Skip to main content
CERT-In — Empanelled security auditor since 2008

Breach and Attack Simulation Services That Prove Whether Your Defences Actually Work

Your firewalls, EDR, SIEM, and SOC exist to stop attacks. BAS tells you if they actually do. Human-led control validation with results mapped to PCI DSS, ISO 27001, and SEBI CSCRF.

6,700+
Assessments
1,000+
Clients
150+
Team
2006
Founded

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

Three different questions

BAS, penetration testing and red teaming answer different things

They are routinely sold as alternatives. They are not, and buying the wrong one produces a report that answers a question you did not have.

ExerciseThe question it answersWhat it produces
Penetration testing Can this system be broken into, and how? Findings in the system, with reproduction steps and fixes
Breach and attack simulation Do the controls we already bought actually detect and stop known techniques? A control-by-control verdict: blocked, alerted, logged silently, or missed entirely
Red teaming Can a determined adversary reach a defined objective without us noticing? A narrative of one path, and what the defenders saw at each step

Penetration testing

The question it answers
Can this system be broken into, and how?
What it produces
Findings in the system, with reproduction steps and fixes

Breach and attack simulation

The question it answers
Do the controls we already bought actually detect and stop known techniques?
What it produces
A control-by-control verdict: blocked, alerted, logged silently, or missed entirely

Red teaming

The question it answers
Can a determined adversary reach a defined objective without us noticing?
What it produces
A narrative of one path, and what the defenders saw at each step

What gets validated

The stack you have already paid for

Most tested

Endpoint detection and response

Whether the agent detects the technique, whether it blocks or only alerts, and whether the alert reaches anyone. Deployed coverage is checked too, because the gap is often a subset of hosts without the agent at all.

The silent failure

Detection rules and alerting

Whether the event was recorded, whether a rule fired, and whether anything downstream acted. Logged silently is the most common and most dangerous outcome: the evidence exists and nobody was told.

Boundaries

Network and perimeter controls

Firewalls, intrusion prevention, web application firewalls and segmentation, tested against the techniques that cross them.

The common entry

Email and web gateways

Delivery of the payload types and lures that actually arrive, testing the control and not the user.

Escalation

Identity and directory defences

Whether the techniques used against directory services and privileged accounts are detected before they succeed.

Egress

Data loss controls

Whether an exfiltration path is noticed, which is the question an incident makes urgent and nobody asks beforehand.

Reading the result

Four verdicts, and the middle two are why this is worth doing

Four verdicts, and the middle two are why this is worth doing
StateWhat it meansWhat follows
Blocked The control prevented the technique from executing. What you paid for. Worth confirming, because a control assumed to block and merely alerting is a different security posture from the one on the architecture diagram.
Alerted The technique executed and an alert reached a human who could act. An acceptable outcome when detection is the design. It becomes a problem when the same technique was believed to be prevented.
Logged silently The event was recorded and no rule fired, so nobody was told. The single most valuable finding a simulation produces. The evidence existed and the organisation learned nothing from it, which is exactly what a real intrusion looks like from the inside.
Missed No prevention, no alert, no record. A blind spot, and the honest version of the coverage map. Often a licensing gap, an agent that was never deployed, or a rule disabled during a past false-positive storm.
Key
  • Working as intended
  • Check it matches the design
  • Why the exercise pays for itself

Where it fits in compliance

Useful evidence, and stated accurately

Control validation produces evidence that is genuinely useful in a compliance conversation: a documented, dated statement of whether specific controls detect and stop specific techniques, mapped to the control requirements of PCI DSS, ISO 27001 and SEBI CSCRF. It is worth being precise about the SEBI position, because it changed and a great deal of vendor copy has not caught up. CSCRF guideline DE.CM.S3 3.c originally read that regulated entities shall deploy solutions such as BAS, CART, decoy and vulnerability management. The technical clarifications of 28 August 2025 restated it: it is recommended that regulated entities consider deploying a range of security solutions in consultation with their IT Committee, such as threat simulation, vulnerability management and decoy systems. The acronyms were dropped from the instrument and the obligation was softened to a recommendation. We run this capability and think it earns its place on merit, and a buyer should know they are choosing it. If a vendor tells you the framework makes it compulsory, ask which clause, and then read the clarification of 28 August 2025.

Methodology

What happens between kickoff and the report

Every engagement follows this process through Lemon, our proprietary audit management platform.

Discovery
01

Threat Landscape and Scope Definition

We work with your security leadership to identify the most relevant threat scenarios for your industry, regulatory obligations, and technology stack. Scope is defined across control categories, and success criteria are established upfront. ShadowMap provides immediate external attack surface visibility to inform scenario design.

02

Control Inventory and Baseline

We document your entire defensive stack including network controls, endpoint agents, SIEM rules, DLP policies, email gateways, and SOC procedures. This baseline ensures simulations are designed to test specific control behaviours, not just generic attack vectors.

03

Attack Scenario Design

Senior consultants design multi-stage attack chains that mirror real threat actor behaviour relevant to your organisation. Scenarios cover initial access, execution, persistence, privilege escalation, lateral movement, collection, exfiltration, and impact. Each scenario is mapped to specific controls it should trigger.

Testing
04

Controlled Attack Execution

Our team executes simulations in a controlled, coordinated manner using a combination of proprietary frameworks and manual attacker tradecraft. Simulations run across the full kill chain with careful monitoring to ensure no unintended business disruption. Lemon tracks every test case, artefact, and outcome in real time.

05

Human-Led Analysis and Interpretation

This is where Security Brigade fundamentally differs from tool-only BAS. Every simulation result is analysed by a senior security consultant who interprets why a control failed, what an attacker would do with that gap, and how to fix it. Raw pass/fail data is transformed into actionable intelligence with business context.

Delivery
06

Compliance Mapping and Reporting

Findings are mapped to PCI DSS, ISO 27001, and SEBI CSCRF control requirements. Reports are delivered in multiple formats for technical teams, security leadership, and board-level stakeholders. Every finding includes specific remediation guidance, not generic recommendations.

07

Retest and Validation

After your team remediates findings, we retest affected controls to confirm fixes are effective. Lemon tracks the complete vulnerability lifecycle from initial finding through remediation to validated closure, providing auditable evidence for compliance reviews.

"We swap auditors every two years as policy. Security Brigade is the only firm we've kept continuously since 2016. The difference is Lemon — every engagement follows the same methodology, every finding gets three-layer review, and our RBI auditors have never questioned a report. That kind of consistency across 300+ annual assessments is rare."
CISO, Top-3 Indian Bank
Chief Information Security Officer

Read more client stories →

FAQ

Breach and attack simulation, answered

What it validates and where it fits. Talk to our team about your control stack.

Contact us
Is breach and attack simulation required for SEBI CSCRF compliance?+
It is recommended, and the wording changed in 2025. CSCRF guideline DE.CM.S3 3.c originally read that regulated entities shall deploy solutions such as BAS, CART, decoy and vulnerability management. The technical clarifications of 28 August 2025 restated it as a recommendation that entities consider deploying a range of security solutions in consultation with their IT Committee, such as threat simulation, vulnerability management and decoy systems, and both acronyms were dropped from the text. The evidence a simulation produces is still useful in a CSCRF audit; a buyer should simply know they are choosing the exercise on merit.
How is this different from a penetration test?+
A penetration test asks whether a system can be broken into and produces findings in the system. A simulation asks whether the controls you already own detect and stop known techniques, and produces a verdict per control: blocked, alerted, logged silently, or missed. Most organisations need both, and they answer different questions, so buying one expecting the other produces a report about something you were not asking.
What is the most common finding?+
Logged silently. The event was recorded, no rule fired, and nobody was told. It is the most valuable result a simulation produces because it is precisely what a real intrusion looks like from the inside: the evidence existed and the organisation learned nothing from it. The fix is usually a rule, not a purchase.
Will this generate alerts and disrupt our operations?+
It should generate alerts, and that is the point. Scenarios are agreed beforehand, executed in a controlled sequence, and coordinated with whoever watches your alerting so the exercise is not mistaken for a real incident unless you specifically want it tested that way. Techniques with a plausible availability impact are scoped explicitly and never run by surprise.
How often should we run it?+
Annually for most organisations, and after change: a tool replacement, a major infrastructure shift, or a rebuild of your detection content. A simulation validates a configuration at a moment in time, so its value decays exactly as fast as your environment moves.

Stay protected between assessments with ShadowMap

Continuous attack surface monitoring: it discovers new assets, detects credential leaks, and alerts on new exposures the day they appear.

Learn about ShadowMap →

Find Out If Your Security Controls Actually Work

Request a scoping call to discuss breach and attack simulation for your environment. Our team will help you define the right scope, attack scenarios, and compliance mapping for your organisation.

Typically responds within 1 business day · No commitment required

Request a Scoping Call

The platform underneath

Every engagement runs on B-52.

Simulation answers whether a control fires, and the answer decays the moment anything changes. Running it on a cadence instead of on a calendar invitation is what the platform is for.

See the B-52 platform Built and run by Security Brigade