Offensive cybersecurity: use cases
The weaknesses are best found by the defender's own side before an adversary finds them, and best done under the buyer's governance rather than a foreign service's. The Cybersecurity Group runs red-team engagements against live production environments, from vessels at sea to payment networks, backed by vulnerability research responsibly disclosed across maritime, rail and industrial control systems. Offensive work is defined by what it is allowed to touch and what happens when it goes wrong, not by how clever the exploit is. Its researchers have found flaws rated at the top of the severity scale in production fleets and hold entries on the US NIST register. Every engagement runs under strict legal and governance controls, accountable to the buyer alone, and every finding feeds the defensive platforms rather than sitting in a report.
Where it is used
A red-team engagement starts by deciding what is being tested and why: which systems, which mission or business outcome the adversary is chasing, and what the engagement is deliberately not allowed to touch. A vague scope produces a vague finding and an avoidable outage, so the boundary is drawn before anyone touches a keyboard. Work stays inside the agreed target list, and systems out of scope or third parties never party to the authorisation are not touched, because reaching them would be neither legal nor useful. That authorised-target discipline is precisely the difference between a red team and an intruder, and it is what makes the exercise defensible afterwards.
Before an engagement runs, both sides agree the timing, the permitted techniques, the escalation path, the stop conditions and who has authority to call a halt. Testing live production, from a vessel under way to a settlement window, means an accidental disruption is a real event, so the rules exist to keep the exercise from becoming the incident. Very few teams will attack a ship at sea, and fewer still know what can be isolated without stopping it. Any supplier willing to test live critical infrastructure without that conversation should be declined, because the safety case for a moving vessel or a payment network is written first, not improvised.
Threat modelling and penetration testing can go down to the specification itself, including individual 5G core network functions built from the 3GPP standard. Building the threat model from the specification rather than from a scanner is how logic and interface flaws surface that a generic penetration test walks straight past. A penetration test enumerates weaknesses in a defined scope; a red team pursues an objective and will use whatever authorised path reaches it, including people and process. Both are run here, and the depth of the research behind them, disclosures across maritime, rail and industrial control systems, is what makes the emulation reflect how these environments actually break.
Industrial control work is judged on restraint as much as on access, because the same technique that proves a point can trip a process. Disclosures span maritime, rail and industrial control systems, including CVEs credited on the US NIST register and findings that have reached the maximum severity rating available in production fleets. The way to judge a red team before hiring is to look at what it has found rather than how it describes its methodology, because a disclosure record against real systems is evidence and a polished method statement is not. Frontline breadth and deep research are different kinds of evidence, each worth weighing on its own terms.
Every finding from an offensive engagement is fed back into the defensive platforms, so an attack proven once becomes a defence maintained thereafter. Assessment is not a report that gathers dust; it is the input that keeps the protection honest. Offensive testing and defensive operations are two sides of one discipline, and procuring both through one accountable channel means the testing feeds the defence rather than sitting in a separate contractor's report. Critical estates typically test at least annually and after significant system changes, but the follow-through matters more than the cadence: the red team attacks, the findings drive hardening, the next engagement probes deeper.
A red-team report is a map of how to defeat a national system, so the question of who else can read it belongs in the contract rather than in an assumption. A tester learns exactly where the bodies are buried, which is why many states hesitate to let a foreign-aligned firm rehearse attacks on their most sensitive systems. This capability is independent and non-aligned, with no political exposure to a major-power ecosystem and no third government with standing to ask for a copy; findings never travel further than the buyer decides. A commercial model is not published, because any figure quoted before a written scope against the actual estate is a guess.

