Inside the CSRTM Assessment: What Successful Red Team Managers Do Differently

As one of the architects of the Cyber Scheme Red Team Manager (CSRTM) qualification, Gemma Moore, Partner at Cyberis Reply, helped define the knowledge, skills and judgement that the profession expects from a successful Red Team Manager. In this latest article, Gemma shares what assessors are looking for and explains why successful red team management is about far more than technical expertise alone.

For the Cyber Scheme Red Team Manager qualification, we have mapped the knowledge, skills and abilities needed by a red team manager along with the tasks they need to conduct; the assessment has been designed to assess evidence from candidates about their capability against these “KSAT”s. The role is complex and multi-faceted, and a Red Team Manager requires substantial knowledge and experience across many different domains in order to perform well.

So what do we expect of a successful candidate for the qualification?

There are many factors that influence the way a red team exercise or cyber attack simulation runs, including:

  • The outcomes of the exercise and the learning objectives – this is informed by why the simulation is taking place, what sort of controls and assumptions are being challenged and what the target organisation wants to learn from conducting the exercise.
  • The legal and regulatory framework in which the target organisation and the red team are operating.
  • The risk appetite of the target organisation requiring the exercise. How much risk are they keen to accept – risk to their systems, risk of upsetting their staff, risk of damaging internal relationships?
  • The risk appetite of the red team.
  • The ethical boundaries of the target organisation and of the red team. A successful red team operation needs to be closely managed to ensure success. The Red Team Manager has to account for these diverse factors and ensure that:
  • The operation can continuously move forwards towards the desired outcomes of the exercise and achieve the learning outcomes
  • The operation functions inside the law, avoiding criminality and minimising any potential civil consequences
  • The operation functions inside the risk tolerance of both the target organisation and the red team itself
  • The operation functions within a robust ethical framework respecting the boundaries of both the target organisation and the red team.

 

To achieve a passing grade for the CSRTM qualification, a candidate must demonstrate that they have the capability to achieve all of these. The Red Team Manager is the expert in charge of the delivery of the red team operation. They are a leader, who will implement risk management frameworks and enforce policies and procedures ensuring that things operate effectively. They need to ensure that their operators work within the agreed boundaries for the exercise, and as a subject matter expert, they need to provide clear and consistent guidance to those commissioning the exercise.

Whilst there is no such thing as a “risk-free” adversary simulation, the Red Team Manager must ensure that they and their team do not take any unnecessary risks with themselves or their clients. Whilst the Red Team Manager does not need to be an expert in deeply-technical operating fields, they must understand the technical aspects of red team methodology with sufficient detail to be able to identify, interpret and manage the risks of these technical operations. To keep an operation progressing, the Red Team Manager needs to be able to dynamically assess and reassess plans in the light of unfamiliar situations or new information. The operating landscape changes flexibly during an operation and it’s crucial that the Red Team Manager is able to dynamically assess risk and adapt instructions when new information becomes available. When faced with roadblocks – such as excessive risk, ethical problems or practical constraints – the successful Red Team Manager is able to creatively identify alternative approaches and strategies that allow the exercise to continue productively but within acceptable parameters.

The Red Team Manager is a coordinator and project manager. A successful Red Team Manager therefore needs resource management and stakeholder engagement skills to ensure a simulation is run on time and to budget. A candidate needs to be able to communicate effectively with stakeholders at many different levels – from deeply technical red team operators to Board-level budget holders. They must be capable of translating business objectives into technical instructions, and simultaneously capable of translating detailed technical findings into actionable business risks. Ownership is a very important attribute for a Red Team Manager; they are the decision-maker and the accountable person for the red team whilst they are operating.

It’s crucial that an operator working within an exercise is able to rely on the Red Team Manager to provide guidance, steering and decisions through the exercise. The successful candidate will demonstrate throughout the assessment that they take accountability for the activities of their red team and own the consequences of those decisions.

The Red Team Manager needs to understand the legal and regulatory framework in which they are operating. We don’t expect them to be a legal expert, but we do expect a Red Team Manager to be able to identify lawful and unlawful actions and explain what aspects of law apply in various situations. We also expect a Red Team Manager to be able to explain to others (for example, to a client or to a regulator) why a particular aspect of a simulation might not be able to be exercised legally and what alternatives might be considered as a result. As well as understanding criminality, the Red Team Manager needs to understand the potential exposure to civil consequences of their operations – a covert red team may risk damage to reputation and relationships in such a way as to incur liability. A Red Team Manager must understand their own risk appetite and ethical boundaries. The matter of risk and ethics is not always clear-cut, and a Red Team Manager needs to understand and apply their own risk management and ethical framework to the work that they do.

When reviewing a candidate, we will assess them for consistency in applying their approach to risk and ethics, and may also challenge these to ensure that they can defend their position appropriately. A red team exercise is inherently risky, and inevitably requires ethical decisions to be made – whilst we do not expect actions to be risk-free, we do demand that risks are taken consciously and in full appreciation of their magnitude with the appropriate safeguards in place.

Ultimately, as the accountable person, a Red Team Manager should be able to withstand challenges to their decisions and be able to defend their position; in a situation where stakeholders are pushing for dangerous or unethical actions to be conducted, the Red Team Manager must be capable of managing and steering these stakeholders towards a safe pathway and preventing damage.

The structure of the Cyber Scheme Red Team Manager exam has been developed to allow these capabilities to be demonstrated through various forms of evidence – including a selection of written work, the presentation of a plan against a realistic scenario and an interview with a subject matter expert. Ultimately, successful candidates have demonstrated to the assessors that they have the ability, skills and knowledge to perform the Red Team Manager tasks, running a red team exercise safely from start to finish.

“The inclusion of the Cyber Scheme Red Team Manager qualification within the CBEST Implementation Guide recognises its relevance as evidence of the capability needed to manage complex intelligence-led red team exercises safely, lawfully and effectively.”

To contact Gemma and Cyberis Reply:

Contact Form | Visit the website cyberis.com

To learn more about CSRTM and book an assessment click here.