Purple Teaming
Purple Team engagements are collaborative simulations of various attack vectors. Using varied sophistication and TTPs bespoke to the environment, prevention, detection and response can be measured and plotted to show possible attack path maps. The efficacy of technological, procedural and personnel controls can be shown alongside gaps and risks.
Features
- Standard (FLIP), Objective Based, Metric Based, Phased.
- Follows structured frameworks like FLIP for comprehensive assessments.
- Includes diverse focus areas like cloud, endpoint, and AI/ML.
- Evaluates controls across technology, procedures, and personnel.
- Facilitates daily interactions between Red and Blue Teams.
- Captures all activities, outcomes, and recommendations in detailed documentation.
- Provides metrics on the efficacy of security controls.
- Offers both high-level summaries and detailed technical analysis.
- Generates and tests bespoke tactics, techniques, and procedures.
- Delivers actionable recommendations for improving security controls and responses.
Benefits
- Enhances overall security posture and resilience.
- Focuses on critical areas needing attention and enhancement.
- Raises organisational understanding of vulnerabilities and attack vectors.
- Assists in refining EDR/MDR, SOC capabilities, and other defences.
- Engages key personnel in security enhancement processes.
- Establishes baselines for ongoing assessments and improvements.
- Ensures security efforts align with organisational goals and risks.
- Provides recommendations based on attack paths for closing security gaps.
- Optimises resource allocation to high-risk areas.
Pricing
£1,400 a unit a day
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
9 4 8 2 0 7 0 6 6 4 1 0 4 2 9
Contact
Pen Test Partners LLP
Susan Bunce
Telephone: +447538520205
Email: bidteam@pentestpartners.com
Planning
- Planning service
- Yes
- How the planning service works
- We will help to identify areas of cyber security weakness in the deployment of cloud environments.
- Planning service works with specific services
- No
Training
- Training service provided
- No
Setup and migration
- Setup or migration service available
- Yes
- How the setup or migration service works
- Although we do not help the overall migration to cloud, our role is specific to the security of the cloud migration.
- Setup or migration service is for specific cloud services
- Yes
- List of supported services
-
- Azure
- AWS
- Google Cloud
- Private Cloud
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security testing
- Security incident management
- Security audit services
- Certified security testers
- Yes
- Security testing certifications
-
- GBEST
- CHECK
- CREST
- Tigerscheme
- Cyber Scheme
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- Each project is scoped individually, so constraints would be on a case by case basis.
User support
- Email or online ticketing support
- No
- Phone support
- No
- Web chat support
- No
- Support levels
- Our service is a consultancy based service and therefore delivered on a day rate basis with direct email contact of the consultant, account manager, customer support and an escalation route.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- 24/02/2016
- What the ISO/IEC 27001 doesn’t cover
- Not applicable - All services offered by PTP are covered,
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
-
- Crest
- GBEST
- CHECK
- Tigerscheme
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
PTP consider the environmental impact of our cybersecurity practices. Minimizing energy consumption, waste, and carbon footprint is integral to our approach and service delivery.Covid-19 recovery
During COVID, PTP developed new ways of working such as remote service delivery options for our clients and enabled remote working for our staff.Tackling economic inequality
We tackle economic inequality through Education and Awareness: We invest in educating users, employees, and the wider community about cybersecurity risks and best practices. Empowering people with knowledge enhances overall security. We actively participate in local and global cybersecurity events, workshops, and conferences. We share insights, contribute to discussions, and learn from others. : We support cybersecurity education programs, mentor students, and offer guest lectures at Universities to foster the next generation of cybersecurity professionals.Equal opportunity
PTP supports every individual during their employment, to have an equal opportunity to make the most of their lives and talents through open and fair recruitment, progression. We encourage our employees to take a leading role in relation to their individual needs. This may be related to, career progression, development needs or a request to changes to work pattern. Our employees should feel empowered to bring such matters to the attention of their manager as soon as they are reasonably able to, to explore ways forward together.Wellbeing
"PTP employees are our biggest assets who deliver our services to our clients. PTP is committed to support our employees in health and wellbeing including physical and mental health through a range of regular initiatives, policies and practices which are reviewed at regular intervals. "
Pricing
- Price
- £1,400 a unit a day
- Discount for educational organisations
- No