Back to blog
    PTaaS

    Pentesting on Demand with RedSOC: How It Works and When to Use It

    Sectricity Security TeamAugust 27, 2026

    RedSOC is on-demand pentesting by ethical hackers: you request a test when you need it. How a request runs, what you can ask for and when it fits.

    RedSOCPTaaSon-demand pentestingpentesting

    TL;DR

    • RedSOC is on-demand pentesting: you request a test when you need it, and ethical hackers run it.
    • It works with an annual budget in credits, spent on the tests you request.
    • Every engagement ends with a report that names the lead tester, and a retest confirms your fixes.
    • It suits releases, scanner alerts and audit questions that cannot wait for a yearly slot.
    • It sits next to a SOC, MDR or scanner. It does not replace them.

    Most organisations test once a year. Software changes every week. RedSOC is how Sectricity closes that gap: pentesting on demand by ethical hackers, on your timing. This post explains how a request runs, what you can ask for and when it is the right choice compared to a classic pentest.

    Timeline with two yearly test markers and several red on-demand test pings in between, symbolising pentesting on demand

    What RedSOC is

    RedSOC is Sectricity's on-demand pentesting model, also known as PTaaS. You decide the moment: after a release, when a scanner flags something or when an auditor asks for evidence. Ethical hackers pick up the request, test, validate and report.

    The name makes people think of a SOC. A SOC watches your environment and raises alerts. RedSOC does the other job: it tests what an attacker could really exploit and proves it. That is why it works well next to an existing SOC, MDR or scanner.

    How a request runs

    1. Choose an annual budget in credits that fits your release and audit calendar.
    2. Request a test: web, API, cloud, external, identity, social engineering or a retest.
    3. We confirm the scope with you and a senior ethical hacker picks it up.
    4. Credits are spent only on what you request, within your budget.
    5. You receive an audit-ready report with a named lead tester, and a retest confirms your fixes.

    What you can request

    Web applications, APIs and business logic, cloud, external infrastructure, identity, social engineering and red team scenarios. You can also send us the findings of your scanner, ASV platform or AI pentesting tool for manual validation. In total there are 35 services, all through one engagement model.

    When RedSOC is the right choice

    After a major change

    A new release, an infrastructure migration, a vendor onboarding or an acquisition. The yearly test cannot keep pace with that. A focused test right after the change can.

    When a tool flags findings

    Your scanner or AI tool reports vulnerabilities. Are they real, are they exploitable in your context, and which one matters first? A person checks, so your team does not chase false alarms.

    When an auditor or customer asks for evidence

    Regulators and auditors expect documented, repeatable testing of critical systems. Each engagement produces its own report, which you can map to the control that asks for it.

    When something does not feel right

    A suspicious login, an unexpected exposure or a third-party report. Request a focused test instead of waiting for the next audit cycle.

    When an annual pentest is still enough

    If your application changes rarely and one yearly test satisfies your auditor, an annual pentest remains a good fit. Many teams combine both: an annual baseline plus on-demand tests after changes. For the cost side, read Annual Pentest or PTaaS?.

    Frequently Asked Questions

    What is RedSOC?

    RedSOC is Sectricity's on-demand pentesting model (PTaaS). You request a test when you need it, and ethical hackers run it, validate the findings and report. Read more on the RedSOC page.

    Is RedSOC a SOC?

    RedSOC is pentesting on demand: a team of ethical hackers you call in whenever you want to test. A SOC monitors and raises alerts, RedSOC tests and proves what can really be exploited in your environment. That is why it works well next to an existing SOC, MDR or scanner.

    How does the annual budget in credits work?

    You choose an annual budget in credits that fits your release and audit calendar. Every test you request uses credits from that budget, so you pay for what you use, within your budget. We agree the details in a short conversation about your needs.

    Does RedSOC replace the annual pentest?

    It can, if on-demand tests cover your critical systems and your auditor accepts the reports. Many organisations keep an annual baseline and add on-demand tests after changes.

    Can RedSOC check findings from my scanner or AI tool?

    Yes. Send us the findings and our ethical hackers verify what is really exploitable in your environment, filter false positives and tell you what to fix first.

    What do I receive after a RedSOC engagement?

    An audit-ready report with a named lead tester, the scope, the method, the findings and remediation guidance. It serves as evidence for NIS2, ISO 27001, DORA and customer security questionnaires. A retest confirms your fixes.

    Related services and resources

    Start with the RedSOC page for the full list of services. If you prefer a fixed scope, see our penetration testing service or the PTaaS overview. To see how tools and testers fit together, read AI Pentest or Human Pentest?.