# Alacrinet Offensive Intelligence Unit (OIU) > Operator-led offensive security. Penetration testing and red teaming for mid-market and enterprise organizations. Real attack paths, not scan output. Alacrinet's Offensive Intelligence Unit is the offensive security practice of Alacrinet (alacrinet.com), led by Bailey Besheer, Managing Director of Cybersecurity Services. Bailey is a former Marine cyber warfare operator, ranked top 25 globally on Hack The Box, and is personally involved in every engagement. LinkedIn (operator): https://www.linkedin.com/in/baileybesheer/ LinkedIn (company): https://www.linkedin.com/company/alacrinet Parent organization: https://www.alacrinet.com ## Services - [Penetration Testing](https://pentesting.alacrinet.com/pentesting): Manual testing across web, mobile, API, network, cloud, and IoT. Compliance-mapped to PCI DSS, SOC 2, ISO 27001, HIPAA, CMMC. - [Red Teaming](https://pentesting.alacrinet.com/red-teaming): Full-scope adversary simulation across digital, physical, and human vectors. Tests SOC detection and IR readiness. - [Social Engineering](https://pentesting.alacrinet.com/social-engineering): APT-grade phishing, vishing, and manipulation campaigns mimicking real threat actor TTPs. - [Product Security](https://pentesting.alacrinet.com/product-security): Continuous code review, DevSecOps integration, vulnerability management, and cloud security. - [LLM Penetration Testing](https://pentesting.alacrinet.com/llm-pentesting): Manual adversarial testing for LLM applications: prompt injection, jailbreak, data exfiltration, RAG pipeline security. - [Continuous Penetration Testing](https://pentesting.alacrinet.com/continuous-pentesting): Ongoing operator-led testing on your release cadence, with rolling scope and unlimited retesting. ## Industries - [Financial Services](https://pentesting.alacrinet.com/industries/financial-services): Core banking, payments, and customer data testing with regulator-ready reports mapped to PCI-DSS, ISO 27001, and SOC 2. - [Healthcare](https://pentesting.alacrinet.com/industries/healthcare): Patient portals, EHR, and connected medical devices, aligned to the HIPAA Security Rule. - [Manufacturing & OT](https://pentesting.alacrinet.com/industries/manufacturing): Non-disruptive OT/ICS testing of SCADA, PLCs, and the IT/OT boundary, mapped to NIST CSF and IEC 62443. - [Technology & SaaS](https://pentesting.alacrinet.com/industries/technology): API, multi-tenant isolation, cloud IAM, and CI/CD testing with SOC 2 and ISO 27001 evidence. - [Retail & E-Commerce](https://pentesting.alacrinet.com/industries/retail): Checkout and payment-flow testing meeting PCI-DSS v4.0 Requirement 11.4. - [Enterprise](https://pentesting.alacrinet.com/industries/enterprise): Multi-site programs, identity-chain attack paths, M&A due diligence, and board-ready CISO reporting. ## Solutions by use case - [Compliance Readiness](https://pentesting.alacrinet.com/use-cases/compliance-readiness): A penetration test that survives a SOC 2, PCI DSS 4.0.1, HIPAA, CMMC, or ISO 27001 audit. What each framework requires, the gap a scanner leaves, and the evidence auditors accept. - [M&A Cyber Due Diligence](https://pentesting.alacrinet.com/use-cases/m-and-a-due-diligence): Point-in-time adversarial assessment of a target's posture on the deal clock. Surfaces inherited security debt a checklist misses, with board-ready output. - [Vendor Risk Validation](https://pentesting.alacrinet.com/use-cases/vendor-risk-validation): Validate a third-party vendor's security beyond their SOC 2. The questions that discriminate a real program, plus testing of the vendor's app, API, and external surface. - [Incident Readiness](https://pentesting.alacrinet.com/use-cases/incident-readiness): Test whether your SOC actually detects and responds. Assumed-breach and adversary simulation measure dwell time and MTTD/MTTR, mapped to MITRE ATT&CK. ## Ideal customer CISOs, security directors, and VPs of Engineering at mid-market to enterprise organizations ($50M to $2B revenue) under compliance pressure (SOC 2, PCI, HIPAA, CMMC) or with active M&A diligence, expiring pentest contracts, or insurance pressure. ## Differentiator Operator-led from scoping call to executive debrief. No junior consultants. No scan-and-PDF deliverables. Findings are 100% manually validated. Critical findings communicated within 24 hours. Reports map attack paths, not isolated CVSS scores, and connect technical exposure to business impact. ## Contact - Talk to an operator: https://pentesting.alacrinet.com/start - Send a brief: https://pentesting.alacrinet.com/contact - Email: info@pentesting.alacrinet.com ## Canonical pages - https://pentesting.alacrinet.com/ - https://pentesting.alacrinet.com/about - https://pentesting.alacrinet.com/about/bailey-besheer - https://pentesting.alacrinet.com/pentesting - https://pentesting.alacrinet.com/red-teaming - https://pentesting.alacrinet.com/social-engineering - https://pentesting.alacrinet.com/product-security - https://pentesting.alacrinet.com/llm-pentesting - https://pentesting.alacrinet.com/pricing - https://pentesting.alacrinet.com/contact - https://pentesting.alacrinet.com/start - https://pentesting.alacrinet.com/pentesting/web-application - https://pentesting.alacrinet.com/pentesting/external-network - https://pentesting.alacrinet.com/pentesting/cloud - https://pentesting.alacrinet.com/pentesting/api - https://pentesting.alacrinet.com/pentesting/internal-network - https://pentesting.alacrinet.com/pentesting/mobile - https://pentesting.alacrinet.com/pentesting/wireless - https://pentesting.alacrinet.com/continuous-pentesting - https://pentesting.alacrinet.com/red-teaming/physical - https://pentesting.alacrinet.com/red-teaming/adversary-simulation - https://pentesting.alacrinet.com/methodology - https://pentesting.alacrinet.com/glossary - https://pentesting.alacrinet.com/pen-test-vendor-evaluation-checklist - https://pentesting.alacrinet.com/why-no-case-studies - https://pentesting.alacrinet.com/unlimited-remediation-validation - https://pentesting.alacrinet.com/industries/financial-services - https://pentesting.alacrinet.com/industries/healthcare - https://pentesting.alacrinet.com/industries/manufacturing - https://pentesting.alacrinet.com/industries/technology - https://pentesting.alacrinet.com/industries/retail - https://pentesting.alacrinet.com/industries/enterprise - https://pentesting.alacrinet.com/compliance/soc-2 - https://pentesting.alacrinet.com/compliance/pci - https://pentesting.alacrinet.com/compliance/hipaa - https://pentesting.alacrinet.com/compliance/cmmc-level-2 - https://pentesting.alacrinet.com/compliance/iso-27001 - https://pentesting.alacrinet.com/compare/alacrinet-vs-bishop-fox - https://pentesting.alacrinet.com/compare/alacrinet-vs-netspi - https://pentesting.alacrinet.com/compare/alacrinet-vs-trustwave-spiderlabs - https://pentesting.alacrinet.com/compare/alacrinet-vs-kroll - https://pentesting.alacrinet.com/compare/alacrinet-vs-mandiant - https://pentesting.alacrinet.com/compare/alacrinet-vs-optiv - https://pentesting.alacrinet.com/compare/alacrinet-vs-accenture - https://pentesting.alacrinet.com/guides/how-to-get-a-pentest - https://pentesting.alacrinet.com/guides/best-penetration-testing-companies - https://pentesting.alacrinet.com/guides/pentest-vs-vuln-scan - https://pentesting.alacrinet.com/guides/red-team-vs-pentest - https://pentesting.alacrinet.com/guides/what-a-pentest-costs-in-2026 - https://pentesting.alacrinet.com/guides/choosing-a-pentest-vendor - https://pentesting.alacrinet.com/guides/5-pen-test-types-mid-market-security-leaders-should-know - https://pentesting.alacrinet.com/guides/operators-guide-to-nuclei - https://pentesting.alacrinet.com/use-cases/compliance-readiness - https://pentesting.alacrinet.com/use-cases/m-and-a-due-diligence - https://pentesting.alacrinet.com/use-cases/vendor-risk-validation - https://pentesting.alacrinet.com/use-cases/incident-readiness