Anyone can red-team an office network. Very few will do it to a ship that is under way.
Mandiant runs the best-documented red-team methodology on the market and Unit 42 sells offensive work inside a retainer. Neither publishes a track record on vessels, rail or 5G core network functions, which is exactly where our findings come from.
Our offensive work is conducted against live production environments rather than test copies, from vessels at sea to payment networks, under strict legal and governance controls. The research behind it has been responsibly disclosed across maritime, rail and industrial control systems, including two CVEs on the US NIST register and findings up to CVSS 10.0 in production fleets.
Side by side
| Attribute | Represented by UnstratOffensive cybersecurity | Mandiant (Google Cloud)Red Team Assessment1United States | Unit 42 (Palo Alto Networks)Unit 42 Retainer (offensive services)2United States |
|---|---|---|---|
| Engagement model12 | Red-team engagements and adversary simulation against live production environments, with every finding fed back into defensive platforms | A realistic attack scenario using any non-destructive methods necessary to reach a set of jointly agreed mission objectives | Offensive work purchased with retainer credits: penetration testing, purple-team exercises, attack-surface assessment and tabletop exercises |
| Environments attacked12 | Live production, including vessels at sea and payment networks, plus rail and industrial control systems | Enterprise environments. Sample objectives include breaking into a segmented environment holding business-critical data and taking control of an automated device such as an IoT, medical or manufacturing device | Not specified in the retainer datasheet |
| Published research output12 | Responsible disclosures across maritime, rail and ICS; two CVEs credited on the US NIST register; findings up to CVSS 10.0 in production fleets | Not published as a disclosure count in this datasheet; cites frontline experience since 2004 | Not published as a research count; cites more than 1,000 incident-response investigations each year |
| Method12 | Specification-driven threat modelling and penetration testing, down to individual 5G network functions built from the 3GPP specification | Full attack lifecycle: reconnaissance using proprietary intelligence and OSINT, initial access by exploitation or social engineering, privilege escalation, persistence and command and control, then objective completion | Not published in the retainer datasheet |
| Deliverables12Mandiant's published deliverables list is more specific than ours and a procurement team will notice. | Not published as a deliverables list | Executive summary, technical detail with step-by-step reproduction, fact-based risk analysis, plus tactical and strategic recommendations | Not published in the retainer datasheet |
| Governance and safety controls12 | Conducted under strict legal and governance controls | Non-destructive methods only, against objectives agreed jointly with the client before the engagement | Pre-negotiated contract terms and predetermined service-level agreements set before an engagement begins |
| Commercial model12 | Not published | Not published in this datasheet | Prepaid credits at four tiers: 250, 550, 1,250 and 2,500+, spendable across assessment, response and advisory services |
| Feedback into defence12 | Every finding feeds our own defensive platforms, which are in service across grids, finance and fleets | Recommendations for improvement; the assessment tests whether your own detection and response teams can respond | Credits can be redirected into security programme design, zero-trust advisory and IR plan development |
| Origin and political exposure12For a red team, origin is not an abstract concern. The engagement produces a complete map of how to compromise your national infrastructure. | Independent, non-aligned origin, with no political exposure to any major-power ecosystem | United States (Google Cloud) | United States (Palo Alto Networks) |
Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.
What the table means
The deliverable of a red team is a compromise map of your country
A finished red-team report tells the reader exactly which door opened, which credential escalated, and how far into the estate the team travelled before anyone noticed. That document is more useful to a hostile service than anything an intruder could assemble unaided. Mandiant and Unit 42 produce excellent versions of it, and both sit inside large US corporate groups. If the target is a national payment network, a port or a 5G core, the buyer should be asking who else can lawfully compel a copy, and should treat the answer as part of the technical evaluation rather than a legal footnote.
Production systems that cannot be paused
Mandiant's sample objectives include taking control of an automated device such as an IoT, medical or manufacturing device, which is a serious statement of intent. Our environments add ones that move: a vessel under way, a rail signalling estate, a payment network mid-settlement. Nothing in those can be rebooted for the tester's convenience, which changes the technique, the safety case and the governance around it. Our CVSS 10.0 findings came out of production fleets, not a laboratory replica.
Where the competitors are ahead of us on paper
Unit 42 publishes tiered credits, so a buyer knows what they are committing to before the first call. Mandiant publishes an itemised deliverables list, down to step-by-step reproduction instructions. We publish neither, and a procurement officer scoring the responses will mark us down for it. Those are documentation gaps rather than capability gaps, and we would rather say so than pad the page.
Questions buyers ask
Who can red-team a ship or a maritime OT network?
Very few teams will touch a vessel that is under way, because the safety case is real and the systems cannot be reset. We do, and the research that came out of it has been responsibly disclosed across maritime, rail and ICS, with two CVEs credited on the US NIST register and findings up to CVSS 10.0 in production fleets. Mandiant's published sample objectives include taking control of automated and IoT devices, which is the closest documented parallel from a major vendor, but its datasheet describes enterprise environments rather than ships.
What is the difference between a penetration test and a red-team assessment?
A penetration test looks for as many vulnerabilities as possible in a defined scope. A red-team assessment picks a small number of objectives that matter to the business and tries to reach them by any non-destructive route, which is how Mandiant frames its engagement. The second one tests your defenders as much as your systems. Unit 42 sells both as separate line items against retainer credits, which is a useful way to think about the distinction commercially.
How do you red-team a 5G core network?
By building the threat model from the specification rather than from a scanner. We work down to individual 5G core network functions derived from the 3GPP specification, which is how you find logic and interface flaws that a generic penetration test will walk straight past. Palo Alto's 5G-native security material catalogues sixteen use cases across core, RAN, roaming, slicing and MEC, and it is a good checklist for the surface area a serious assessment has to cover.
Is it safe to run offensive testing against live production systems?
Only with governance that is agreed before anyone touches a keyboard. Mandiant states non-destructive methods against jointly agreed objectives. We work under strict legal and governance controls with the same principle: the client sets what is out of bounds, and the safety case for a moving vessel or a settlement window is written first. Anyone offering to test live critical infrastructure without that conversation should be declined.
Sources
- 1. Mandiant (Google Cloud), Red Team Assessment (datasheet, M-EXT-DS-US-EN-000015-07) (copy held on this site)Retrieved: 2026-07-31 · Engagement structure, sample mission objectives and the deliverables list.
- 2. Unit 42 (Palo Alto Networks), Unit 42 Retainer (datasheet, unit42_ds_unit-42-retainer_100424) (copy held on this site)Retrieved: 2026-07-31 · Four retainer tiers with prepaid credits and remote response SLAs, the service catalogue credits can be spent on, and the insurance-panel statement.
- 3. Palo Alto Networks, 5G-Native Security (at a glance, 2022) (copy held on this site)Retrieved: 2026-07-31 · The sixteen numbered 5G security use cases and the mapping of each to ML-Powered NGFW for 5G, Prisma Cloud, Cortex XSOAR and Cortex Xpanse.
