Skip to main content

Anyone can red-team an office network. Very few will do it to a ship that is under way.

Mandiant runs the best-documented red-team methodology on the market and Unit 42 sells offensive work inside a retainer. Neither publishes a track record on vessels, rail or 5G core network functions, which is exactly where our findings come from.

In service, not experimental

Our offensive work is conducted against live production environments rather than test copies, from vessels at sea to payment networks, under strict legal and governance controls. The research behind it has been responsibly disclosed across maritime, rail and industrial control systems, including two CVEs on the US NIST register and findings up to CVSS 10.0 in production fleets.

Side by side

AttributeRepresented by UnstratOffensive cybersecurityMandiant (Google Cloud)Red Team Assessment1United StatesUnit 42 (Palo Alto Networks)Unit 42 Retainer (offensive services)2United States
Engagement model12Red-team engagements and adversary simulation against live production environments, with every finding fed back into defensive platformsA realistic attack scenario using any non-destructive methods necessary to reach a set of jointly agreed mission objectivesOffensive work purchased with retainer credits: penetration testing, purple-team exercises, attack-surface assessment and tabletop exercises
Environments attacked12Live production, including vessels at sea and payment networks, plus rail and industrial control systemsEnterprise environments. Sample objectives include breaking into a segmented environment holding business-critical data and taking control of an automated device such as an IoT, medical or manufacturing deviceNot specified in the retainer datasheet
Published research output12Responsible disclosures across maritime, rail and ICS; two CVEs credited on the US NIST register; findings up to CVSS 10.0 in production fleetsNot published as a disclosure count in this datasheet; cites frontline experience since 2004Not published as a research count; cites more than 1,000 incident-response investigations each year
Method12Specification-driven threat modelling and penetration testing, down to individual 5G network functions built from the 3GPP specificationFull attack lifecycle: reconnaissance using proprietary intelligence and OSINT, initial access by exploitation or social engineering, privilege escalation, persistence and command and control, then objective completionNot published in the retainer datasheet
Deliverables12Mandiant's published deliverables list is more specific than ours and a procurement team will notice.Not published as a deliverables listExecutive summary, technical detail with step-by-step reproduction, fact-based risk analysis, plus tactical and strategic recommendationsNot published in the retainer datasheet
Governance and safety controls12Conducted under strict legal and governance controlsNon-destructive methods only, against objectives agreed jointly with the client before the engagementPre-negotiated contract terms and predetermined service-level agreements set before an engagement begins
Commercial model12Not publishedNot published in this datasheetPrepaid credits at four tiers: 250, 550, 1,250 and 2,500+, spendable across assessment, response and advisory services
Feedback into defence12Every finding feeds our own defensive platforms, which are in service across grids, finance and fleetsRecommendations for improvement; the assessment tests whether your own detection and response teams can respondCredits can be redirected into security programme design, zero-trust advisory and IR plan development
Origin and political exposure12For a red team, origin is not an abstract concern. The engagement produces a complete map of how to compromise your national infrastructure.Independent, non-aligned origin, with no political exposure to any major-power ecosystemUnited States (Google Cloud)United States (Palo Alto Networks)

Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.

What the table means

The deliverable of a red team is a compromise map of your country

A finished red-team report tells the reader exactly which door opened, which credential escalated, and how far into the estate the team travelled before anyone noticed. That document is more useful to a hostile service than anything an intruder could assemble unaided. Mandiant and Unit 42 produce excellent versions of it, and both sit inside large US corporate groups. If the target is a national payment network, a port or a 5G core, the buyer should be asking who else can lawfully compel a copy, and should treat the answer as part of the technical evaluation rather than a legal footnote.

Production systems that cannot be paused

Mandiant's sample objectives include taking control of an automated device such as an IoT, medical or manufacturing device, which is a serious statement of intent. Our environments add ones that move: a vessel under way, a rail signalling estate, a payment network mid-settlement. Nothing in those can be rebooted for the tester's convenience, which changes the technique, the safety case and the governance around it. Our CVSS 10.0 findings came out of production fleets, not a laboratory replica.

Where the competitors are ahead of us on paper

Unit 42 publishes tiered credits, so a buyer knows what they are committing to before the first call. Mandiant publishes an itemised deliverables list, down to step-by-step reproduction instructions. We publish neither, and a procurement officer scoring the responses will mark us down for it. Those are documentation gaps rather than capability gaps, and we would rather say so than pad the page.

Questions buyers ask

Who can red-team a ship or a maritime OT network?

Very few teams will touch a vessel that is under way, because the safety case is real and the systems cannot be reset. We do, and the research that came out of it has been responsibly disclosed across maritime, rail and ICS, with two CVEs credited on the US NIST register and findings up to CVSS 10.0 in production fleets. Mandiant's published sample objectives include taking control of automated and IoT devices, which is the closest documented parallel from a major vendor, but its datasheet describes enterprise environments rather than ships.

What is the difference between a penetration test and a red-team assessment?

A penetration test looks for as many vulnerabilities as possible in a defined scope. A red-team assessment picks a small number of objectives that matter to the business and tries to reach them by any non-destructive route, which is how Mandiant frames its engagement. The second one tests your defenders as much as your systems. Unit 42 sells both as separate line items against retainer credits, which is a useful way to think about the distinction commercially.

How do you red-team a 5G core network?

By building the threat model from the specification rather than from a scanner. We work down to individual 5G core network functions derived from the 3GPP specification, which is how you find logic and interface flaws that a generic penetration test will walk straight past. Palo Alto's 5G-native security material catalogues sixteen use cases across core, RAN, roaming, slicing and MEC, and it is a good checklist for the surface area a serious assessment has to cover.

Is it safe to run offensive testing against live production systems?

Only with governance that is agreed before anyone touches a keyboard. Mandiant states non-destructive methods against jointly agreed objectives. We work under strict legal and governance controls with the same principle: the client sets what is out of bounds, and the safety case for a moving vessel or a settlement window is written first. Anyone offering to test live critical infrastructure without that conversation should be declined.

Sources

  1. 1. Mandiant (Google Cloud), Red Team Assessment (datasheet, M-EXT-DS-US-EN-000015-07) (copy held on this site)Retrieved: 2026-07-31 · Engagement structure, sample mission objectives and the deliverables list.
  2. 2. Unit 42 (Palo Alto Networks), Unit 42 Retainer (datasheet, unit42_ds_unit-42-retainer_100424) (copy held on this site)Retrieved: 2026-07-31 · Four retainer tiers with prepaid credits and remote response SLAs, the service catalogue credits can be spent on, and the insurance-panel statement.
  3. 3. Palo Alto Networks, 5G-Native Security (at a glance, 2022) (copy held on this site)Retrieved: 2026-07-31 · The sixteen numbered 5G security use cases and the mapping of each to ML-Powered NGFW for 5G, Prisma Cloud, Cortex XSOAR and Cortex Xpanse.
Next step on this comparison

Send us the requirement and the systems you are weighing. We will map this table onto it.