An OnyxTrace brand

Grey teaming starts on the inside.

A grey team tests an organisation the way a real adversary would: from within, and across the lines between departments, systems and buildings.

What it is

An adversary who is already inside.

Most security testing starts at the perimeter. A grey team starts where the damage usually happens: inside the organisation, with the access, routines and trust that an employee, contractor or supplier already has.

We look at how people, processes and money can be misused, and at the places where the handover between two departments leaves a door open.

How grey teaming relates to the other security teams
Our approach

Mostly from the inside. From the outside when the case calls for it.

Our starting point is the insider threat: what a malicious employee, a compromised supplier or a contractor with too many rights could actually do. When an assignment needs it, we work as a pure outsider instead, with no access and no introduction.

Organisations bring us in for:

  • Process and financial exploitation: workflows, contracts and payment flows that allow fraud or hide liabilities.
  • Insider technical attacks: insider knowledge combined with technical attacks on your most critical systems.
  • Human-centric vulnerability testing: social engineering, and the other ways people become the route around your controls.
  • Pentesting: technical testing of systems and applications, with or without insider context.

Every assignment ends in the same deliverable, evidence-based risk clarity. You get proof of what an adversary could reach, written so your own teams can act on it, from a party that does not sell the fix.

Let’s Talk

A simple, confidential conversation is the best starting point. We’re here to be your sparring partner — not just another vendor.

Talk to OnyxTrace