Better us
than them.
Most small and mid-sized companies can't staff an attack team or a defense team, so they staff neither and hope. RTBT does both, in the same week, with the same people — and hands you one report you can act on Monday.
Drag the seam. On the left is what a red team does. On the right is what the defenses actually see. The gap between them is the whole product.
Three ways in.
Start wherever the pressure is. Most clients begin with an engagement, then keep the appliance.
A test is a photograph.
Your network is a film.
A laptop arrives, a contractor gets a VPN account, someone opens a firewall rule on a Friday to make a printer work — and by autumn the report you paid for in spring describes a company that no longer exists.
RT-1 is how we sell a small company continuous testing without also selling them a security team. It stays after we go and keeps running the same attacks, safely, on a schedule.
Small enough
to answer the phone.
The big firms sell you a 200-page PDF. You needed four sentences and a Tuesday afternoon.
The security industry is built for enterprises and priced for them too. The 30-person manufacturer, the regional clinic, the law firm with two offices — they face the same attackers and get sold either nothing or a program they have no way to run.
We keep the engagement small, the report short, and the fixes ones your existing people or your IT provider can actually make.
Book a
scoping call.
Thirty minutes. Tell us how many people you have, how many locations, and whether anyone has ever tested you before. If we're not the right fit we'll say so on the call.
Every engagement runs under a signed scope and authorization letter. Nothing is touched that isn't named in it.
The red team
that doesn't leave.
RT-1 is a 1U appliance we rack in your closet. It re-runs the attack paths from your engagement on a schedule, safely and within agreed limits, and emails you the day something you fixed comes back.
Because drift is
the actual problem.
Nobody gets breached the week after a penetration test. They get breached eight months later, through something that wasn't there when the testers were.
A new laptop with the old image. A contractor's VPN account that outlived the contract. A firewall rule someone opened on a Friday to make a printer work. Every one of those is small, reasonable, and invisible — and together they rebuild the attack path you just paid to close.
RT-1 watches for exactly that. It knows the paths that worked on you, because it was built from your engagement, and it walks them again every week.
Why not software?
Because the honest test comes from inside, on your network, from a machine that isn't yours to reconfigure. An agent installed on your servers gets whitelisted, excluded, and eventually turned off by whoever is troubleshooting something else. A box in the rack is harder to quietly defeat — which is the point of a red team.
Four jobs,
every week.
Re-walks your paths
The exact routes our team used during the engagement, run again on a schedule you set. If a closed door reopens, you hear about it in days rather than at the next annual test.
Finds what's new
New devices, new open services, new shares, new accounts with more access than they need. The stuff that appears between tests because a business is a living thing.
Proves your alerts still work
A detection rule that nobody has fired in six months is a rule you should not trust. RT-1 sets them off on purpose so you learn whether they still reach a human.
Writes it down
A short weekly email to you and to whoever runs your IT. New findings, resolved findings, and what changed since last week. Not a dashboard you'll stop logging into.
What it will
never do.
This is the part most clients want in writing, so it goes in the contract too. An appliance that attacks your network is only acceptable if its boundaries are absolute.
- Encrypt, delete, or modify your dataIt reads and it reports. Destructive actions are not implemented, not disabled — not implemented.
- Copy your files off siteFindings leave the building. Contents do not. Exfiltration testing, if you want it, is a scoped human exercise with named test data.
- Run anything outside the agreed scopeAddress ranges, systems, and techniques are fixed in writing before the unit is shipped and can only be changed by you.
- Touch production during your busy hoursYou pick the window. The default is a weekend overnight, and the unit sits idle the rest of the week.
- Keep running when you say stopA physical switch on the front of the unit halts everything. So does one click in the portal, and so does unplugging it.
One cable,
one afternoon.
- Form factor1U rack mount, or shelf mount for a closet without a rack
- PowerSingle standard outlet
- NetworkOne ethernet port, on the internal network you want tested
- ConnectionOutbound only. No inbound port forward, no public exposure, no VPN into your network
- Firewall changesNone required in the common case
- InstallYour IT provider racks it and plugs it in. We handle the rest remotely
- OwnershipIncluded with an active subscription. It goes back when you stop
- If it's stolenTamper detection wipes it. It holds findings, not your data
Fair concerns.
Could it break something?
The techniques it runs are chosen for safety and agreed in scope before deployment. Anything with a real chance of disrupting a service is excluded from automated runs and only ever done by a person, during an engagement, with you on the phone.
That said, no honest vendor tells you the risk is zero. It's low, it's bounded, and there's a switch on the front of the box.
What if we already have an IT provider?
Good — they get the weekly email too. RT-1 tends to make a decent IT provider look better, because it hands them a short specific list instead of a vague worry. We are not trying to replace them and we don't sell managed IT.
Do we need an engagement first?
Yes. RT-1 is built from your engagement's findings; without one it would be running generic checks, which is a different and much less useful product. The first test is what teaches the box what your network actually looks like.
Does it need access to our sensitive systems?
No standing credentials are required. Where a scenario calls for an account — testing what a compromised employee could reach, for example — you create a dedicated test account with defined access and can disable it at any time.
What does it cost?
It's a monthly subscription that includes the hardware, the weekly runs, and the reporting. Pricing depends on how many sites and how many addresses are in scope, so it comes out of the scoping call rather than a table on a website.
See whether
you need one.
Most companies should start with an engagement and decide about the appliance at the readout, once they've seen what we found. We'll tell you honestly if a box in your closet isn't the thing you need.
Two teams,
one invoice.
Attack and defense are usually sold by two different firms who never speak to each other. We run them as one engagement, because finding the hole and closing it are the same job.
We attack.
- External attack surfaceEverything of yours the internet can reach, including the things you forgot you own. Old marketing sites, a test server from 2019, the portal a vendor stood up for you.
- Internal engagementWe start from the position of a compromised laptop — the realistic starting point — and see how far the network lets us walk from there.
- Phishing and pretextEmail and phone, aimed at the roles that hold the money and the passwords. Measured for who clicked, who reported it, and how long reporting took.
- Cloud and identityMicrosoft 365 or Google Workspace: the accounts, the third-party apps nobody remembers approving, the sharing links that went public.
- Ransomware path reviewOne question, answered plainly: from a single compromised machine, could someone reach the systems that would stop your business, and could they reach your backups?
- Physical and social, optionalCan a stranger in a high-visibility vest reach your server room. Scoped carefully, and only with the right people informed.
We defend.
- Log coverage auditWhat you're recording, what you're paying to record, what's being thrown away after 24 hours, and what you'd actually need at 3am to answer "how did they get in."
- Detection engineeringRules written against the attacks that just worked on you, not a generic vendor pack. Tuned until they fire on the real thing and stay quiet the rest of the time.
- Backup and recovery testNot "do backups run." We restore something real and time it, then tell you what your actual recovery window is versus the one you assumed.
- Hardening baselineThe dozen or so settings that close most of the paths we used. Ordered by how much they help against how much they'll annoy your staff.
- Identity and access reviewWho has administrator rights, who has them because of a project that ended in 2022, and what the shared accounts are protecting.
- Incident playbook and tabletopWho calls whom, in what order, on the worst day — including your insurer and your lawyer. Practiced once, on paper, before you need it.
Purple week.
The part clients tell us they didn't know they could buy. We sit in the same room as your staff or your managed IT provider. We run an attack, everyone watches what fires and what doesn't, we tune the rule, and we run it again until it catches.
It is the fastest security training we know of, because nobody is being lectured — they're watching their own network get taken apart and putting it back together as it happens. That knowledge stays after we go, which matters more for a small company than any document we could leave behind.
Short, ranked,
and written for you.
The one-page version
For the owner or the board. What we found, what it would cost you if someone else found it first, and the three things to fix this month.
The technical findings
For whoever does the fixing. Each finding has the path we took, the evidence, and the specific change to make — not a link to a vendor's documentation.
The detection rules
Working rules for the tools you already own, plus a note on what your current tooling genuinely cannot see, if that turns out to be the case.
We do not sell software licenses, we don't take vendor commissions, and we don't sell you managed IT afterwards. If the right answer is that you should spend nothing and change two settings, that's what the report will say.
Who this is for,
and who it isn't.
A good fit
- Roughly 20 to 500 people, one to a handful of sites
- No full-time security staff, or exactly one overloaded person
- An IT provider or a small internal IT team who can make changes
- A reason to care right now — a customer questionnaire, an insurance renewal, a scare, a near miss at a competitor
- Someone with authority who will actually read the report
Probably not
- You need a checkbox for an audit and don't intend to fix anything — there are cheaper firms for that and we'd rather you use them
- You have a mature security team and want a specialist adversary simulation at enterprise scale
- You're mid-incident right now — you need incident response today, not a test. Call your insurer first, then call us
- Nobody internally has time to make a single change in the next quarter
Tell us what
you're worried about.
The scoping call is thirty minutes and it's how we work out which of the above you actually need. Often it's less than people expect.
Five steps,
in this order.
Numbered because the order matters. Re-testing before fixing tells you nothing, and fixing before attacking means guessing at what to fix. Most engagements run four to six weeks end to end, of which yours takes about six hours of anyone's time.
Scope
We ask what you have, where it is, and what would genuinely hurt if it stopped for three days. Then we write down what's in bounds, what's out, when we can touch things, and who to call if something goes wrong. You sign that document and an authorization letter before anything starts.
This is also where we tell you if you don't need us yet. It happens.
Attack
The red team works the scope. In most engagements your people notice nothing, which is itself a finding. You get a phone number that reaches a human at any hour, and we stop the moment you say stop — no discussion, no change order.
If we find something severe enough that waiting would be irresponsible, we don't save it for the report. You get a call that day.
Readout
We walk you through what we did, in the order we did it, so the story makes sense rather than arriving as a list of severities. Findings are ranked by what a real attacker would do first — not by a scoring formula that puts a theoretical issue above the unlocked door.
Bring whoever will do the fixing. Bring the owner. The point is that everyone hears the same version once.
Fix
This is the part most firms leave to you. Our blue team works with your staff or your IT provider: detection rules written and tuned, settings changed, backups tested, playbook drafted. If you want purple week, this is where it sits — same room, attack and defense side by side.
We work at your pace. If your one IT person has a busy fortnight, the fix window moves.
Re-test
We run the same paths again and show you which are closed, which are partly closed, and which you decided to accept — because accepting a risk knowingly is a legitimate business decision and the report should record it as one.
If you keep RT-1, this becomes continuous instead of a moment. That's the whole argument for the appliance.
What we need
from you.
Less than you'd think, but the last item is not optional and we'd rather say so before you sign anything.
- Someone with authority to approve the scopeTesting systems you don't own or can't authorize is a legal problem, not a technical one.
- A list of your addresses, domains, and sitesRough is fine. Finding the ones you forgot is part of the job.
- A phone number that reaches a decision-maker at any hourUsed rarely. Used immediately when it's needed.
- Your IT provider looped in, or deliberately notBoth are valid. Telling them makes the fix phase faster; not telling them tests whether they'd notice. We'll advise, you choose.
- About six hours of someone's attention, spread over six weeksThe scoping call, the readout, and some back-and-forth during the fix phase.
- The intention to actually change somethingIf nothing is going to change, the money is better spent elsewhere and we'll tell you so.
Written down
before we start.
Every engagement is governed by a scope document and a signed authorization letter. These are the standing terms inside it.
Nothing destructive
No encryption, no deletion, no denial of service against production. Impact is demonstrated, not performed.
Your data stays yours
Where proof requires evidence, we capture the minimum needed and destroy it on an agreed schedule after the report is delivered.
Stop means stop
Any named contact can halt the engagement at any hour with one call. We stand down first and ask questions afterwards.
Critical findings surface immediately
Anything actively exploitable and severe gets reported the same day rather than held for the readout.
Third parties are out of scope
Your cloud providers, your suppliers, and your customers are not tested without their own written permission.
Your staff are not the target
Phishing results are reported as rates and patterns. We don't hand you a list of names to discipline, and we'll push back if you ask.
Fixed price,
agreed up front.
Engagements are quoted as a fixed fee after the scoping call, based on the number of sites, the number of addresses in scope, and which of the red and blue components you want. No hourly billing and no discovering a bigger number halfway through.
The RT-1 appliance is a separate monthly subscription that includes the hardware, the weekly runs, and the reporting.
If the scope changes, we re-quote before doing the work, not after.
A note on cheaper options
You can buy an automated vulnerability scan for a fraction of this, and for some companies that is genuinely the right first purchase. It will find missing patches. It will not find that your backup server accepts your help desk's shared password. If a scan is what you need, we'll say so on the call.
Book the
scoping call.
Thirty minutes, no obligation, and no deck. The worst outcome is that you learn what you'd be buying.
Small enough
to answer
the phone.
RTBT is a red team and blue team practice built for the companies the security industry quietly writes off: too small for an enterprise program, too real to be told to buy antivirus and hope.
The big firms sell you a 200-page PDF. You needed four sentences and a Tuesday afternoon.
The security industry is built for enterprises and priced for them too. A 30-person manufacturer faces the same ransomware crews as a bank — more often, in fact, because the crews know the manufacturer has no night shift watching alerts — and gets offered either nothing, or a program that assumes a team it will never have.
So the small company buys a tool, the tool sends alerts to an inbox nobody reads, and everyone agrees that security has been handled.
We started RTBT to sell the other thing: a real attack, run by people, followed by real fixes made alongside your own staff, and a box that keeps testing after we leave. Small scope, short report, and a phone number that reaches a person.
The person who
found it explains it.
There is no account layer between you and the technical work. The people in your network are the people at your readout.
Dowell runs the technical side of RTBT: the engagements themselves, the tooling behind them, and the design of the RT-1 appliance. He is the person who will be in your network, and the person who will explain what he found.
His view of the work is simple — a finding you don't understand is a finding you won't fix. So every report gets written to be read by whoever has to act on it, not by another consultant.
"Most of what we find isn't clever. It's a password from 2019 that still works. The clever part is noticing before somebody else does."
Dowell Stackpole
Six commitments.
We don't sell you tools
No software licenses, no vendor commissions, no reseller margin. If the right answer is to change two settings and spend nothing, the report will say that. Our incentives should not depend on your problem being expensive.
Plain language, always
Findings get written for the person who has to fix them and the person who has to fund it. If a sentence in our report needs a glossary, it goes back for a rewrite.
We tell you when you don't need us
Some companies who call us should buy a scan, turn on multi-factor authentication, and check back in a year. We'd rather say that on the first call than take the money.
Your staff aren't the enemy
Phishing results come back as rates and patterns, not a list of names for a manager to punish. People who fear being blamed stop reporting things, and reporting is the control that actually works.
The scope is a contract, not a suggestion
What's in bounds is written down and signed before anything begins. We don't test what we weren't authorized to test, however tempting the open door looks.
You keep what we build
Detection rules, playbooks, and baselines are yours. Nothing is locked to us, and nothing stops working if you don't renew.
RT. BT.
Red team, blue team. Attack and defense — the two halves of security that most companies are sold separately, by firms who never talk to each other, at a price that assumes you can afford both.
The seam between them is where the value is. In the industry it's called purple teaming, and it's the part we think small companies need most, because you can't afford for the lesson to be lost in the handoff between two vendors.
Talk to
the technologist.
The scoping call isn't a sales call with an engineer brought in later. You get the person who'll be doing the work, in the first thirty minutes.
Book a
scoping call.
Thirty minutes with the person who would run the work. No deck, no discovery process, no follow-up sequence. If we're not the right fit we'll say so on the call and tell you what we'd do instead.
What happens on it.
- You describe the businessHeadcount, sites, what systems the company would stop without, and what prompted the call.
- We ask about six questionsMostly about where things live and who has the keys. No technical knowledge needed on your end.
- We tell you what we'd doWhich parts of red and blue apply to you, roughly how long, and whether the appliance makes sense later.
- You get a fixed quote in writingUsually within two business days. If we need to look at something first, we'll say that on the call.
If you think you're being attacked right now, don't fill in a form. Call your cyber insurance carrier's incident line first — using them is usually a condition of your coverage — and disconnect affected machines from the network rather than powering them off. Then reach us at hello@rtbt.ai. A test is not what you need today.
Or just
email us.
General
Technical
Existing clients
Use the number on your engagement letter. It reaches a person at any hour for the duration of your engagement.