What a regulator means by red teaming
The RBI Directions, 2026 say red teams may be used. What a red team engagement covers, and what its report says about your detection.
17 guides, published by Security Brigade and last updated .
How the testing works
What a tester actually does, by asset class, and what tooling does and does not reach.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the…
What the Exercise Tells You About Detection
The findings are about your systems. The timeline is about your team. Read from the defender’s side, a red team report is a much more uncomfortab…
After the Foothold: Movement and Escalation
One workstation is not the objective. It is the start of credential harvesting, lateral movement and privilege escalation, and four internal weak…
How Red Teams Get In
Rarely by defeating a control. Usually by asking someone. The four initial-access routes, roughly in the order they work.
The Phases of a Red Team Engagement
Reconnaissance, initial access, foothold, movement, objective, debrief. What happens in each, roughly what share of the weeks it takes, and which…
Physical Penetration Testing
Tailgating, cloned badges, an unattended meeting room and a network socket. What a physical assessment tests, why the Indian shared-tenancy offic…
Scope and preparation
What to have ready, what can and cannot be tested, and how the boundary gets drawn.
Reading the report
Severity, CVSS and the vector string, and how to tell written work from tool output.
Where the requirement comes from
Which regulators name you, and where the obligation arrives from when none do.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering…
Threat-Led Penetration Testing: What TLPT Actually Means
In some jurisdictions a supervised regulatory programme with prescribed intelligence and a regulator in the room. In marketing, a synonym for red…
Red Teaming Under the RBI's 2026 Directions
Four of the six 2026 Directions say red teams may be used. Two do not mention red teaming at all. The paragraph numbers entity by entity, and wha…
Buying one
What it costs, who is qualified to do it, and what you receive at the end.
Choosing a Red Team Provider
Every firm answers yes to every capability question. Six questions where the generic yes runs out, and what a real answer sounds like.
Adversary Simulation and Breach-and-Attack Simulation
One is a tool that replays known techniques on a schedule. The other is people improvising. Both get sold as red teaming, and both are useful, fo…
Purple Team: When It Beats a Red Team
A red team measures whether you would notice. A purple team fixes the fact that you would not. The one prerequisite, the three outcomes each tech…
What a Red Team Engagement Costs
Quotes for the same objective can differ threefold. The objective itself is the largest lever, duration and access routes explain most of the res…
What a Red Team Assessment Involves
An objective, a set of rules, and a team that will take any route the rules permit. What you have to have ready, what happens across the weeks, h…
Red Team vs Penetration Testing
A penetration test asks what is broken. A red team asks whether anyone would notice. Where VAPT sits between them, what each proves to a regulato…
Turning this into an exercise
Scope a red team against a stated objective.
A red team is defined by its objective and its rules of engagement, not by a service catalogue. Tell us what you want to find out: whether detection works, how far an intruder gets, or what a regulator expects you to evidence. You will get the objective, the constraints and the reporting format in writing. Security Brigade is CERT-In empanelled and publishes this site.