place.

  3. Get in

    Whether entry is possible at all: the question most organisations expect a test to answer, and usually the least interesting of the three.

  4. Stay unnoticed

    Whether presence goes undetected once inside. This is normally the finding that matters: the gap is detection and response, not the perimeter.

  5. Take something out

    Whether anything can actually leave. A perimeter that holds and an exfiltration path that is open is a common and expensive combination.

  6. Report and stand down

    The escalation path and named contacts are agreed before anyone deploys, so a challenge by staff or police resolves in minutes and the exercise ends the way it was designed to.

Empire Executive Protection Pty Ltd · ABN 30 622 627 034 · trading as Empire Protection