How we started

It began as a red team assignment at VWS.

The three of us met on an assignment at the Dutch Ministry of Health, Welfare and Sport.

It started as classic red teaming, with an external attacker, a defined scope and targets agreed in advance. Over more than a year we worked with the ministry's CISO to turn it into an assignment without a scope. We agreed on what mattered to the organisation and left the route to us.

Why no scope

Without a scope, we could think like an adversary.

An attacker never asks which systems are in scope. Once we were allowed to work the same way, we started combining methods that normally live in separate assessments. A call to reception gives you a name and an email address, a copied supplier badge opens a door, and a contractor account with too many rights connects the two.

Each step can be explained within its own department. The chain as a whole appears in no risk analysis. New legislation calls this a hybrid threat, and it is where our work started to add value.

What we found

Each department guards its own domain. Nobody guards the seams.

Assignment by assignment our approach became more structured, and one pattern kept returning. The weaknesses we found were rarely inside a department. They sat where two parts of the organisation touch: where IT hands over to facilities, where HR hands over to access management, where a contractor falls between two owners.

Nobody owns that space, so nobody tests it. That is where we work.

Where grey teaming sits between the other teams

Looking for a grey team?

The people who developed this approach to grey teaming founded OnyxTrace together. If you are looking for a grey team, OnyxTrace is one of the parties you can approach. If they are not the right fit, they will gladly help you find someone closer to home.

Talk to OnyxTrace