- Capability
- Cyber Operations
- Lead
- Joey Victorino — personally led
- Basis
- Written authorization · rules of engagement agreed before start
- Contact
- joey@victori.no
Test the defenses before an adversary does.
You need to know how a capable adversary could reach what matters — before one arrives, or after one has been evicted and you need proof the fixes hold.
What I do
Red team & adversary simulation
Objective-led operations against attack paths, identity, cloud, endpoints, and detection.
Exposure assessment
The external picture: what an adversary can discover, reach, exploit, or combine — and which paths change the outcome.
Control & detection validation
Whether the controls you paid for actually alter an attack, with evidence for the ones that don’t.
Offensive work begins only after written authorization, verified scope, and agreed rules of engagement.
What you get
The attack paths that actually reach something worth reaching, ranked by consequence, each with the evidence behind it and the change that closes it. Written twice: once for the people who approve the budget, once for the engineers who do the work.
It arrives as a written conclusion in the format of the sample memorandum: the question, the evidence reviewed, the assumptions it rests on, the findings, the unknowns, and what to do next. You can read that format before you call.