ISO 9001 + ISO 27001 · QSI CERTIFIEDFIRST.ORG MEMBERCROC 24/7 · SANTO DOMINGO, DR
Beyond monitoring: Proactive cybersecurity risk management for customer peace of mind

Red Team and Blue Team. Under one roof.

Most firms either test defenses or run them. CBRT does both: offensive security that feeds the CROC — our 24/7 managed defense — and the other way around. Every finding arrives with its remediation.

Book a scoping callView the services →
Accreditations
ISO 9001
ISO 27001
FIRST member
Certified quality and information security management. Certified members of the global Forum of Incident Response and Security Teams.
Audited certification
ISO 9001 and 27001 verified by QSI
FIRST member
Global incident response
24/7/365
We stand watch while you sleep

A firm of cyber risk management experts, certified, with global vision and experience.

Cybersecurity Blue & Red Team (CBRT) runs the CROC — our Cyber Risk Operation Center — and an in-house offensive team. We defend and attack with the same staff: whatever the Red Team learns by breaking in, the Blue Team turns into detections that same week.

We serve banking, healthcare, energy, pension funds and education across the Dominican Republic and the region, under ISO 9001 and ISO 27001 certified processes.

Service catalog

Four areas. One firm.

Each area works on its own; contracted together, they reinforce one another. Every SOC service is also available independently.

01 · MANAGED DEFENSE

Security Operations Center

The core that brings together monitoring, response and intelligence — with annual adversary emulation included to prove the defenses still hold.

24/7 monitoringIncident responseThreat huntingDigital forensicsThreat intelligenceDNS + WAFMXDR · managed EDR24/7 DFIR retainerRegulatory reporting
Explore the CROC →
02 · OFFENSIVE SECURITY

Red Team

Real, controlled attacks: the same intrusion techniques threat actors use, to find the gaps before they do.

Objective-based Red TeamWeb · infrastructure · cloud pentestAdversary emulationSocial engineeringActive Directory assessmentHardening and configurationSAST/DASTRed/Blue simulation · purple
See the offensive approach →
03 · CONTINUOUS EXPOSURE

Cyber Exposure Monitoring

Two pentests a year are not enough. A continuous Red Team that finds and neutralizes risk constantly, before threat actors get there first.

CTEM · exposure managementBrand protectionData leaks · dark webVulnerability managementAttack surface (EASM)
Get a quote for continuous exposure →
04 · GOVERNANCE AND COMPLIANCE

Regulatory and standards compliance

More than standard controls: strategic integration to comply today — ISO 27001, PCI DSS, SOC 2, GDPR, NIST CSF — and adapt to whatever comes next.

Virtual CISOISO 27001 (implementation)Law 172-13 · personal dataPCI DSS v4.0Essential controlsBusiness continuityTabletop (TTX)Maturity assessmentAudits
View governance and compliance →
24/7/365
Eyes on screen, all year round
2 × ISO
9001 and 27001 QSI certified
100 %
Of cases with human analysis
< 15 min
From critical alert to first action
SectorsBanking and financeHealthcareEnergy and industryPension fundsEducationGovernment
Live defense · CROC

From finding to action, without a layover.

The Cyber Risk Operation Center watches your environment in real time. Every alert is analyzed by a person — not an automated email — and the response arrives while the incident is still warm: containment, forensics and intelligence within the same shift.

  • 24/7 monitoring with human triage and prioritization by business impact
  • Proactive threat hunting: we look for what alerts never see
  • Annual adversary emulation included — the Red Team tests the Blue Team
Get a CROC quoteINTEGRATES WITH YOUR SENSORS AND CLOUD
CROC · ACTIVE SHIFTONLINE
Brute force against corporate VPN
CRITICAL · CONTAINED IN 9 MIN
#CROC-4821
Impossible travel sign-in · O365
HIGH · UNDER INVESTIGATION
#CROC-4822
DNS beacon to newly registered domain
MEDIUM · HUNT IN PROGRESS
#CROC-4819
CRITICAL SLA < 15 MINILLUSTRATIVE SCENARIO
PREVENTED · SQL INJECTION IN ONLINE BANKINGREPORTED · DEFAULT CREDENTIALS IN OTBLOCKED · STORED XSS IN PORTALSECURED · EXPOSED S3 BUCKETPATCHED · RCE IN HEALTHCARE APPLICATION PREVENTED · SQL INJECTION IN ONLINE BANKINGREPORTED · DEFAULT CREDENTIALS IN OTBLOCKED · STORED XSS IN PORTALSECURED · EXPOSED S3 BUCKETPATCHED · RCE IN HEALTHCARE APPLICATION
Offensive security · Red Team

We think like the attacker so you never have to live it.

Hands-on, not scanners: certified consultants apply the tactics, techniques and procedures of real actors against your systems, networks and applications. The report arrives prioritized by impact, with step-by-step remediation and retest included.

Penetration testing
Web, infrastructure, cloud, wireless and social engineering.
Adversary emulation
Real-actor TTPs (MITRE ATT&CK) against your detection and response.
SAST/DAST code analysis
Software vulnerabilities before and during execution.
Request a pentest scope
01
Virtual CISO
Strategic security leadership without the cost of a full-time executive.
02
Audits and compliance
ISO 27001, SWIFT, PCI DSS, SOC 2, GDPR, NIST CSF and sector regulation.
03
Business continuity
BCP and DRP plans aligned to ISO 22301 and NIST SP 800-34.
04
Tabletop and executive exercises
The board and the crisis committee, trained on realistic scenarios.
Governance and compliance

Audit-ready. Every day.

Compliance is not an annual project: it is a posture. We build the controls into the operation so the evidence always exists — and the next audit is paperwork, not a crisis.

Assess my posture →
CBRT ADVANTAGE · 01

Visit the CROC.

Before signing anything, come to Santo Domingo: see the floor, meet the analysts who will handle your alerts and ask whatever you like. No sales script.

Schedule a visit →
CBRT ADVANTAGE · 02

The closed loop.

What red finds, blue blocks — in your environment and in every client environment we defend. Every pentest improves the CROC; every incident sharpens the next pentest.

RED FINDSBLUE BLOCKS

Where should you start?

If no one has ever tested you

Start on the red side.

A pentest or an adversary emulation tells you, with evidence, how far an attacker would get today. It is the most honest picture of your posture.

Quote an offensive assessment
If no one is watching at night

Start on the blue side.

The CROC puts trained eyes on your environment 24/7 within weeks, using the sensors you already own. The annual emulation is included.

Get a CROC quote

Not sure which? Book 30 minutes and we will tell you straight — sometimes the answer is “you do not need us yet.”

Knowledge center

Advisories, in-house research and training

We publish the CVEs that matter in the region, what our team finds and the CyberAcademy calendar.

Enter the knowledge center →
Advisories Vulnerabilities and active exploitation RSS feed with the latest CVEs and the recommended action. Technical blog Findings, techniques and detections Written by the team on shift. R&D included. News and events Where we will be this quarter Forums, webinars and firm announcements. CyberAcademy Courses and specialized training Taught by the people who operate, with a real lab.

Frequently asked questions

What is CBRT?

Cybersecurity Blue & Red Team: a Dominican firm that runs managed defense (the CROC) and offensive security (Red Team) with the same staff, ISO 9001 and ISO 27001 certified and a FIRST.org member.

What does the SOC service include?

24/7 monitoring, incident response, threat hunting, digital forensics, threat intelligence, DNS filtering and WAF — plus an annual adversary emulation. Every service can also be contracted separately.

Pentesting or vulnerability assessment?

A scanner lists weaknesses; a pentest proves which ones are exploitable and how far a real attacker gets. If you need to prioritize investment or meet regulation, you need the pentest — and for the rest of the year, continuous cyber exposure monitoring.

How does a service start?

With a 30-minute scoping call: we understand your environment, define objectives and hand you a proposal with scope, schedule and a closed price. No commitment.

Operation in numbers · {{ mPeriodo }}

What runs through our operation, in numbers

UPDATED {{ mActualizado }}
Managed defense · CROC
What we watch and contain
{{ mEventos }}
events ingested and correlated
{{ mAdvisories }}
alerts raised and triaged
Critical{{ mSevCritica }} High{{ mSevHigh }} Medium{{ mSevMedium }} Low{{ mSevLow }}
Offensive security testing · Red Team
What we test and break
{{ mHallazgos }}
findings recorded in the period
{{ mCriticos }}
rated high or critical
Critical{{ mCriCritica }} High{{ mCriHigh }} Medium{{ mCriMedium }} Low{{ mCriLow }}

Security by design: these figures are aggregates across the whole operation. The engine does not publish — or store in this view — client names, identifiers, hostnames, IP addresses, usernames or finding titles. No organization is identifiable from these numbers.

CBRT
{{ conteoCajon }} {{ r.n }}{{ r.area }} No matches. Try “pentest”, “maturity” or “monitoring”.
Report an incident Talk to an expert
Active incident?DFIR RESPONDS 24/7