The shape of the work does not change with the discipline. It is framed, run, evidenced, handed over, then verified — in that order, by the same operator, on a six-week red team and on a two-week pentest alike. What changes is the second phase, and what you are holding at the end of each one.
⬡Five phases
⬡One operator
⬡Five frameworks
// 01 — The loop
What each phase owes you.
A phase is not finished when the time budgeted for it runs out. It is finished when the artifact it exists to produce is in your hands and you can use it without us in the room.
01
Frame
Nothing is touched until the objective, the boundaries and the rules of engagement are written down and signed. That includes what is explicitly out of scope, what counts as a stop condition, and who gets called out of hours. A scope agreed in a meeting is not a scope.
[ you hold ] A signed scope, a named threat model, and a map of what is actually worth reaching.
02
Operate
The one phase that changes with the discipline: emulate a named actor, exploit a defined surface, build the implant, enumerate the identity graph, exercise the detections, probe the model. Work is logged as it happens — timestamped and deconflicted — so your SOC can tell our traffic from someone else's while the engagement is still running.
[ you hold ] A campaign log you can reconcile against your own telemetry, action by action.
03
Evidence
A finding without a reproduction is an opinion. Every one is reproduced end to end and captured — the request, the response, the exact sequence of calls — before it goes near the report. Severity follows blast radius: what the access reaches, not what a scanner scored it.
[ you hold ] A working proof of concept per finding, and the impact argument that ranks it.
04
Hand-off
Remediation written for the team that owns the code: the specific change, the trade-off it carries, and a test that fails if the issue returns. Where a detection is the better control, the rule ships with it, mapped to the technique it fires on and tested against the thing that produced it.
[ you hold ] A fix path per finding and, where it applies, a tested detection in your own format.
05
Verify
We re-run the path against your changes and confirm it is dead, and that nothing opened behind it. A regression re-opens the finding rather than closing the engagement. This is real work and it is quoted separately — pricing it into the engagement window is how verification quietly becomes a re-read of the report.
[ you hold ] A re-test report with verified-closed stated per finding, not per engagement.
Alignment, not accreditation. None of the five below is a certification this practice holds or a body it belongs to. They are the public references the work is structured and reported against, so a finding can be argued in your language and checked against something other than our word for it.
MITRE ATT&CK
Adversary behaviour taxonomy
A public catalogue of what real intrusion sets do, technique by technique, built from observed campaigns rather than from theory.
// how it is usedEvery action in the operate phase carries the technique it implements, and every detection handed over names the technique it fires on. That is what turns coverage into a measured figure instead of an assertion: the heatmap is generated from the tags, not from a claim about them.
PTES
Penetration Testing Execution Standard
The seven-stage baseline for how a test is scoped, executed and reported — the closest thing the field has to an agreed shape for the work.
// how it is usedIt is why the five phases exist in this order. Where procurement asks which recognised methodology an engagement follows, this is the one the scope document and the report structure map to.
TIBER-EU
Threat Intelligence-based Ethical Red Teaming
The European Central Bank's framework for red teaming financial entities against live threat intelligence, adopted by national supervisors across the EU.
// how it is usedIt sets the shape of a red team engagement in a regulated environment: intelligence that names a plausible actor, emulation that stays inside that actor's observed behaviour, and a control team on your side who knows the test is running while the blue team does not.
TLPT
Threat-Led Penetration Testing
The generic name for the class of test TIBER-EU describes, and the term the legislation itself uses.
// how it is usedIt is what a red team engagement becomes once a supervisor will read the output. The practical difference from a standard red team is the evidence burden: the intelligence behind the scenario, the traceability of every action, and the sign-offs are part of the deliverable rather than working notes.
DORA
Digital Operational Resilience Act
The EU regulation applicable since January 2025 that puts ICT risk management and threat-led testing on a statutory footing for financial entities and their critical technology providers.
// how it is usedWhere an engagement exists because of DORA, the scope, the evidence and the retention period are set by what the regulation requires a firm to be able to show — not by what is convenient to test. Reports are structured so the evidence a supervisor asks for is already in them.
None of this makes the practice a TIBER-EU registered provider, an accredited testing body, or a DORA compliance assessor. Where an engagement needs one of those, we say so before scope rather than after it.
Scope it before you buy it.
Describe what you need proven and we come back with a threat model, a proposed scope and a price. A mutual NDA precedes any technical discussion.