Red team / blue team — for companies without a security team

Better us
than them.

Most small and mid-sized companies can't staff an attack team or a defense team, so they staff neither and hope. RTBT does both, in the same week, with the same people — and hands you one report you can act on Monday.

A week-one engagement, in the shape it usually takes

Drag the seam. On the left is what a red team does. On the right is what the defenses actually see. The gap between them is the whole product.

What we didWhat you saw
MON 09:40 — Reconnaissance
Pulled the staff list off LinkedIn and matched it to the email format found in a public PDF on the company's own website. 61 valid addresses, no contact with the network.
MON 09:40 — Nothing
There is nothing to see here, and that's the point. By the time an attacker touches your network they already know your org chart. Your first real chance to notice is step two.
Not detectable
TUE 02:15 — Credential access
Tried three common passwords against all 61 accounts on the VPN portal, slowly, spread over six hours to stay under the lockout threshold. Two accounts opened.
TUE 02:15 — 180 failed logins
The events were all in the firewall logs. Nobody was watching at 2am and no alert existed for "many accounts, few attempts." That rule got written on Thursday.
No rule fired
TUE 08:05 — Initial access
Logged into the VPN as the accounts payable clerk. No second factor on the portal, so the password was the whole door.
TUE 08:05 — A normal login
It looked exactly like her. Right name, right hours, wrong country. Geo-anomaly alerting was the single cheapest fix in the whole report.
No rule fired
WED 11:30 — Lateral movement
Found the same local administrator password on 40 workstations. One shared password meant one machine was the same as every machine.
WED 11:32 — Endpoint alert
The endpoint tool caught this one and raised a medium-severity alert. It sat unread in a console nobody had logged into since the vendor installed it in March.
Detected, unread
THU 16:50 — Impact, simulated
Reached the file server and the backup console with domain admin. Took a directory listing and stopped. No files were encrypted, moved, or copied out.
THU 16:50 — The honest answer
Ransomware would have taken the backups first, and the backups were reachable with the same credentials as the thing they were backing up. That finding alone paid for the engagement.
No rule fired
What you can buy

Three ways in.

Start wherever the pressure is. Most clients begin with an engagement, then keep the appliance.

The problem with a pentest

A test is a photograph.
Your network is a film.

A laptop arrives, a contractor gets a VPN account, someone opens a firewall rule on a Friday to make a printer work — and by autumn the report you paid for in spring describes a company that no longer exists.

RT-1 is how we sell a small company continuous testing without also selling them a security team. It stays after we go and keeps running the same attacks, safely, on a schedule.

Who this is for

Small enough
to answer the phone.

The big firms sell you a 200-page PDF. You needed four sentences and a Tuesday afternoon.

The security industry is built for enterprises and priced for them too. The 30-person manufacturer, the regional clinic, the law firm with two offices — they face the same attackers and get sold either nothing or a program they have no way to run.

We keep the engagement small, the report short, and the fixes ones your existing people or your IT provider can actually make.

Start here

Book a
scoping call.

Thirty minutes. Tell us how many people you have, how many locations, and whether anyone has ever tested you before. If we're not the right fit we'll say so on the call.

Every engagement runs under a signed scope and authorization letter. Nothing is touched that isn't named in it.