Your ICT infrastructure is under attack. Let us be the first and only ones to succeed in this.

As an entrepreneur, you face a wide variety of challenges every day. One of these is maintaining the security of your company's assets. These exist not only physically, but increasingly also in electronic form. Industrial espionage, cyber attacks and targeted malware are just a few examples from a long list of risks. With our Attack Simulation, we test the overall resilience of your organization to cyber attacks.

Selected references on the subject

Why Attack Simulation?

To effectively protect your company from cyber threats, you should carry out simulations. These offer a proactive and holistic approach that goes beyond traditional security checks and allows you to run through realistic attack scenarios - putting not only your infrastructure but also your processes and employees to the test.

Proactive Simulation

Traditional security assessments such as penetration tests limit the scope and focus on the depth of the test instead. In a real attack, such boundaries are not observed. In our Attack Simulations, the traditional scope is also eliminated, allowing us to proactively play out realistic attack scenarios. This not only checks your infrastructure, but also your processes and your employees in all areas.

Worst-Case Scenarios

Our Attack Simulations are tailored to the specific requirements of your organization and your business processes. To identify realistic and context-specific worst-case scenarios, these are developed together with your internal specialists. Such scenarios must be developed individually for each company and can, for example, include access to research results, payroll data, or the impairment of industrial and control systems. This approach ensures that critical scenarios for your organization are considered within the scope of the Attack Simulation.

Relevant Risks

In an Attack Simulation, your company is exposed to real attacks, all of which aim to control the predefined worst-case scenarios. This gives you a clear idea of the current threat situation in your company. Our security experts provide you with concrete answers to the question of which areas need to be protected more strongly and where the existing protection is already sufficient from a risk perspective. Based on this, individual packages of measures can be defined and implemented. One way to identify your current risk areas in a measurable way without interfering with your infrastructure is provided by our Cyber Security Assessment.

Difference between Attack Simulation, Red Teaming and Purple Teaming

The aim of an attack simulation is to uncover security gaps and vulnerabilities that are particularly relevant for you and your company. As with Red Teaming, a real attacker is simulated, but for reasons of efficiency, no consideration is given to any detection and response capabilities.

In contrast, Red Teaming takes existing detection and response processes into account by carefully weighing up and selecting the chosen attack techniques before execution in order to remain undetected as an attacker for as long as possible. This also uncovers and exploits vulnerabilities and security gaps, but the main focus is on testing your company's existing detection and response capabilities.

Purple Teaming, on the other hand, involves collaborative testing between the attacker and defender of a predefined series of attack techniques with the aim of uncovering any gaps and weaknesses in your company's detection capabilities as efficiently and comprehensively as possible.

Possible modules of an Attack Simulation

A comprehensive security strategy requires the simulation of various attack scenarios in order to uncover potential vulnerabilities and develop effective defensive measures. Our Attack Simulation has a modular structure and can, for example, consist of a combination of the following modules.

01

External attack

Within a modern organization, it is often unavoidable that at least some IT systems are publicly accessible via the internet. This exposure makes the systems an interesting target for attack, as it allows sensitive data to be accessed directly and a first step towards the internal network to be taken. In this scenario, Redguard behaves like an external attacker trying to gain access to systems in your infrastructure that are accessible via the internet. Our security experts use both known and specifically tailored attack methods for your systems. If access is achieved, possible sensitive data is extracted and analyzed. Furthermore, attempts are made to penetrate into internal network areas.

02

Spear Phishing

This module mounts tailored phishing attacks on individual persons or groups. It involves an attempt to target the persons in a deliberately relevant context in order to encourage them to disclose sensitive information like customer data or login details or even to execute malware on their workstations. The findings of this module provide a clear impression of your current employee awareness and can be used furthermore as a basis for relevant training or evaluating technical measures. Last but not least, this external threat puts the perimeter security through its paces – and therewith also the responsible employees within your organization.

03

Malware Infection

All important data or information will at some point be processed or read by someone. Most commonly this will take place on the employees’ client devices. This means that in many cases, attackers will not have to penetrate central servers. Instead it is sufficient if they gain access to suitable client devices to obtain the data they seek. This scenario simulates infection of a client with malware as a means of accessing sensitive data. The next step is to place the device in your internal network and to manipulate it via the Internet using the command & control channel (C2). Additionally, we attempt to transfer sensitive data out of the company, which enables an assessment of the installed data loss prevention (DLP) systems and the defense mechanisms such as intrusion detection and prevention systems (IDS/IPS).

04

Social Engineering

Our company physically penetrates your business premises (without the use of force). In particular, this involves the use of social engineering. The underlying aim is to steal or least copy sensitive information in hard copy (e.g. documents), as well as to position technical eavesdropping devices. This module addresses a large number of issues: Firstly, the social engineering attack reviews the current awareness among your employees, while secondly assessing the internal security measures such as active security systems and other technical mechanisms.

05

Internal Attack

Placed on your internal network, we simulate an attacker who has gained access to your internal network. We uncover vulnerabilities and actively exploit them there. So-called exploits can be used, for example, or techniques such as the redirection of network traffic and technically supported social engineering (e.g. displaying false login masks). The aim of this scenario is to determine what an attacker can achieve once it has penetrated your internal network, for example, through malware. This scenario enables well-founded statements to be made about the security status of the internal network and simulates the potential damage that could be caused by a failure of the perimeter security.

Results

As a result of an Attack Simulation, you receive a transparent, practical, and holistic assessment of your organization's resilience. We provide sound decision-making foundations and actionable recommendations:

  • Management Summary & Detailed Report: An executive summary for decision-makers alongside an extensive technical report covering all findings across the tested modules, mapped to realistic attack paths and prioritized remediation measures.
  • Chronological Action Log: Complete timeline documenting all performed attack actions, leveraged techniques, and left artifacts for full transparency and traceability.
  • Structured Risk List: Individual findings with standardized risk ratings for straightforward triage, prioritization, and integration into your risk management processes.
  • Final Presentation & Debriefing: A collaborative session with technical teams and leadership to review key findings, discuss technical details, and formulate sustainable security improvements.

By connecting technical vulnerabilities into tangible attack chains, you gain a clear view of your actual risk exposure, enabling you to invest your security resources where they deliver the highest impact.

Simulation Blog Posts

Bypassing Remote Browser Isolation
07. Jul 2026

Bypassing Remote Browser Isolation

Remote Browser Isolation (RBI) represents a significant leap forward in enterprise security and has gained popularity...
Let yourself in: Insights in einen Social Engineering-Einsatz mit Redguard
08. Dec 2025

Let yourself in: Insights in einen Social Engineering-Einsatz mit Redguard

In diesem Blog-Beitrag wird die reale Situation eines vergangenen Auftrags in anonymisierter Form genutzt, um unser...
Penetration Test, Schwachstellenscan, Red & Purple Teaming: Nur ein Apfel ist ein Apfel!
17. Mar 2025

Penetration Test, Schwachstellenscan, Red & Purple Teaming: Nur ein Apfel ist ein Apfel!

In der heutigen digitalen Welt sind Unternehmen ständig Cyberbedrohungen ausgesetzt. Cyberkriminelle nutzen raffinierte...
Offensive Security mittels KI
09. Aug 2024

Offensive Security mittels KI

Künstliche Intelligenz (KI) bzw. Artificial Intelligence (AI) ist nicht mehr nur ein Schlagwort, sondern hält Einzug in...
Threat-Led Penetration Testing gemäss DORA
24. Jul 2024

Threat-Led Penetration Testing gemäss DORA

In der immer stärker digitalisierten Welt stehen Finanzinstitute vor einer Vielzahl an Herausforderungen. Ein wichtiger...
16. Jan 2024

Vier Jahre Attack Simulation für die Suva – und wie ihre Cybersecurity-Maturität dadurch erhöht wurde

In der dynamischen Welt der Cybersicherheit gibt es eine Konstante, welche sowohl Angreifer als auch Verteidiger...
Kontrollierter Cyber-Angriff auf eine Bank
14. Jul 2020

Kontrollierter Cyber-Angriff auf eine Bank

Kontrollierter Angriff auf eine Bank – wie geht das? Mittels einer Attack Simulation haben Security Tester der Redguard...
Simulierter Cyber-Angriff
01. Apr 2017

Simulierter Cyber-Angriff

Die KIBAG Dienstleistungen AG ist täglich bestrebt, die eigenen Unternehmenswerte zu schützen. Werte existieren nicht...