Volkis emulated an Advanced Persistent Threat over 5 months, giving the Company’s Blue Team a live opportunity to respond to a highly realistic breach.
The Company is a large insurance provider that wished to remain anonymous in public-facing documents.
The Challenge
The Company had traditionally conducted annual penetration tests with other providers. However, they were looking to take things further beyond the limitations of a standard penetration test — expanding the scope to gain a deeper, more holistic understanding of their security posture.
The Company partnered with Volkis to experience how a real attacker might target their business, attempting to breach sensitive Personally Identifiable Information (PII) from the internet. The assessment was designed to uncover hidden vulnerabilities and give the Company’s Blue Team a live opportunity to respond to a simulated, yet highly realistic, breach — allowing gaps in incident response to be plugged, and giving staff as close to real-world experience as possible in dealing with a breach.
Why Volkis
At first, there was some understandable hesitation among the board members. As the Non-Executive Director shared, “We just wanted to be sure that we could get as much experience as possible,” and that “sometimes in the corporate world… we think you have to be big to be good.”
But after meeting with Volkis, the Company saw, first-hand, a unique combination of flexibility and professionalism. They realised we could work together to tailor the Red Team engagement to their needs and deliver exceptional results. The Company enjoyed direct access to the consultants — the same people who perform the work — rather than dealing with layers of management.
The Exercise
The Red Team exercise spanned five months, encompassing multiple campaigns, some successful, others unsuccessful. The team was tasked with emulating an Advanced Persistent Threat (APT), identified as the most likely and potentially damaging adversary to the Company.
Primary objectives were to obtain PII of specific customers, compromise VIP assets such as payroll or executive network shares, and map the network topology. Secondary objectives included finding configuration documents for an internal asset, increasing the security level of an internal user, obtaining source code of one or more web modules, changing bank account details of a supplier or an employee, and downloading the contents of a database table to a network share.
OSINT and infrastructure setup. Open Source Intelligence (OSINT) gathering enabled Volkis to learn as much as possible about the Company without interacting with any of their infrastructure — identifying assets, staff, email addresses, physical addresses, password leaks, documents, and more. Custom phishing and Command and Control (C2) infrastructure was also built for use in later campaigns.
External campaigns. The Red Team conducted multiple targeted phishing campaigns, each carefully crafted to test the resilience of the Company’s defences — including fake help desk tickets, insurance complaints with malicious Excel attachments, and online cyber security training requests. The help desk campaign successfully captured a username and password, demonstrating the team’s ability to breach the first line of defence, although multi-factor authentication (MFA) remained a barrier against unauthorised access to internet-facing services. The team went on-site to the Company’s office, where the wireless network extended into publicly accessible areas, but attempts to leverage the captured credentials for network access were unsuccessful.
Implant. As the external campaigns did not result in access to the internal network, and physical intrusion was out of scope, the Red Team played a threat card — a device installed on the Company’s network by a trusted insider, providing access to the internal network via a VPN connection.
Lateral movement. By chaining a printer misconfiguration with lateral movement techniques such as “Pass-the-Cert”, the Red Team managed to gain Domain Admin privileges, and used that access to explore the Company’s assets in Microsoft 365 and its accounting applications — achieving all but one of the Red Team’s objectives.
Incident response. Once the Red Team had achieved as many of the Company’s goals as possible within the given time frame, the team escalated its activity until its presence was detected by the Blue Team, simulating a “breach” scenario that activated the Company’s incident response plan. This realistic engagement gave the Blue Team hands-on experience identifying critical gaps in their defences and strengthening their response capabilities.
Purple Team Workshop and Executive Debrief. After the exercise wrapped up, Volkis hosted a collaborative workshop with the Company’s Blue Team to review the exercise from both the offensive and defensive angles, walking through each campaign step-by-step to identify which actions were logged, detected, or missed. An Executive Debrief then gave the leadership team key insights into the engagement: what was done, the vulnerabilities discovered, and strategic actions the Company could take to enhance security moving forward.
The Results
Were the Company’s goals achieved? Yes. The exercise went beyond testing defences — it highlighted areas where alerting systems needed fine-tuning, uncovered critical vulnerabilities that had been assumed fixed, and empowered the internal security team to refine and enhance their incident response policies.
“The report was a lot more comprehensive than we expected. Volkis provided a high level of detail on findings and recommendations… We came out with a lot more learnings and improvement activities than we would achieve out of a standard penetration test.”
Company Board Member
Large Insurance Provider