- Vocational Certification
CSRTM
RED TEAM MANAGER
measuring competence, acknowledging excellence.
CSRTM is the pinnacle of the assessments we offer, and is aimed at those working at the highest level with experience managing Red Team projects. This comprehensive and innovative assessment breaks the mould when assessing competence, experience and appropriate measures, based on a range of KSATs (Knowledge, Skills and the Ability to carry out Tasks). It includes a presentation based on a real world scenario, a written assessment and an interview – providing the most well-rounded overview of a practising Red Teamer on the market.
“Having been active in Cyber Security for over 25 years, measuring a professional Cyber Security consultants skills and readiness, in my opinion, has always been a challenge, being able to identify critical tradecraft, skills and knowledge of an individual is key to endorsing a standard in the industry that can be trusted and relied upon by the cyber security community, The Cyber Scheme have absolutely nailed it with this exam format, from preparation, demonstration, tradecraft and knowledge measurement! They have my full backing personally and professionally!”
Shaun Peapell, Rootshell Security
A Red Team Manager (RTM) is responsible and accountable for the planning, team selection, tasking, risk analysis/management and overall quality assurance of engagement report(s). It is NOT JUST a technical role and needs to be assessed in a way that reflects the holistic approach required.
The Cyber Scheme have undertaken extensive research over the past two years into the assessment and procurement landscape around the role of a Red Team Manager. This involved the creation of an Advisory Working Group consisting of principal organisations involved in the delivery of Red Team projects, as well as surveys carried out with our Sponsor companies, and the wider community.
The result of this research has led us to the creation of CSRTM – an innovative assessment aimed at recognising the core competency of a Red Team Manager, including negotiation techniques, communication skills, the ability to set and change direction and technical tradecraft.
We are not assessing technical ability…
We have created an innovative approach to assessing the competence of candidates as a result of extensive research and development with our Advisory Working Group and the industry.
The four elements give candidates the chance to provide evidence of their competence to be a Red Team Manager by meeting the KSATs.
The process will consist of:
- Candidate will be given a Red Team scenario and asked to prepare a presentation against set criteria.
- Presentation (see below)
- Written assessment – long form questions.
- Interview/professional discussion.
It is unlikely that candidates who have not had exposure to real live fire Red Team exercises will be able to gather sufficient evidence to pass the assessment.
The face to face interview will be conducted by Cyber Scheme Red Team Manager assessors who are experts in this domain.
Assessment Process
The assessment uses a multi-faceted approach to assess a candidate’s knowledge, skills and abilities as a Red Team Manager.
Scenario presentation preparation
You will be sent a detailed Red Team scenario on which to base your presentation.
Details provided will include organisational information, key threat actors, a comprehensive brief and all appropriate network, information and ancillary systems.
Candidates will be expected to prepare a 30 minute presentation against the scenario, which will need to be submitted prior to the assessment day. We recommend that you take 2-3 weeks to work on your presentation, before attending the written assessment.
Written assessment
In the written assessment, you will be presented with a series of scenarios or situations, typical of those that arise during a Red Team engagement and asked questions relating to them. You will be required to provide long form written responses.
The situations presented are chosen to represent day-to-day tasks that are likely to arise when working as a red team manager and provide an opportunity for the candidate to provide evidence of their knowledge, skills and abilities in relation to these. The questions are designed to cover a wide selection of the KSATs defined for the role.
Questions are designed to give candidates the opportunity to provide evidence of thought processes and the ability to make realistic and proportionate decisions. Candidates should draw on their real life experience and knowledge.
Written assessment (long and/or shortform questions). 2.5 – 3 hours.
Scenario presentation
Candidate presents wireframe scenario.
Presentation of pre-work to assessor – ½-1 hour.
Interview
An interview will be the final step in the process.
Interview after written assessment to interrogate further some of the themes that have come up in responses to written work and other topics relating to the KSATs – 1-1.5 hours.
Thank you to our Advisory Working Group for their involvement in the creation of this assessment:
- Accenture
- Cyberis
- KPMG
- NCC Group
- Pen Test Partners
- PwC
- QinetiQ
- WithSecure
- UK Cyber Council Technical Advisory Board
- Partners of The Cyber Scheme.