Red Team
testing · vulnerability managementKnow what an attacker would find before they do. Every finding proven, so your team works a short list.
Anyone can hand you a scan. The work is proving which findings an attacker could actually use, then retesting to show they are closed. No open port, no hardware to buy.
How it works
Scope, discover, validate, report, retest.
Written authorization, agreed targets, anything explicitly excluded, and a schedule around instruction.
Every device on the network found and fingerprinted, including the ones nobody remembers.
Internal and external testing, with and without credentials. Exploitability confirmed without destructive techniques.
A posture score, a board summary, technical detail for IT, and a retest to prove each finding is closed.
Inside Red Team
Two reports from one assessment.
Page one is for the board and reads like English. Page two is for your team and reads like a work order. Both come from the same validated findings.
Page 1 of 2
up from 71
11 validated findings from 318 raw. The other 307 were false positives or duplicates, and are listed in the appendix so nobody chases them.
What matters most
- A student laptop on the Wi-Fi can reach the server that holds every password. Fix: separate the student network. Two days of work.
- The VPN box is missing a patch attackers are using right now. Fix: update it this week.
- The heating system still has the factory password. Fix: change it. Ten minutes.
VPN appliance unpatched
- Where
- Network edge,
vpn.district.k12.tn.us - Evidence
- Version banner and a safe check confirm the vulnerable build. No exploit was run.
- Reproduce
- Three steps, documented for your team only.
- Fix
- Update to the current build; restrict the admin page to the management network.
- Retest
- Booked for 18 Sep
- HVAC default credentials — fixed 21 Aug
- Exposed RDP on admin VLAN — fixed 28 Aug
- Stale domain admin accounts (6) — fixed 3 Sep
- SMBv1 on 41 hosts — retest booked
What is included
What we test, and how we prioritise it.
Complete asset discovery
Every host inventoried and scored by real risk, so you can see where exposure concentrates.
Internal and external
What the internet can see, and what an attacker already inside would see.
Web applications and portals
District websites, parent portals and internally hosted applications assessed.
Credential and configuration review
Weak passwords, default credentials, legacy protocols, unnecessary exposure.
Actively-exploited flagging
Findings under active attack in the wild are pushed to the top of your list.
Point-in-time, recurring, or continuous
One assessment for a renewal, or an ongoing program with tracking to closure.
What you get to keep
Reports that work for two audiences.
Board summary
What was found, what it means, what it will take. No jargon.
Technical detail for IT
Reproduction steps and remediation for every validated finding.
Retest certificate
Proof each finding is closed, dated, for your insurer or auditor.
Questions districts ask
Before you call
Do we have to open a port or buy hardware?
No. Testing runs from a small appliance that only talks outbound. Nothing inbound, nothing to purchase.
Will it disrupt instruction?
No. Scope is agreed in writing, destructive techniques are never used, and testing is scheduled around the school day and testing weeks.
What does the report look like?
Two documents: a board-level summary and a technical report for your team, plus a posture score you can track between assessments.
How is it priced?
Fixed, in writing, by scope. Point-in-time, recurring, or continuous.
Get started
Tell us what you are being asked to prove.
An insurance renewal, a state review, a board question. We will tell you which program answers it, or that none of them do. Straight answer, fixed quote, from the engineer who would do the work.
Reply within one business day. No sales sequence, no mailing list.
