AmberWolf

AmberWolf

Red Teaming
Security Testing

Key Info

Summary

3 years of membership
United Kingdom
Europe
10-49 employees
CREST Accreditations & Specialisms
Penetration Testing
Threat Led Penetration Testing (Formerly STAR ILPT)
TLPT-FS Threat Led Penetration Testing
Company Certifications Awarded
ISO27001
UK NCSC Cyber Essentials
UK NCSC Cyber Essentials +

About

At AmberWolf, we take pride in our commitment to providing high-quality security services. Our approach is underpinned by significant experience with threat-led Red Teaming within frameworks such as the Bank of England’s CBEST Scheme, among other international equivalents. This background allows us to offer services that are both adaptable and closely aligned with the specific needs of our clients. We aim to support client organisations in identifying and addressing security challenges, offering guidance and support on immediate solutions for risk reduction/remediation and long-term strategies for broad improvement across the enterprise. In the dynamic field of cyber security, our practice of… Read more

At AmberWolf, we take pride in our commitment to providing high-quality security services. Our approach is underpinned by significant experience with threat-led Red Teaming within frameworks such as the Bank of England’s CBEST Scheme, among other international equivalents. This background allows us to offer services that are both adaptable and closely aligned with the specific needs of our clients. We aim to support client organisations in identifying and addressing security challenges, offering guidance and support on immediate solutions for risk reduction/remediation and long-term strategies for broad improvement across the enterprise.

In the dynamic field of cyber security, our practice of simulating realistic cyber threats contributes to the depth of our understanding and effectiveness in this area.

Read less

Cybersecurity Focus

Security Testing (30%)
Red Teaming (30%)
Governance, Risk, and Compliance Advisory Services (10%)
Cyber Assurance (5%)
Cybersecurity Maturity Assessment (5%)
Incident Management (5%)
Cyber Management (5%)
Secure Design (5%)
Threat Intelligence (3%)
Cybersecurity Training (2%)

Technical People
26-50
Delivery Model
Hybrid
On-site / Customer Premises
Remote / Off-site

Specialisms

CREST Red Teaming - Threat-led Pen Test Badge

AmberWolf’s certified targeted attack services are conducted by our seasoned red team experts and backed by real-world threat intelligence. We specialise in simulating common threats such as phishing, browser, and email-based exploits, all the way to comprehensive assessments of the whole cyber kill-chain.

The outcome of each engagement is a tailored report, with realistic, actionable, prioritised, and detailed recommendations for remediation and security improvement, augmented by a high-level presentation to C-level executives or senior stakeholders.

STAR-FS tests are intelligence-led but require significantly less input from regulatory bodies, allowing the faster production of deliverables that enable organisations to uplift their security posture and improve their detection and response capabilities.

AmberWolf maintain a skillset that complies with and exceeds the STAR-FS requirements to have CCSAM and CCSAS consultants with a minimum of four thousand hours of testing financial institutions.

Partner Assured Services

CBEST logo

CBEST is the original regulated TLPT (Threat-Led Penetration Testing), developed by the Bank of England as a supervisory tool for testing resilience of regulated financial service entities. These exercises involve performing multiple red-team scenarios against an organisation without the wider knowledge of their defensive teams, testing their people, process and technologies in resilience to attack as well as the detection and response capability of targeted organisations.

Within the UK market CBEST is generally considered the highest level of accreditation awarded to cyber security consultancies within the UK, with AmberWolf being one of a small number of accredited organisations.

Our team have deep-rooted experience of performing CBEST engagements, dating back to 2016, with staff having consistently held CCSAS and CCSAM qualifications since 2015. Our staff have delivered CBESTs for some of the world’s largest financial institutions, as well as delivering similar engagements under other regulated schemes including TIBER, ICAST, AASE and CORIE.

AmberWolf is built around its expertise in attack-simulation capabilities. Our breadth of experience delivering these engagements and technical capability enables simulation of offensive activities within live production IBS (Important Business Services) systems whilst managing operational risk. AmberWolf understands some of the unique challenges facing many financial service organisations, with our balanced reports detailing identified risks and remediation advice tailored to the technology stacks and existing business processes within the organisation.

STAR-FS Intelligence-led Pen Test

Other 3rd Party Aligned Services

TIBER-EU is the TLPT (Threat-Led Penetration Testing) scheme for European financial services. Originally based on the Bank of England’s CBEST scheme. TIBER engagements focus on testing Cyber Resiliency for the EU financial services market.

Our team have deep-rooted experience of performing regulated TLPT engagements, dating back to 2016, with staff having consistently held CCSAS and CCSAM qualifications since 2015. Our staff have delivered CBESTs for some of the world’s largest financial institutions, as well as delivering similar engagements under other regulated schemes including CBEST, ICAST, AASE and CORIE.

AmberWolf is built around its expertise in attack-simulation capabilities. Our breadth of experience delivering these engagements enables simulation of offensive activities within live production IBS (Important Business Services) systems whilst managing operational risk.

GBEST is a scheme designed to test the cyber resilience of government departments, based on Bank of England’s CBEST scheme with a focus on testing resilience and demonstrating impact of sophisticated cyber attacks against government services.

AmberWolf is one of a very small number of firms with staff who have experience of performing GBEST engagements. We are happy to have the capability to provide this service to UK government departments.

Project Profile

Client Size

Enterprise Business (80%)
Large Business (20%)

Project Size

£100k-£500k (60%)
£50k-£100k (40%)

Expertise & market focus

Target Sectors

Financial Services (40%)
Information Technology (20%)
Automotive (10%)
Energy (10%)
Government/Public Sector (10%)
Telecommunications (10%)

Tech Focus

Identity & Access Management (30%)
Cloud & Hybrid Environments (20%)
Endpoint & Operating Systems (20%)

Partner Assured Services

UK BoE CBEST Threat Led Penetration Testing
UK BoE STAR-FS Threat Led Penetration Testing

Other 3rd Party Assured Services & Company Certification Awarded

ISO27001
UK NCSC Cyber Essentials
UK NCSC Cyber Essentials +