ANOMAL service

Red team assessment: detection and response under realistic load

A red team assessment is a goal-based, multi-week attack simulation against the entire detection and response chain, not against a narrow scope. The output is not a vulnerability list but an evidence-backed statement about what SOC, EDR, identity and cloud controls stop together. ANOMAL runs red team engagements using MITRE ATT&CK with a methodology based on TIBER-EU. For systemically important institutions, FINMA considers red-teaming exercises a required part of cyber exercises (supervisory notice 03/2024) and names frameworks such as TIBER-EU and CBEST.

All

What a red team is and is not

A red team attacks specific objectives. It asks whether an attacker can reach objective Y within X weeks without the SOC stopping them. Objectives include payment initiation, crown-jewel data and domain admin access. The team chooses the scope and attack paths, mirroring a real attacker. This distinguishes the exercise from a pentest, which checks whether systems within a defined scope are exploitable.

Red team tests people and processes too

Unlike a pentest, a red team also evaluates analysts' responses, playbooks, escalation paths and communication with executive leadership. Endpoint or cloud findings form part of this wider assessment. For a comparison, see [Penetration testing Switzerland](/en/services/penetration-testing-switzerland).

Engagement types

TypeObjectiveWhen it fits
Full red teamNo blue-team foreknowledge, realistic attacker, goal-based.When the claim 'our SOC catches attacks' needs hard evidence.
Assumed breachAttack starts from a compromised endpoint or account.When lateral movement and detection matter more than initial access.
Purple teamRed and blue collaborate openly and tune detection rules live.After a full red team, to convert findings into rules.
TIBER-EU-oriented exerciseThreat-intelligence-led, regulator-ready report, methodology based on TIBER-EU.Regulated financial institutions with FINMA / DORA expectations. For systemically important institutions, FINMA considers red-teaming exercises a required part of cyber exercises (supervisory notice 03/2024) and names frameworks such as TIBER-EU and CBEST.

How an ANOMAL red team engagement runs

  1. Objective workshop with executive leadership: which assets constitute 'winning', what rules apply (time windows, blackout, communication).
  2. Threat-intelligence build-up: which attacker profiles are realistic for the sector, which TTPs (MITRE ATT&CK) will be used.
  3. Operational phase over several weeks: initial access, persistence, lateral movement, objective achievement, continuous OpSec.
  4. Controlled white-cell channel: a small named group knows about the exercise and stops it if real risks arise; everyone else treats events as real.
  5. Reporting: executive summary with objective outcome, attack timeline, detection gaps, concrete rule and process recommendations.
  6. Optional purple team phase: convert observed paths into detection rules and anchor them in the SOC.

If the team discovers a real compromise during the exercise, it follows the same process as for a real incident. See Incident Response 72h. The team pauses or aborts the exercise in that case.

How this compares to pentest, bug bounty and tabletop

ActivityQuestionWhat it does not cover
PentestIs scope X exploitable?Statement on SOC reaction and playbook effectiveness.
Bug bountyWhat do external researchers find on publicly exposed assets?Systematic attack chains, targeted objective achievement, detection evaluation.
Red teamHow far does a realistic attacker get before we stop them?Broad compliance evidence (use audit or certification for this).
TabletopHow does the organisation react to a planned scenario?Technical reality of the attack chain, real detection latencies.

A red team replaces neither pentest nor SOC. It is the maturity exercise once both are in place. Without an established SOC with detection content the yield is low because almost everything gets flagged. Detection latencies across the SOC chain (see MTTD and MTTR in a SOC) are the actual yardstick. For the broader framework, see SOC as a Service Switzerland.

Frequently asked questions

When does a red team make sense?

A red team makes sense once a SOC has run for at least six to twelve months. The organisation should have established detection content and a standard pentest cycle. Before that, the exercise yields little because basic gaps limit the findings' value.

How long does a red team engagement take?

An engagement typically involves four to eight weeks of operations, plus two weeks of preparation and two weeks of reporting. Shorter formats are possible but lose realism because OpSec and persistence take time.

Who in our organisation may know about it?

A small white cell knows about the exercise, typically two to four people including the CISO and sponsor. Everyone else, SOC analysts included, treats events as real. Only that makes the reaction meaningful.

Does a red team satisfy cyber-insurance requirements?

A red team cannot replace baseline controls. Insurers recognise a red team report as strong evidence of maturity, and it often reduces premiums, especially for regulated institutions. For an overview of requirements, see [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland).

What happens to evidence and access after the engagement?

The team removes or disables all persistence mechanisms, access and accounts it created, following a documented chain of custody. It hands over or deletes artefacts according to customer instructions. This is a standard part of the playbook.

Continue reading in this cluster
Penetration testing Switzerland: find attack surfaces before attackers do
A penetration test is a targeted attack simulation against defined systems, carried out by Swiss testers using a documented methodology. The test produces an auditable report with prioritised findings and recommendations that fit your environment. The report provides evidence for regulators and insurers. ANOMAL tests web, cloud, Active Directory, APIs and internal networks.
Incident response within 72 hours
The outcome of a serious cyber incident is decided in the first hours. ANOMAL provides a Swiss incident response team that works within the 72-hour notification window of cyber insurance. It covers first analysis, containment, evidence preservation and communication with insurer, regulator and executive leadership. A retainer is not mandatory but recommended so the clock does not start with the first phone call.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.
MTTD and MTTR: the two SOC KPIs that count
Mean Time to Detect (MTTD) measures how fast a SOC spots an attack. Mean Time to Respond or Contain (MTTR, MTTC) measures how fast it is stopped. Together they are the only credible evidence that a SOC is working, not just running.