Why Gectiv?
Two reasons, both of which you can verify before committing to anything. First, we advise against engagements you do not need: if a narrower test, or no test at all, would answer your question, we say so during scoping, and the scoping notes are yours to keep either way. Second, the standard applied to every engagement was formed in environments with mature, well-resourced defence teams, where only careful and thorough work produces results. That standard does not change with the size of your organisation.
Penetration test or red team?
If you want to know what is wrong with a system, a penetration test. If you want to know whether your organisation would notice and stop an attacker, a red team. Most first engagements should be a penetration test; a red team is most useful once the obvious has been fixed.
What drives the cost?
Scope and depth: the number of applications, roles and environments; whether testing is authenticated; whether the cloud environment and the people are included. A clear scope gives you a price up front rather than an open-ended day rate.
Will testing disrupt the business?
Testing is coordinated with you: time windows, systems to leave alone, and a way to pause at any moment. Destructive actions are never taken without explicit agreement. Red teams are designed to be quiet; that is the point of them.
What do we need to prepare?
For a penetration test: test accounts, a decision on staging versus production, and a contact who can answer questions quickly. For a red team: a small trusted group who know, and everyone else who does not.
Can the engagement be run remotely, and in which languages?
Engagements are run remotely by default, in English or French. On-site work, where it is needed, is agreed during scoping.