Red teaming

Build your cyber defence resilience through real-world simulations

What you need to know - latest guidelines on red teaming

With cyber security attacks developing in scope, complexity and sophistication, assessing cyber resilience and security audit has become an integral part of business operations, and financial institutions make particularly high risk targets. In 2018, the Association of Banks in Singapore, with support from the Monetary Authority of Singapore, released the Adversary Attack Simulation Exercise guidelines (or red teaming guidelines) to help financial institutions build resilience against targeted cyber-attacks that could adversely impact their critical functions. In January 2021, the Monetary Authority of Singapore (MAS) published the revised MAS Technology Risk Management Guidelines for the financial sector, which included best practices and principles for cyber resilience - including performing red teaming simulations to validate cyber defence models.

Red teaming is the closest picture to the reality of your cyber defences

According to PwC’s Digital Trust Insights Survey 2021 - Singapore findings, Singapore executives have higher threat outlooks than that of their global counterparts, given the region’s accelerated adoption of new technologies. The highest threat outlooks are for the Internet of Things (65% voted significantly negative impact’ or ‘negative impact’), social engineering attack (61%) and attacks or hacking on cloud service providers (55%).

Often, cyber investments to combat these high threat outlooks are spent on controls or system-specific penetration testing - but these might not provide the closest picture to an organisation’s response in the event of a real-world cyber attack. A red team exercise simulates real-world hacker techniques to test an organisation’s resilience and uncover vulnerabilities in their defences.

Knowing the strength of your own defences is as important as knowing the power of the enemy’s attacks. Red teaming enables an organisation to:

  1. Assess organisational resilience against different attack techniques, tactics and procedures.
  2. Identify weaknesses in security controls and associated risks, which are often undetected by standard security testing method.
  3. Train your defence teams to be more prepared and proficient in the event of real-time responses.

Build your red-teaming capabilities with PwC

With a CREST accreditation to provide simulated targeted attacks, our award-winning and industry-certified red team members will use real-world hacker techniques to help your organisation test and strengthen your cyber defences from every angle with vulnerability assessments.

Depending on the size and the internet footprint of the organisation, the simulation of the threat scenarios will include:

1. Project planning workshops

Our cyber specialists will work with you to define the scope of the assessment, vulnerability scanning of the targets, and various attack scenarios.

2. Threat scenario development

The attack scenarios are driven by real-life threat actor tools, techniques and procedures, by drawing on a spectrum of intelligence sources, including past incident response engagements and data, open source intelligence (OSINT tools), and geopolitical intelligence.

We also help you analyse the tactics that might be used in an attack and how an attacker might conduct a compromise and align it with your wider enterprise context digestible for your stakeholders.

3. Execution

We prepare the testing infrastructure and software and execute the agreed attack scenarios. The efficacy of your defense is determined based on an assessment of your organisation’s responses to our Red Team scenarios.

4. Analysis and reporting

Finally, we collate and analyse evidence from the testing activities, playback and review testing outcomes and client responses and produce a final testing report on the defense resilience.

What the red teaming simulation exercise will give you

Threat modelling report

The threat modeling report will cover an in-depth overview of:

  • The current threat landscape based on our research into the organisation's key lines of services, critical assets and ongoing business relationships.
  • Technical specifics on threats, actors and scenarios.

Red teaming report

The red teaming report will cover:

  • The overall maturity of the organisation’s responses relative to the types of attack
  • The details of threat actors’ attack narratives
  • Assessment of organisation detection
  • Response capabilities
  • The recommended tactical and strategic actions the organisation should take to improve their cyber defence posture.

About the team

PwC’s team of 200 experts in risk, compliance, incident and crisis management, strategy and governance brings a proven track record of delivering cyber-attack simulations to reputable companies around the region.

Our award-winning penetration testing professionals are certified to some of the highest global industry standards, including Council of Registered Ethical Security Testers (CREST), Offensive Security Certified Professional (OSCP), Offensive Security Certified Expert (OSCE), Offensive Security Wireless Professional (OSWP), Certified Red Team Professional (CRTP), Global Information Assurance Certification Forensic Analyst (GCFA) and GIAC Certified Forensic Examiner (GCFE).

Follow us
Hide

Required fields are marked with an asterisk(*)

By submitting your email address, you acknowledge that you have read the Privacy Statement and that you consent to our processing data in accordance with the Privacy Statement (including international transfers). If you change your mind at any time about wishing to receive the information from us, you can send us an email message using the Contact Us page.

Contact us

Jimmy Sng

Jimmy Sng

Technology Risk Services Leader, PwC Singapore

Tel: +65 9746 6771