Adversary Simulation

CORIE Framework

Simulate nation-state-level attacks to assess and strengthen the resilience of Australia's financial sector against sophisticated cyber threats, guided by the CORIE framework.

Discuss an engagement
Objective
Financial sector resilience
Maturity
CFR-mandated institutions
Approach
Intelligence-led red team
Result
Critical Business Services evidence

Simulating advanced threats for financial sector resilience

The Cyber Operational Resilience Intelligence-led Exercises (CORIE) framework represents the highest standard of adversary simulation for Australia's financial sector. Developed by the Council of Financial Regulators (CFR), CORIE exercises simulate the techniques of sophisticated threat actors including nation-states, organised cybercrime, and advanced persistent threats (APTs).

SilentGrid conducts CORIE-aligned red team exercises to rigorously assess the resilience of financial institutions. Our engagements test the end-to-end security posture of your organisation, targeting technology, personnel, and incident response capabilities to uncover weaknesses before they are exploited by real attackers.

Why CORIE matters

A financial sector under threat

The financial sector remains one of the most targeted industries globally. CORIE tests whether an institution's defences hold up against evolving threats.

Regulatory and operational significance

For many financial entities, CORIE is a regulatory requirement mandated by the CFR, providing a proactive approach to achieving resilience against catastrophic cyber incidents.

Is CORIE the right fit?

CORIE is the Council of Financial Regulators' framework, so the exercise is built around financial sector threat profiles and Critical Business Services. Outside that sector, a red team engagement tests the same defences without the CORIE framing and reporting.

CORIE testing is ideal for

  • Banks, insurers, and payment providers mandated by the Council of Financial Regulators
  • Financial institutions aiming to proactively enhance resilience against APTs
  • Organisations seeking real-world insights beyond standard penetration tests
  • Entities prioritising resilience, compliance, and threat readiness

CORIE engagement lifecycle

SilentGrid follows the CORIE-mandated engagement lifecycle, which mirrors real-world attack chains while aligning with regulatory expectations.

  1. 01

    Threat intelligence and reconnaissance

    • Intelligence gathering aligned with financial sector threats
    • Client-provided threat intelligence integration for targeted scenarios
  2. 02

    Initial compromise

    • Simulating spear phishing, web application exploitation, and credential harvesting
    • Custom malware payloads to bypass security controls and gain foothold
  3. 03

    Persistence and lateral movement

    • Testing for Active Directory misconfigurations and privilege escalation
    • Moving laterally through internal environments to expand access
  4. 04

    Impact and objective execution

    • Simulating data exfiltration, financial fraud, or disruption scenarios
    • Testing resilience of Critical Business Services and essential functions
  5. 05

    Post-engagement review and uplift

    • Comprehensive technical and executive debriefs highlighting findings
    • MITRE ATT&CK mapping showcasing detection blind spots

Our approach

Advanced adversary emulation

We simulate the methods used by the most dangerous actors targeting the financial sector, mirroring tactics of ransomware groups, state-sponsored hackers, and insider threats.

Industry-specific targeting

CORIE exercises are tailored to reflect the unique attack paths and threat profiles facing financial institutions, ensuring relevance to your business model and infrastructure.

Critical Business Services focus

We help identify and prioritise Critical Business Services: those functions that, if disrupted, would significantly impact confidentiality, integrity, or availability of core financial systems.

Run it continuously

One CORIE exercise, or red teaming all year.

A single CORIE exercise tests your Critical Business Services against the threats facing the financial sector. Where those services change faster than the exercise schedule, CAOS (Continuous Adversary Operations Service) runs red team cycles through the year and retests each fix.

Explore CAOS

Deliverables and reporting

Our CORIE engagements provide strategic insights for both operational teams and executive leadership:

Attack execution report

Step-by-step documentation of red team activities with actionable recommendations

Executive summary

Board-level insights on business risks and strategic recommendations

Tactical uplift workshops

Post-engagement sessions with custom remediation roadmaps

Critical Business Services analysis

Assessment of systemically important services and their resilience

The team CORIE requires

The framework specifies the roles a provider must field. Here is who fills each one and what stands behind them:

Red Team Lead

Our founders have delivered CBEST engagements in the United Kingdom, the intelligence-led framework CORIE was modelled on, and have led red team exercises against major Australian banks and ASX-listed organisations.

Red Team Specialist

Credentials across the delivery team include OSEE, OSCE3, OSEP, OSWE, GXPN, CRTO, CRTE, CRTP and OSCP, alongside CREST registrations. SilentGrid is a CREST ANZ approved company.

Exploit Development Specialist

Consultants certified OSEE and OSED who have discovered and responsibly disclosed previously unknown vulnerabilities in commercial software from Hexagon, VMware and Commvault. The advisories and the exploit development behind them are published at /security-advisories.

Threat intelligence

Delivered by a specialist intelligence partner under our management, so the targeting package is produced by dedicated analysts rather than by the operators who will execute against it.

Why SilentGrid

SilentGrid's consultants are hand-picked, and between them they have delivered red team engagements globally over decades, including CBEST for UK financial institutions and CORIE engagements in Australia. Their sector experience covers banking and financial services, insurance, government, critical infrastructure and healthcare.

Consultants find 0-day vulnerabilities in commercial software and speak or teach at security conferences. That research produces the custom tooling used to bypass EDR and network controls, and keeps techniques current with the threat actor being simulated. The methodology follows concepts set out in NIST, OWASP, PTES and OSSTMM.

CREST ANZApproved company

Individual credentials across our team include

  • OSEE
  • OSCE3
  • OSED
  • OSEP
  • OSWE
  • GXPN
  • CRTO
  • CRTE
  • CRTP
  • OSCP
Meet the team

Common questions

What is the CORIE framework?

CORIE (Cyber Operational Resilience Intelligence-led Exercises) is the Council of Financial Regulators' framework for testing Australia's financial sector the way a sophisticated threat actor would: an intelligence-led red team exercise against an institution's Critical Business Services, covering technology, personnel and incident response, and simulating the techniques of nation-states, organised cybercrime and advanced persistent threats.

Who is a CORIE exercise for?

Banks, insurers and payment providers mandated by the Council of Financial Regulators, along with financial institutions that want to enhance resilience against advanced persistent threats ahead of any mandate.

How does a CORIE exercise run?

It follows the CORIE-mandated engagement lifecycle: threat intelligence and reconnaissance, initial compromise, persistence and lateral movement, impact and objective execution, then post-engagement review and uplift.

What are Critical Business Services?

The functions that, if disrupted, would significantly impact the confidentiality, integrity or availability of core financial systems. Identifying and prioritising them is part of the engagement, and their resilience is tested during objective execution.

How is CORIE different from a standard penetration test?

A CORIE exercise assesses the end-to-end security posture of the organisation, targeting technology, personnel and incident response capabilities, rather than testing a defined system. It is intelligence-led and tailored to the attack paths facing financial institutions.

Is SilentGrid qualified to deliver CORIE engagements?

Yes. We field the team structure the framework specifies. Our founders have delivered CBEST engagements in the United Kingdom, the intelligence-led framework CORIE was modelled on, and have led red team exercises against major Australian banks and ASX-listed organisations. Exploit development is held by consultants certified OSEE and OSED who have discovered and disclosed previously unknown vulnerabilities in commercial software from Hexagon, VMware and Commvault. SilentGrid is a CREST ANZ approved company.

Who will lead the exercise, and what are their credentials?

Named before you sign, not after. The CORIE framework specifies a Red Team Lead, a Red Team Specialist and an Exploit Development Specialist. Our exploit development capability is held by consultants certified OSEE and OSED who have discovered and disclosed previously unknown vulnerabilities in commercial software from Hexagon, VMware and Commvault. Credentials across the delivery team include OSEE, OSCE3, OSEP, OSWE, GXPN, CRTO, CRTE, CRTP and OSCP, and every consultant is listed publicly on our team page.

Is threat intelligence provided in-house or subcontracted?

Through a specialist intelligence partner, managed by us. We think that is the right structure rather than a compromise: the targeting package is produced by dedicated analysts instead of by the operators who will execute against it, which keeps the intelligence honest about what a real adversary would find. Ask any provider claiming in-house intelligence who the analysts are and what they do between engagements.

How is separation from the Blue Team maintained?

Through a Control Group: a small, named set of people at your organisation who know the exercise is running, agreed before it starts. Defenders are not told. Communications with the control group run out of band, away from the systems in scope, so an exercise is not revealed by the response to it. Deconfliction procedures let the control group confirm within minutes whether an alert is us or a real intrusion.

Can you run the physical and social engineering components?

Yes, and they are in scope where the threat scenario justifies them. Social engineering is delivered in person, over video calls, and via email, SMS, voice and social media. Physical intrusion is scoped separately with written authorisation, since it carries obligations that email-based phishing does not.

Is SilentGrid CREST approved?

Yes. SilentGrid is a CREST ANZ approved company, listed on the CREST ANZ approved companies register. Worth noting for procurement: CREST approval is not the same as CORIE capability, and the Council of Financial Regulators does not treat one as evidence of the other. CORIE is intelligence-led and built around adversary objectives rather than vulnerability discovery, so evaluate the two separately.

What do we receive at the end?

An attack execution report documenting red team activity step by step with actionable recommendations, a board-level executive summary, tactical uplift workshops with a custom remediation roadmap, and a Critical Business Services analysis.

Meet the highest standards

Get started with CORIE

Enhance your cyber defences against sophisticated financial sector threats

SilentGrid helps financial institutions meet the highest standards of operational resilience through CORIE-aligned red team exercises.