A red team engagement is a goal-based adversary simulation that tests whether your organisation can detect and respond to a real attack — not merely whether vulnerabilities exist. We agree an objective, such as reaching a specific data set, then pursue it using the techniques a genuine attacker would, while your team responds without prior warning. The deliverable is an honest measure of your detection and response capability.
Red team vs penetration test
| Penetration test | Red team |
| Goal | Find as many exploitable weaknesses as possible | Achieve a specific objective, like a real attacker |
| Scope | Defined systems | Broad — technology, people and process |
| Your team knows? | Usually yes | Usually no, beyond a small trusted group |
| Stealth | Not a priority | Central — evasion is part of the exercise |
| Measures | Vulnerability exposure | Detection and response capability |
| Duration | Days to weeks | Weeks |
| Right for | Most organisations | Organisations with existing detection capability |
Be honest about readiness. If you have no monitoring, no EDR and no incident response process, a red team will simply succeed quietly and tell you what you already know. Invest in
penetration testing and detection capability first — red teaming measures a capability you must already have.
How an engagement runs
- Objective setting — agreeing concrete goals with a small trusted group: reach a named database, obtain domain admin, access a specific document store.
- Rules of engagement — written authorisation, out-of-scope systems, prohibited techniques, emergency contacts and stand-down procedure.
- Reconnaissance — open-source intelligence on your organisation, people and exposed infrastructure.
- Initial access — via agreed vectors, or starting from an assumed-breach position.
- Establish and expand — persistence, privilege escalation and lateral movement toward the objective while avoiding detection.
- Objective execution — demonstrating access to the target without causing harm.
- Debrief — a full timeline of our actions compared against what your team detected and when.
Assumed breach: usually better value
Many engagements start from an "assumed breach" position — we begin with a standard user account or a foothold on a workstation, as though a phishing email had already succeeded.
This is deliberate. Spending two weeks proving that phishing works tells you little; it always works eventually. Starting from the assumption that it has succeeded focuses the entire engagement on the questions that actually matter: how far can they get, how quickly, and would anyone notice?
What you learn
- Detection coverage — which of our actions generated alerts, and which passed unseen.
- Response effectiveness — whether alerts were triaged, escalated and acted upon.
- Time to detect and contain — the metrics that most directly determine breach severity.
- Real attack paths — the specific chain from foothold to objective in your environment.
- Process gaps — where escalation stalled or ownership was unclear.
Purple teaming
For many organisations a purple team exercise delivers more value. Red and blue teams work collaboratively: we execute a technique, your team checks whether it was detected, we tune together, then repeat. It is less dramatic than a covert red team but improves detection far faster — and it is what we often recommend for a first engagement.
Frequently asked questions
What is the difference between red teaming and penetration testing?
A penetration test aims to find as many exploitable weaknesses as possible within a defined scope, usually with your team's knowledge. A red team engagement pursues a specific objective covertly, using realistic attacker techniques across technology, people and process, to test whether your organisation can detect and respond. Penetration testing measures exposure; red teaming measures capability.
Is our organisation ready for a red team engagement?
Only if you already have detection and response capability to test — typically endpoint detection and response, centralised logging, and someone responsible for reviewing alerts. Without those, a red team will succeed quietly and tell you little you did not already know. Start with penetration testing and building detection first.
What is an assumed breach engagement?
An assumed breach engagement starts from the position that an attacker has already gained an initial foothold, such as a standard user account or access to one workstation. This skips proving that phishing works, which it eventually always does, and focuses the engagement on how far an attacker can move and whether they would be detected.
Will a red team engagement disrupt our business?
Engagements are conducted under written rules of engagement specifying out-of-scope systems, prohibited techniques, emergency contacts and a stand-down procedure. The objective is to demonstrate access, not cause damage. A small trusted group within your organisation always knows the exercise is authorised.
What is purple teaming?
Purple teaming is a collaborative exercise where the offensive and defensive teams work together in real time. We execute a technique, your team checks whether their tooling detected it, adjustments are made, and the process repeats. It improves detection coverage faster than a covert engagement and is often a better first step.