NSI Global conducts authorised, threat-informed adversary emulation and red-team exercises using tactics, techniques and procedures relevant to the client’s environment. Scenarios can be mapped to MITRE ATT&CK and may incorporate publicly documented actor behaviour, client threat intelligence and organisation-specific assets, identities and attack paths.
Each engagement defines its objectives, scope, rules of engagement, safety constraints, communication protocols and stop conditions. Exercises test prevention, detection, containment and response across approved digital, physical and social-engineering attack paths.
How This Differs from Traditional Penetration Testing
Penetration testing typically evaluates defined systems or controls. Adversary emulation tests selected tactics, techniques and procedures associated with a defined threat, while red teaming evaluates whether people, processes and technology can prevent, detect and respond to an objective-driven attack within agreed rules of engagement.
Industrial Environments and ICS Testing
ICS and OT testing is separately scoped with the client’s operational personnel. Depending on the environment, testing may use passive review, a laboratory or staging environment or carefully authorised active techniques with defined safety constraints and stop conditions. Active testing of live operational systems is not assumed.
Learn more about our specialised ICS and OT penetration testing.