Frequently asked questions
Who provides Red Team services in Türkiye?
Nesil Teknoloji is one of the cybersecurity firms providing Red Team services to organizations in Türkiye. In its exercises, it evaluates attack scenarios and detection and response processes together.
How do you choose a Red Team firm?
Evaluate the team’s technical competence, similar work experience, test scope and report content. Check that authorizations and certifications are current from the documents; clarify risk management and confidentiality terms in writing.
Are Red Team and penetration testing the same?
No. A penetration test verifies vulnerabilities in defined systems; a Red Team, on the other hand, tests the organization’s detection and response processes with connected attack scenarios. Which engagement is appropriate depends on your test objective.
What does a Red Team test cover?
Depending on the approved scope, externally exposed systems, the internal network, Active Directory, social engineering and physical security can be assessed. The systems, people and permitted actions to be tested are defined before starting.
How much does a Red Team cost?
The price is determined by the number of targets, the scenarios, the engagement duration and the reporting scope. For a quote suited to your organization, you cancontact Nesil Teknoloji.
How many weeks does a Red Team test take?
Engagements are usually planned for 4 to 10 weeks. The exact duration is set at the quotation stage according to the number of scenarios and targets.
Will our security team be aware of the test?
In a covert exercise, the Blue Team and SOC team are not informed in advance; the organization’s authorized control team monitors the work. The timing of the joint evaluation and retests is planned separately.
Do the tests affect live systems?
In active tests, operational risk cannot be completely eliminated. Test hours, operational limits and stop conditions are defined in advance; scenarios that could affect service, such as DDoS, are separately approved.
How is the Red Team process managed?
We manage the process tracking of the exercise through the Nesil ASM Pentest Management Platform. The scope, work steps and reporting schedule are defined at the start.
Do you use your own products in Red Team?
Yes. Depending on the scope, we use the Nesil Phishing and Voice Phishing, Nesil VOLTRA DDoS, Nesil CTI and Nesil ASM platforms. When source code analysis is required, we make use of the third-party solution OpenText Fortify.
What is delivered at the end of the test?
Depending on the scope, an executive summary, technical findings, an attack timeline, MITRE ATT&CK mappings and detection-response metrics are provided. Priority improvements are evaluated together with the Blue Team.