Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

Red Team

A red team is a goal-oriented adversarial engagement that simulates a real attacker to test an organization's people, processes, and technology together, including its ability to detect and respond. Rather than cataloguing every vulnerability, a red team pursues a specific objective such as accessing sensitive data. It measures resilience, not just exposure.

In practice

A pen test asks "what is vulnerable?" A red team asks "if a determined attacker targeted us, would we notice and could we stop them?" Engagements often run stealthily and may include social engineering and physical access.

The defending side is the blue team, and a purple team exercise blends both so attackers and defenders share findings in real time. Red teaming suits organizations that already have a working security program to stress-test.

// how traztech helps

traztech delivers adversarial red-team engagements for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

Red teaming is what you commission when you already believe your controls work and want to know whether they hold up against somebody actively trying to defeat them, including your detection and response.

It is the wrong purchase for a first-time security programme. If you do not yet have logging, alerting and an incident process, a red team will confirm that quickly and expensively.

Red Team: common questions

How is a red team different from a penetration test?

A penetration test aims for coverage of a defined scope. A red team aims for an objective, is usually time-boxed and stealthy, and tests your detection and response as much as your controls.

Do we need a red team for SOC 2?

No. SOC 2 does not require red teaming. It is a maturity exercise, generally for organisations that already run testing and have a functioning detection capability.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.