Skip to main content
Offensive cybersecurity, Cyber (Cyber & Critical Infrastructure), Unstrat

Offensive cybersecurity

Red-team and assessment

Overview

Authorised offensive security: red-team engagements against live production environments, from vessels at sea to payment networks, that expose weaknesses before adversaries do. Backed by vulnerability research responsibly disclosed across maritime, rail and industrial control systems, under strict legal and governance controls.

Offensive work is defined by what it is allowed to touch and what happens when it goes wrong, not by how clever the exploit is. Authorised offensive capability under your governance, never a foreign service's: the scope, the targets and the record all answer to you.

Unstrat represents this capability to a market only once classification and the end-user-certificate chain are confirmed. Full specifications are shared under briefing.

Capabilities

  • Scoping before shooting. A red-team engagement starts by deciding what is being tested and why: which systems, which business or mission outcome the adversary is chasing, and what the engagement is deliberately not allowed to touch. A vague scope produces a vague finding and an avoidable outage, so the boundary is drawn before anyone touches a keyboard
  • Rules of engagement in writing. Before an engagement runs, both sides agree the timing, the permitted techniques, the escalation path and the stop conditions, and who has authority to call a halt. Testing live production, from a vessel at sea to a payment network, means an accidental disruption is a real event, so the rules exist to keep the exercise from becoming the incident
  • Authorised-target discipline. Work stays inside the agreed target list. Systems that are out of scope, and third parties that were never party to the authorisation, are not touched, because reaching them would be neither legal nor useful. That discipline is the difference between a red team and an intruder
  • Adversary simulation for organisations that need to understand their real attack surface, played to a defined objective rather than a scattergun sweep, so the finding maps to how a real attacker would actually come at them
  • Vulnerability research responsibly disclosed across maritime, rail and industrial control systems: CVSS 10.0 vulnerabilities discovered in production fleets, research credited on the US NIST register (2 CVEs)
  • Specification-driven threat modelling and penetration testing, down to 5G network functions built from the 3GPP spec, with every finding written up to feed the defensive platforms rather than sit in a report

Specifications

TypeOffensive / red-team
EnvironmentsLive production, vessels to payment networks
ResearchAvailable under controlled technical briefing
DepthAvailable under controlled technical briefing
GovernanceStrict legal controls
OriginIndependent / non-aligned

In depth

The target is defined before the test

Offensive work is useful only when the buyer knows what is being tested and what the test is allowed to touch. An engagement begins with the target list, the mission or business outcome under examination, and the systems deliberately excluded. Timing, permitted techniques, escalation, stop conditions and the people who can halt the exercise are agreed in writing before activity starts. That discipline matters when the environment is live. The catalogue names vessels at sea and payment networks as examples of production environments where an accidental disruption would be an operational event. Out-of-scope systems and third parties that never authorised the work remain untouched. Authorisation is not a decorative preface. It defines the boundary between adversary simulation and an intrusion.

A red-team operator working through code and network diagrams during an authorised engagement.
A red-team operator working through code and network diagrams during an authorised engagement.

Research informs the attack model

The service combines red-team work with vulnerability research responsibly disclosed across maritime, rail and industrial control systems. The catalogue records two CVEs credited on the US NIST register and research findings up to CVSS 10.0. It also describes specification-driven threat modelling and penetration testing down to 5G network functions built from the 3GPP specification. Those facts give the assessment a concrete research basis. The exercise is designed around a defined adversary objective rather than a scattergun sweep, and each finding is written so it can feed defensive platforms instead of ending as an isolated report. The result is an examination of the attack surface in the conditions where the system actually operates.

The record belongs to the buyer

The catalogue classifies the capability as offensive and red-team work in live production, with strict legal controls and independent, non-aligned origin. That combination describes more than a penetration-test technique. It covers governance, authorised targets, research depth and the handling of what the engagement uncovers. The related incident-response capability addresses containment, eradication, recovery and after-action hardening when a real breach occurs. Defensive cybersecurity uses the findings to strengthen layered monitoring and response. In that chain, offensive testing has a defined job: expose weaknesses before an adversary does, while the scope, targets and record remain accountable to the buyer rather than to a foreign service.

A war-room whiteboard mapping attack paths across a client's live systems.
A war-room whiteboard mapping attack paths across a client's live systems.

Why Unstrat: the difference

Unstrat is the authorised global representative and distributor for this capability. It is already in service with a track record behind it, so you are buying something that has done the job elsewhere, not funding a first attempt. You are not the test bed.

01

Independent, non-aligned origin, with no political exposure to any major-power ecosystem.

02

One accountable team from first briefing through delivery and in-region sustainment.

03

Red-teams live production environments, from vessels at sea to payment networks, under scope and rules of engagement agreed in writing first.

How it reaches you

Independent maker
Non-aligned manufacturer
Unstrat
Single accountable channel
End user
Government or enterprise buyer
In-region sustainment · training · classification & end-use governance

Related capability

View all
See use cases for Offensive cybersecurity

Procurement & sustainment

Classification & EUC

Classification and the end-user-certificate chain are confirmed before this capability is represented to your market.

Non-aligned origin

Sourced from an independent manufacturer: no major-power disclosure rules or political conditions.

One accountable channel

A single team responsible from first briefing through delivery: not a chain of foreign primes to integrate yourself.

In-region sustainment

Lifecycle support and operator training delivered in-region, building capability that outlasts the initial deployment.

Applications it supports

Capability comparisons

Questions buyers ask

What is offensive cybersecurity?

Authorised attack on your own systems, conducted the way a real adversary would, to find what the defences missed. It is commissioned by the defender and governed by written authority, scope and rules of engagement. Our engagements run against live production environments, from vessels at sea to payment networks, under strict legal and governance controls.

See: Offensive cybersecurityOffensive vs defensive security

Best red team providers

Mandiant publishes the clearest red-team methodology on the market, running a full attack lifecycle against jointly agreed mission objectives, and Unit 42 sells offensive work through retainer credits. Both are strong in enterprise IT. Neither publishes a track record on vessels, rail signalling or 5G core network functions, which is where our findings come from.

See: Against Mandiant and Unit 42

Penetration testing vs red teaming

A penetration test enumerates weaknesses in a defined scope; a red team pursues an objective and will use whatever authorised path reaches it, including people and process. Mandiant frames its assessment around agreed mission objectives such as reaching a segmented environment or taking control of an automated device. We run both, and our threat modelling is specification-driven, down to individual 5G network functions built from the 3GPP specification.

See: Red teaming in the catalogueThe offensive capability page

Is offensive cybersecurity legal?

When properly authorised, yes. Legitimate offensive security operates under explicit written authority, agreed scope and governance controls, which is what separates adversary emulation from an offence. All our offensive work is conducted under strict legal and governance controls, with the client setting what is out of bounds before the engagement starts.

See: Governance in the comparison

Red team assessment for a shipping company

Very few teams will attack a ship that is under way, and fewer still know what can be isolated without stopping it. Our offensive work covers live production environments including vessels at sea, and the research behind it has been responsibly disclosed across maritime, rail and industrial control systems. Findings in production fleets have reached CVSS 10.0, the maximum severity rating available.

See: Offensive cybersecurityMaritime cybersecurity

How do you red team a 5G core network?

By building the threat model from the specification rather than from a scanner. We work down to individual 5G core network functions derived from the 3GPP specification, which is how logic and interface flaws surface that a generic penetration test walks straight past. Palo Alto's public 5G material catalogues sixteen use cases across core, RAN, roaming, slicing and MEC, and it is a fair checklist for the surface a serious assessment has to cover.

See: Telecom and 5G network securityMethod compared with Mandiant and Unit 42

Adversary simulation against industrial control systems

ICS work is judged on restraint as much as on access, because the same technique that proves a point can trip a process. Our disclosures span maritime, rail and industrial control systems, including two CVEs credited on the US NIST register. Mandiant's sample objectives include taking control of an automated device such as an IoT, medical or manufacturing device, which is adjacent but not the same estate.

See: IT and OT security comparedOT security capability

How often should critical infrastructure be red teamed?

Treat it as a cycle rather than an event: the red team attacks, the findings drive hardening, the defence improves, the next engagement probes deeper. Critical estates typically test at least annually and after significant system changes, and the follow-through matters more than the cadence. Our findings feed straight into the defensive platforms we run, which is how the loop closes.

See: The attack and defend cycleDefensive cybersecurity

What does a red team engagement cost and how is it priced?

We do not publish a commercial model, and any figure quoted before scoping is a guess. For reference, Unit 42 publishes four tiers of prepaid credits at 250, 550, 1,250 and 2,500 or more, spendable across offensive and response services. Ask us for a written scope and price against your estate rather than a rate card.

See: Commercial models compared

Is it safe to run offensive testing against systems that are actually in service?

Only with governance agreed before anyone touches a keyboard. Mandiant commits to non-destructive methods against jointly agreed objectives, and we work to the same principle under strict legal controls, with the client setting what is out of bounds. For a moving vessel or a settlement window, the safety case is written first. Any supplier willing to test live critical infrastructure without that conversation should be declined.

See: Offensive cybersecurityGovernance and method, side by side

Who will red team our national systems without their government reading the report?

Ask the question directly and get the answer into the contract, because a red-team report is a map of how to defeat a national system. Mandiant sits inside Google Cloud and Unit 42 inside Palo Alto Networks, both United States groups. We are independent and non-aligned, with no political exposure to a major-power ecosystem and no third government with standing to ask us for a copy.

See: Origin and exposure

How do we know a red team is any good before we hire them?

Look at what they have found, not at how they describe their methodology. Our record is responsible disclosure across maritime, rail and industrial control systems, two CVEs credited on the US NIST register and findings up to CVSS 10.0 in production fleets. Mandiant cites frontline experience since 2004 and Unit 42 more than 1,000 incident-response investigations a year, which are different kinds of evidence and worth weighing on their own terms.

See: Published research output, compared

Our regulator wants proof our defences work, not another vulnerability scan. What satisfies that?

A demonstrated attack path, with the detection record showing what your team saw and when. That is what an objective-driven engagement produces, and it is why the findings command budget in a way a scan report never does. We run those engagements against live production and feed every finding into hardening, so the follow-up work is evidenced too.

See: Offensive cybersecurityWhy one discipline needs the other

What happens to the report and the tooling after a red team engagement ends?

Settle it in the contract, because by the end of the work the team holds an accurate account of how your estate can be defeated. We publish that our engagements run under strict legal and governance controls and that findings feed our defensive platforms; the detailed handling and retention terms are agreed per engagement. Ask every bidder the same question in writing and compare the answers rather than the marketing.

See: What we publish and what we do not

Should the same firm run our red team and our security operations?

There is a fair argument both ways. Separation protects the independence of the report; combination gives you defenders who know exactly where the estate broke last quarter. We deliberately run both from one team, which is why our defensive operations are continuously hardened by our own offensive findings. If your governance demands separation, say so at scoping and we will structure it accordingly.

See: Defensive cybersecurityIncident response and red teaming

Offensive cybersecurity: questions

What is Offensive cybersecurity?

Offensive cybersecurity is Unstrat's Cyber (Cyber & Critical Infrastructure) capability: Authorised offensive security: red-team engagements against live production environments, from vessels at sea to payment networks, that expose weaknesses before adversaries do. Backed by vulnerability research responsibly disclosed across maritime, rail and industrial control systems, under strict legal and governance controls.

How does Offensive cybersecurity work?

Offensive cybersecurity delivers its effect through scoping before shooting. A red-team engagement starts by deciding what is being tested and why: which systems, which business or mission outcome the adversary is chasing, and what the engagement is deliberately not allowed to touch. A vague scope produces a vague finding and an avoidable outage, so the boundary is drawn before anyone touches a keyboard, Rules of engagement in writing. Before an engagement runs, both sides agree the timing, the permitted techniques, the escalation path and the stop conditions, and who has authority to call a halt. Testing live production, from a vessel at sea to a payment network, means an accidental disruption is a real event, so the rules exist to keep the exercise from becoming the incident and Authorised-target discipline. Work stays inside the agreed target list. Systems that are out of scope, and third parties that were never party to the authorisation, are not touched, because reaching them would be neither legal nor useful. That discipline is the difference between a red team and an intruder, capabilities matched to the requirement and confirmed under briefing rather than published.

Who provides Offensive cybersecurity?

Offensive cybersecurity is delivered by The Cybersecurity Group, whose focus is cyber & critical-infrastructure security. Unstrat represents The Cybersecurity Group to government and enterprise buyers worldwide as an independent, non-aligned prime vendor.

Who uses Offensive cybersecurity?

Government and enterprise buyers acquire Offensive cybersecurity to address cyber attacks on government across the cyber & critical infrastructure, matched to the mission and accountable to them, not to a foreign vendor's government.

Why choose Offensive cybersecurity over a major-power alternative?

Offensive cybersecurity is sourced from an independent, non-aligned provider, so it carries no major-power disclosure rules, upgrade-locks or political ramifications. Concretely: Red-teams live production environments, from vessels at sea to payment networks, under scope and rules of engagement agreed in writing first. The capability is accountable to you, not to a foreign vendor's government and its release schedule.

How is Offensive cybersecurity procured, and where can it be delivered?

Offensive work is defined by what it is allowed to touch and what happens when it goes wrong, not by how clever the exploit is. Authorised offensive capability under your governance, never a foreign service's: the scope, the targets and the record all answer to you. Every engagement begins with a briefing, and export eligibility is confirmed per market under briefing rather than published. Where controlled capabilities are involved, the classification and end-user-certificate chain is confirmed first. Offensive cybersecurity is then sustained in-region by one accountable team from briefing through long-term operation.

Contact us

Tell us the requirement. Specifications and the export position are confirmed in briefing, not published here.