
A Region Under Siege, and Why That Matters
The Western Balkans is no longer a peripheral concern in the global cybersecurity conversation. It is a live battlefield.
In the first half of 2026 alone, Albania’s National Cyber Security Authority (AKSK) recorded 14,628,595 cyberattack attempts against the country’s information infrastructure, a figure equivalent to roughly 56 attack attempts every single minute, day and night, for six consecutive months. Of those attempts, 54% targeted important information infrastructure, while 46% were aimed directly at critical infrastructure: finance, energy, public administration, and digital government services.
This is not an abstract statistic. Since 2022, Albania has weathered some of the most consequential state-sponsored cyber operations in Europe, including sophisticated wiper attacks attributed to Iranian state actors that attempted to erase government systems outright. Neighboring Montenegro has seen government institutions crippled for weeks, delaying social welfare payments. Kosovo’s telecommunications infrastructure has been targeted directly. North Macedonia went years without a national cybersecurity strategy at all. Across the region, a pattern repeats itself: institutions react to breaches instead of preparing for them.
At the same time, something notable is happening. Albania climbed from 54th to 9th place globally in the 2026 National Cyber Security Index, one of the largest single-country jumps ever recorded on that index, a signal that national policy, institutional capacity, and public-sector cyber maturity are accelerating fast. The question the region now faces is whether the private-sector offensive security ecosystem, the people who actually break into systems before criminals do, can keep pace with that ambition.
That is the gap Red Team Albania was built to close.
What Red Team Albania Is
Red Team Albania (RTA) is an offensive security company founded in Tirana in early 2026, built to give organizations across Albania and the wider Western Balkans access to the kind of adversarial security testing that has historically been available almost exclusively through Western European or American firms, at Western European prices and Western European turnaround times.
RTA’s premise is simple and, in security, timeless: the only reliable way to know whether your defenses will hold against a real adversary is to have a real adversary, an ethical, contracted, disciplined one, try to break them first. Firewalls, compliance checklists, and vulnerability scanners tell you what should be secure. Offensive testing tells you what actually is.
The company was co-founded by Orgito Leka, a security researcher also behind RTA Academy, alongside a small founding team drawn from 42 Tirana, one of the region’s most demanding software engineering programs. RTA is scheduled to formally launch on September 1, 2026, with a public event combining a technical presentation and a live Capture-the-Flag competition for the 42 Tirana community.
The Discipline Behind the Offense
What separates a credible offensive security firm from a liability is process. Anyone can run automated scanners and hand over a PDF of false positives. RTA’s engagements instead follow a structured, six-phase methodology designed to mirror how real adversaries actually operate, while staying fully within legal and contractual boundaries:
- Scoping, defining targets, rules of engagement, and boundaries with the client before any technical work begins.
- Reconnaissance, mapping the attack surface the way a genuine threat actor would, using open-source intelligence and technical enumeration.
- Exploitation, attempting to actively compromise identified weaknesses, not just flag them.
- Post-Exploitation, assessing what a real attacker could reach after the initial breach: lateral movement, privilege escalation, data exposure.
- Reporting, translating technical findings into a document that both engineers and executives can act on, with clear severity ratings and remediation guidance.
- Retest, verifying that fixes actually close the gaps, rather than treating the initial report as the end of the relationship.
This methodology is anchored to internationally recognized frameworks rather than improvised judgment calls: MITRE ATT&CK for adversary tactics and techniques, the OWASP Web Security Testing Guide and Application Security Verification Standard for application-layer assessments, the Penetration Testing Execution Standard (PTES), NIST SP 800–115 for technical security testing, and CVSS v3.1 for consistent, defensible severity scoring. Findings are handled under coordinated disclosure principles, a non-negotiable baseline for any firm operating in this space.
Five Service Lines, One Objective
RTA structures its work around five interconnected service lines:
- Red Teaming, full-scope, objective-driven adversary simulation designed to test people, processes, and technology together, not just a single application or network segment.
- Penetration Testing, focused, scoped assessments of specific systems, applications, or infrastructure, including dedicated AI and LLM security assessments, an increasingly urgent category as organizations rush to deploy AI systems without understanding their new attack surface.
- Threat Intelligence, proactive monitoring and analysis of the threats most relevant to an organization’s sector and region, informed by the reality that Western Balkan targets face a distinct threat profile shaped by regional geopolitics.
- Research, original security research that feeds back into the methodology and tooling used across engagements, rather than relying solely on commercial or off-the-shelf capability.
- RTA Academy, training, CTF competitions, and internship pathways designed to grow the next generation of Albanian and Balkan offensive security talent, addressing the single biggest long-term constraint on the region’s cybersecurity capacity: people.
That last point deserves emphasis. Every credible national cybersecurity strategy in the region, Albania’s included, identifies workforce development as a critical gap. Tools and frameworks can be imported; skilled, regionally-rooted practitioners cannot. RTA Academy exists because a sustainable security ecosystem in the Western Balkans has to be built from the ground up, not rented from abroad indefinitely.
Why Regional, Not Just Local
There is a strategic argument for a Balkans-headquartered offensive security firm that goes beyond convenience or cost. Threat intelligence and reporting from the EU’s diplomatic service, the Balkan Investigative Reporting Network, and independent researchers converge on the same conclusion: cyber threats in this region carry a distinct geopolitical signature, shaped by state-sponsored activity linked to actors including Iran and Russia, and by the region’s uneven pace of digital transformation. A security team that understands that context natively, rather than treating it as a footnote in a generic global threat report, is better positioned to test for the threats that are actually most likely to materialize.
The European Union has recognized this dynamic directly, committing dedicated “Rapid Response” cybersecurity support to Albania, Montenegro, and North Macedonia specifically to strengthen detection, prevention, and resilience against the region’s rising threat volume. RTA’s ambition is to be the private-sector counterpart to that public-sector effort: the team organizations call not after a breach, but before one, to find out, under controlled, professional, contractually bounded conditions, exactly where they would have failed.
The Bottom Line
The Western Balkans is digitizing faster than its adversaries are slowing down. Albania alone now absorbs tens of millions of attack attempts every year, against a backdrop of state-sponsored intrusion campaigns, ransomware, and an expanding public-sector digital footprint that includes more than a thousand electronic government services. National policy is responding, Albania’s climb in global cybersecurity rankings proves that. What the region has lacked is a homegrown offensive security capability built to match that ambition on the private-sector side.
Red Team Albania was founded to be that capability: methodologically rigorous, standards-driven, regionally rooted, and structurally committed, through RTA Academy, to building the talent pipeline the entire ecosystem depends on. The company launches publicly on September 1, 2026. For a region under continuous, measurable, escalating attack, that launch is not a moment too soon.
Sources: AKSK / Euronews Albania (2026); Albanian Telegraphic Agency, National Cyber Security Index 2026; Balkan Insight / BIRN Digital Rights Programme report on Western Balkans cybersecurity (2022–2024); EU External Action Service; U.S. State Department OSAC report on Albania.