Login to profile
NCC Group

NCC Group is a people-powered, tech-enabled global cyber security and software escrow business. Driven by a collective purpose to create a more secure digital future, NCC Group has been at the forefront of testing and providing industry-leading services for over 30 years.

 

Through continuous innovation, timely audits and assessments, our technical expertise enables us to offer threat-led penetration testing, offensive security, and regulatory assurance.  All backed by extensive research, threat intelligence, and real-world experience in handling threat actors.

 

Our accredited consultants specialise in Penetration Testing, Attack Simulation, Incident Response, and Threat Intelligence, providing compliance testing and audits.

Contact: NCC Group
E: [email protected]

T: +44 (0) 161 209 5200

Membership Start Date: 01 Jan 2008

No. of Employees: 1,000-4,999

CREST Accreditations

CREST Partner Programmes

Other Accreditations and Services

Intelligence Led Penetration Testing (STAR)

Contact

Lloyd Bruce ([email protected])

+44 (0) 161 209 5200

https://www.nccgroup.com/globalassets/service-pages/documents/security-consulting/technical-security-consulting/crest-star-and-cbest.pdf

 

NCC Group’s Full Spectrum Attack Simulation practice specialise in the delivery of Intelligence-Led/Threat-Led Penetration Testing (ILPT/TLPT). With extensive experience in delivering these engagements in collaboration with NCC Group’s Global Threat Intelligence practice, NCC Group are well-positioned to support you as both Threat Intelligence and Pentest Providers. NCC Group have a long-standing history of delivering ILPT/TLPT engagement as well as supporting regulatory bodies globally in the creation and improvement of their ILPT/TLPT Frameworks. From CBEST, STAR FS and CREST STAR in the UK, TIBER in the EU, iCAST in Hong Kong, AASE in Singapore, FEER in Saudi Arabia and CORIE in Australia NCC Group has a fully qualified and experienced team supporting the financial services sector. Our team have a vast amount of experience in delivering ILPT/TLPT to non-finance sector organisations through frameworks such as GBEST, TBEST and GCASE. Our years of experience in the regulatory red teaming space, particularly with TIBER, also means that we have an experienced and qualified team able to support organisations through DORA TLPT. NCC Group’s Attack Simulation services are focussed on the delivery of threat intelligence-led red team scenarios, delivered by our world-class red team, to replicate real world threats. We help organisations to understand if they are susceptible to and can Prevent, Detect or Respond to real-world threats by demonstrating what a threat actor could achieve and the potential impact this may have. Supported by NCC Group’s exploit development and research group, our red team is comprised of dedicated and experienced operators capable of providing advance attack simulations. Armed with a combination of commercially available, open-source and proprietary tooling and tradecraft, NCC Group’s Full Spectrum Attack Simulation practice can support you with the delivery of a CREST STAR G-Cloud:

·https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/527869061275747

CREST Qualified Consultants:

·CREST Certified Simulated Attack Manager

·CREST Certified Simulated Attack Specialist Pentest Overview:

·Test and Risk Management Plans

·Execution of Threat intelligence led Scenarios

·Comprehensive Reporting & Debriefs

·Purple Teaming

·D&R Capability Assessments

·Purple Teaming & Replay Workshop Pentest Approach

·In Phase – gaining initial access to an environment and establishing persistence.

·Through Phase – Discovery, privilege escalation through exploitation or credential access, and lateral movement

·Out Phase – actions on objectives again important business services

CREST Qualified Consultants:

  • CREST Certified Simulated Attack Manager
  • CREST Certified Simulated Attack Specialist
  • Contact: NCC Group