Grey teaming starts on the inside.
A grey team tests an organisation the way a real adversary would: from the inside, combining digital, physical and human attack vectors across the lines between departments.
An adversary who is already inside.
Most security testing starts at the perimeter. A grey team starts where the damage usually happens: inside the organisation with the access, routines and trust that an employee, contractor or supplier already has.
A grey team looks at how people, processes and money can be misused. It also looks at the handovers between departments where responsibilities do not always fully match.
How grey teaming relates to the other security teamsMostly from the inside. From the outside when the case calls for it.
The starting point is usually the insider threat: what someone with legitimate access could do with bad intentions, whether that is an employee, a supplier or a contractor. When an assignment calls for it, a grey team can also act as an outside threat, but its focus stays on threats with an insider component.
Organisations bring in a grey team for:
- Process and financial exploitation: workflows, contracts and payment flows that allow fraud or hide liabilities.
- Insider technical attacks: insider knowledge combined with technical attacks on your most critical systems.
- Human-centric vulnerability testing: social engineering and the other ways people become the route around your controls.
- Pentesting: technical testing of systems and applications as one part of a wider grey team assignment.
A grey team assignment ends in evidence-based risk clarity: proof of what an adversary could reach, written so the organisation's own teams can act on it. That works best when the grey team does not also sell the fix.
Looking for a grey team?
The people who developed this approach to grey teaming founded OnyxTrace together. If you are looking for a grey team, OnyxTrace is one of the parties you can approach. If they are not the right fit, they will gladly help you find someone closer to home.
Talk to OnyxTrace