
Incident response & red teaming
Breach response and adversary simulation
Overview
Incident-response engagements that contain and eradicate live breaches, and red-team operations that rehearse the adversary before one arrives. Delivered by researchers with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems.
When the breach is live, the team that arrives has broken into ships, rail systems and payment networks legally, and knows exactly how the adversary thinks.
Capabilities
- Incident-response engagements: containment, eradication, recovery
- Red-team operations rehearsing realistic adversaries
- Forensics and after-action hardening
- Retainer and rapid-deployment options
- Reduces the dwell time of a live intrusion: the team contains and eradicates before an attacker can pivot deeper into critical systems
- Every engagement leaves the estate more defensible, feeding findings straight into hardening so the same breach cannot recur
Specifications
| Type | Incident response & red teaming |
| Modes | Live response / adversary simulation |
| Basis | Disclosed research across maritime / rail / ICS |
| Origin | Independent / non-aligned |
In depth
Containment comes before certainty
A live breach creates a practical order of work. The incident-response engagement covers containment, eradication and recovery, with forensics and after-action hardening recorded as part of the offer. The first task is to limit the intrusion and prevent an attacker from pivoting deeper into critical systems. Eradication removes the foothold, while recovery restores the affected environment and the confidence to operate it again. Forensics preserves the account of what happened so the response is not reduced to a hurried reset. The catalogue also records retainer and rapid-deployment options, reflecting the difference between arranging help after a compromise and having a response path ready when the event is live.

Rehearse the route an attacker takes
Red-team operations provide the other mode of the capability. They rehearse realistic adversaries against the buyer's environment before an actual breach, using the same attention to objectives and attack paths that makes response useful under pressure. The team is associated in the product record with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems. Its work has also included legally conducted attacks against ships, rail systems and payment networks. Those references establish the research and operating domains without turning a simulation into a claim of access to every environment. The purpose is specific: expose weaknesses, exercise response plans and learn where an attacker could move before the organisation is dealing with the real event.
The breach should change the defence
After-action hardening is the connection between response and prevention. Findings from a live engagement feed into hardening so the same weakness is not simply documented and forgotten. Offensive cybersecurity supplies authorised adversary testing, while defensive cybersecurity supplies continuous detection and response. The incident-response capability joins them around the event itself, with an independent and non-aligned origin and a basis in disclosed research across maritime, rail and industrial control systems. Its role is not to claim that an incident can be made impossible. It is to reduce dwell time, contain the compromise before it travels further, recover the affected systems and leave the estate more defensible than it was when the response began.
Response has a defined handoff
The response sequence is deliberately wider than finding a compromised machine. Containment limits the incident, eradication removes the foothold, recovery returns the affected systems to operation, and forensics records what can be established about the intrusion. After-action hardening then turns that record into changes to the estate. The catalogue lists retainer and rapid-deployment options because those modes address different procurement decisions without changing the work itself. A buyer may need a standing path for a live breach, or a rapid engagement when no retainer exists. The red-team side provides a controlled way to rehearse the same sequence before the next event. It uses realistic adversaries and a defined objective, with the work bounded by authorisation. Research across maritime, rail and industrial control systems keeps the assessment grounded in environments where a breach can affect more than an office endpoint. The capability therefore links response, forensics, simulation and hardening, while leaving the buyer with the findings needed to make the defensive estate stronger.
The research boundary is part of the response
The record does not describe incident response as a generic help desk. Its basis is responsibly disclosed research across maritime, rail and industrial control systems, and its related offensive work has legally tested ships, rail systems and payment networks. That operating background matters when the responder has to understand how an adversary could move through a specialised environment, not just how to reset an office account. The response still follows the defined modes in the catalogue: containment, eradication and recovery for a live breach; red-team adversary simulation before one; forensics and after-action hardening after the work. Retainer and rapid-deployment options provide the available engagement paths without changing those responsibilities or making a claim that every incident has the same cause.

Why Unstrat: the difference
Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.
Independent, non-aligned origin, with no political exposure to any major-power ecosystem.
One accountable team from first briefing through delivery and in-region sustainment.
Responders with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems.
How it reaches you
Related capability
View all →Procurement & sustainment
Classification and the end-user-certificate chain are confirmed before this capability is represented to your market.
Sourced from an independent manufacturer: no major-power disclosure rules or political conditions.
A single team responsible from first briefing through delivery: not a chain of foreign primes to integrate yourself.
Lifecycle support and operator training delivered in-region, building capability that outlasts the initial deployment.
Questions buyers ask
What is an incident response retainer?
A contract signed before the breach, so that the NDA, the data-handling terms and the commercial arrangement are already agreed when the phone rings. The strongest practical argument for one is procurement speed rather than raw response time. We offer retainer and rapid-deployment options, and the responders are the same people who legally break into ships, rail systems and payment networks.
See: Incident response and red teamingAgainst Unit 42 and Mandiant
What response time should an IR retainer guarantee?
The market benchmark is now two hours to first human contact: Mandiant guarantees it on any retainer, and Unit 42 offers it on its top tier with 4, 8 and 24 hours below that. We do not publish an SLA, which is a genuine gap and we say so on our comparison page. Note also that time to first contact and time to containment are different numbers, and only the second one changes the outcome.
Best incident response firms
Unit 42 and Mandiant publish the clearest commitments in the industry, and on paper we do not match them: Unit 42 cites more than 1,000 investigations a year and Mandiant frontline work since 2004. What neither publishes is a track record inside vessels, rail signalling and industrial control systems. Choose on the estate you actually need defended.
Who can respond to a cyber incident on a ship at sea?
Very few teams. Most IR practices are built for enterprise IT and will not know what can safely be isolated on a vessel under way. Our responders come from the research that produced responsible disclosures across maritime, rail and industrial control systems, so the first hour is spent containing rather than learning the environment. Neither the Unit 42 nor the Mandiant retainer datasheet publishes sector experience of that kind.
Incident response for industrial control systems and rail signalling
Containment in an OT estate is a safety decision as much as a security one, because isolating the wrong segment stops the process. Our incident work covers containment, eradication and recovery on systems in service, followed by hardening that feeds back into the defences. The disclosures behind the team span maritime, rail and industrial control systems.
Is an IR retainer worth it if we are never breached?
The good ones are designed so the money converts into readiness. Mandiant allows unused prepaid hours to be repurposed across other consulting within the term, and Unit 42 credits can be spent on readiness assessments, tabletop exercises, penetration testing and IR plan development. If a supplier cannot tell you what happens to unused capacity, negotiate harder before signing.
Should the same firm do our red teaming and our incident response?
A reasonable argument exists both ways. Separation preserves independence in the report; combination gives you responders who already know where the estate is weak because they broke it last quarter. We offer both from one team deliberately, and Unit 42 does something similar through retainer credits. Mandiant keeps its Red Team Assessment as a separate engagement.
See: Adversary simulation in the retainerOffensive cybersecurity
How do you reduce attacker dwell time once a breach is found?
By containing before the intruder pivots, which needs prior knowledge of what can be isolated in your estate without stopping operations. Our engagements are built around exactly that: containment, eradication and recovery, then forensics and after-action hardening so the same breach cannot recur. On the defensive side, our published example is a fleet-wide ransomware event contained and fully recovered inside a week.
We have a live intrusion in a national payment switch right now. What matters in the first hour?
Knowing which segments can be isolated without failing settlement, and having someone on the call who has seen a payment network mid-incident before. Our responders work on live production systems including payment networks, and the containment options are worked out from experience of those estates rather than from a generic playbook. After containment, forensics and hardening feed straight back into the defences.
See: Incident response and red teamingFinancial infrastructure defence
How should we score IR bidders when one publishes an SLA and another does not?
Score the two clocks separately and ask everyone for both: time to first human contact and time to containment by severity, written into the contract. Mandiant and Unit 42 both publish two-hour contact commitments and we do not, which we will not dress up. Then ask what happens after the callback, because a fast call from someone who has never seen your kind of system is not a response.
Who keeps the forensic images and credentials collected during a response?
By the end of an engagement the response team holds forensic images, credential material, network maps and an accurate account of how a national system was defeated. Neither competitor datasheet addresses onward disclosure, because product literature rarely does, so get the answer into the contract. Our answer is that there is no third government with standing to ask us for a copy.
Our cyber insurer has a panel of approved responders. Does that limit who we can call?
It can shape claims handling, and it is worth checking before an incident rather than during one. Unit 42 publishes recognition on the approved vendor panels of more than 70 major cyber-insurance carriers, honouring applicable panel rates. We do not publish insurance-panel recognition. If your policy makes panel membership decisive, raise it at scoping so the arrangement is clear.
What preparedness work should we do before we ever need a responder?
Test whether you can detect, decide and isolate. Mandiant's preparedness service reviews monitoring, logging and detection, checks containment capability and runs collaborative scenario planning, which is a good model of the scope. We deliver readiness through range exercises and after-action hardening from the same team that would respond, so the plan is rehearsed by the people who will execute it.
How does an incident response engagement leave us better off afterwards?
Only if the findings turn into work. Every engagement we run ends in after-action hardening, with findings fed straight into the defensive platforms so the same breach cannot recur. Ask any bidder what their report obliges them to do next, and whether the same team is accountable for the remediation.
Can a responder reach a remote site or a vessel when the network is down?
That is the case worth testing at contract stage, since most retainers assume remote access to a live estate. Our response work sits alongside off-grid assurance for isolated and remote systems, so the disconnected case is part of the same practice rather than an exception. Unit 42 publishes remote response SLAs by tier and regional emergency numbers, which is a different model and a useful comparison.
Incident response & red teaming: questions
What is Incident response & red teaming?
Incident response & red teaming is Unstrat's Cyber (Cyber & Critical Infrastructure) capability: Incident-response engagements that contain and eradicate live breaches, and red-team operations that rehearse the adversary before one arrives. Delivered by researchers with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems.
How does Incident response & red teaming work?
Incident response & red teaming delivers its effect through Incident-response engagements: containment, eradication, recovery, Red-team operations rehearsing realistic adversaries and Forensics and after-action hardening, capabilities matched to the requirement and confirmed under briefing rather than published.
Who provides Incident response & red teaming?
Incident response & red teaming is delivered by The Cybersecurity Group, whose focus is cyber & critical-infrastructure security. Unstrat represents The Cybersecurity Group to government and enterprise buyers worldwide as an independent, non-aligned prime vendor.
Why choose Incident response & red teaming over a major-power alternative?
Incident response & red teaming is sourced from an independent, non-aligned provider, so it carries no major-power disclosure rules, upgrade-locks or political ramifications. Concretely: responders with responsibly disclosed vulnerabilities across maritime, rail and industrial control systems. The capability is accountable to you, not to a foreign vendor's government and its release schedule.
How is Incident response & red teaming procured, and where can it be delivered?
When the breach is live, the team that arrives has broken into ships, rail systems and payment networks legally, and knows exactly how the adversary thinks. Every engagement begins with a briefing, and export eligibility is confirmed per market under briefing rather than published. Where controlled capabilities are involved, the classification and end-user-certificate chain is confirmed first. Incident response & red teaming is then sustained in-region by one accountable team from briefing through long-term operation.





