Skip to main content

Choosing a Red Team Provider

Every firm answers yes to every capability question. Six questions where the generic yes runs out, and what a real answer sounds like.

By Siddarth G
August 19, 2026 Last updated 7 min read

Capability questions do not discriminate. Every firm does red teaming, has certified people and follows a methodology. The questions below are harder to answer without having done the work.

Ask them on a call, not in a questionnaire. A questionnaire is answered by whoever writes the bids. A call is answered by the people who would run your engagement, or it shows you that you cannot get those people on a call.

1. Given this objective, what would you try first, and what if it failed?

The single most useful question, and it costs nothing.

A team that has run these describes a sequence: what reconnaissance would target, which routes they would rank and why, what the fallback is. A team selling a penetration test under a different name describes a methodology and a toolset.

Send the objective in advance and let them prepare. You are testing whether they can reason about your environment, not whether they think quickly on a call.

2. Who is actually on the team?

Names, and what each person does. Red teaming is small-team work and the outcome depends heavily on the individuals. A proposal that names a capability but no people is describing a bench you may not get.

Ask specifically whether the people who scoped it will run it.

Then ask what else those people are committed to during your window. An operator pulled onto an incident somewhere else in week two is how an engagement quietly becomes something smaller than the one you bought.

3. How many team-weeks, and how many people?

The unit that makes proposals comparable. A "10-day red team" and a "4-week" may be similar money and very different exercises. Details in what a red team engagement costs.

Ask how those weeks divide between getting in and what happens afterwards. Initial access is the visible part and the smaller part; the findings that change your architecture come from movement and escalation once a foothold exists. A plan that spends most of its effort on the way in produces a dramatic story and a thin set of conclusions.

4. Is the detection timeline a deliverable?

If it is not in the proposal it will not be in the report, and half the value of the exercise goes with it. Same for the joint debrief with your defenders, which is usually the cheapest line item and the most useful hours.

Ask what the timeline will be built from. Your own alert and ticket timestamps, reconciled against the testers' activity log, are evidence. A recollection written up at the end is a story. What the exercise tells you about detection sets out what that reconciliation involves.

5. What have you not been able to do?

An honest team will describe an engagement where they did not reach the objective, or were caught in the first week, and what they learned. A team claiming an unbroken record is either selling to organisations with no defences or is not telling you about the other ones.

6. What happens if you break something?

It is rare, but it happens. What matters is whether there is a rehearsed answer: who is called, how quickly, what the stop conditions are, what insurance exists. A team that has not thought about it has not run many.

Ask for the escalation number and call it during the evaluation. You are looking for a person with authority to halt the exercise, reachable at night and at the weekend, and you find out by dialling.

What the quote leaves out

Most of the friction in month two is about work nobody priced. Ask for each of these to be written in or written out:

  • Retest. Whether the team comes back after you fix, how long the window stays open, and whether it is billed again.
  • Remediation support. Hours with your engineers while they build the fix, and with your detection team while they write the rule that would have caught it.
  • The debrief. Named as a deliverable with an attendee list, or absent.
  • Permission you do not control. Assets on another company's platform, and offices where the floor is shared with other tenants, need consent from a party neither of you employs. Providers price the testing; chasing that consent is work somebody has to own.
  • Travel and out-of-hours windows. Physical attempts and change-freeze weekends price differently from remote work in business hours.

Excluding any of these is reasonable. Discovering the exclusion after the engagement starts is not. Agree the shape of the deliverable at the same time, because what a red team report contains is a commercial decision taken before the work, not a technical one taken after it.

References, when every engagement is under NDA

No credible provider will name clients, and asking is a test you should not set. Ask instead for a reference call with an organisation in your sector and roughly your size, arranged by them.

Then ask that reference something answerable. "Were they good" gets a yes from everybody. These do not:

  • What did you change after the report, and how long did it take?
  • Did the detection timeline in the report match what your own tickets showed?
  • Was there a retest, and had the fixes held?
  • Who from the provider actually turned up, and were they the people in the proposal?

If you are regulated, the selection is itself an artefact

On 31 July 2026 the Reserve Bank repealed 628 circulars, including the 2016 Cyber Security Framework, and issued six entity-class cyber Directions, all of them in force on issuance with no transition period. Three paragraphs change how a regulated buyer runs a selection.

  • ¶156. Qualification, professional expertise, credentials and competency of the firm and of its assigned personnel, considered at selection, appointment, engagement and renewal. Keep that evidence per person and refresh it each renewal. A tender file holding a corporate profile and no personnel record does not answer it.
  • ¶157. Explicit assurance for each area assessed, an expectation to be set at the point of empanelment or contract award. Put the report format in the RFP; raising it at delivery is too late.
  • ¶158. Addresses what follows when something is missed, and carries it into later selection and renewal decisions. Ask a provider directly how they handle it. A firm that has not read ¶158 has no answer to give.

On the exercise itself, ¶162 says red teams may be used, and the 2016 framework said the same at Annex 1 section 18.5. If a proposal justifies a cadence by citing a Direction, ask for the paragraph number. The same discipline applies under SEBI's CSCRF, where the technical clarifications of 28 August 2025 revised the relevant guideline: it now recommends that regulated entities consider deploying a range of security solutions in consultation with their IT Committee, such as threat simulation, vulnerability management and decoy systems. A pitch that quotes CSCRF as naming a product category is quoting text those clarifications replaced. Red teaming under the RBI Directions and red teaming and SEBI CSCRF work through both instruments in full.

On credentials

Certifications and accreditations set a floor. They are useful for excluding a firm and weak for choosing one. An accreditation is genuinely load-bearing when an external requirement names it, and at that point it is a prerequisite.

CERT-In empanelment is that floor for Indian work. A regulator that accepts an audit report accepts it from a CERT-In empanelled auditor, so establish empanelment before you commission: a competent exercise from a firm outside the panel still produces a document your auditor will decline. ¶159 adds the part that matters beyond the stamp. Where an empanelled auditor is engaged, CERT-In's audit policy guidelines come into the supervisory relationship, so you are buying a defined audit-policy regime alongside the test. Our own empanelment has run continuously since 2008, across more than 6,700 assessments.

Before anyone starts: what has to be signed

Three documents decide whether the exercise is lawful and whether it can be stopped cleanly. A provider who raises them before you do has run these.

  • Written authorisation from a person with authority over every asset in scope, naming the window, the permitted techniques and the stop conditions. The rules of engagement carry the detail.
  • The consent position for anything aimed at people, agreed with HR and legal in advance, including what is disclosed to staff afterwards. See social engineering assessments and consent.
  • Third-party sign-off where a landlord, a shared floor or another company's platform sits inside the boundary.

Ask who on your side owns each one. If the answer is the provider, the answer is wrong.

The question to ask yourself first

Before comparing anyone: what would we do differently depending on the result? If the honest answer is nothing, no provider is the right one yet.

Apply the same test to the prerequisites. If your logs are not centralised and nobody is watching them during the window, the detection half of the exercise has nothing to measure, and you will buy that half again once the logging is fixed.

Buy the exercise that would change something, which for most organisations, most of the time, is a purple team.

About the author

Siddarth G

Practice Director — Cybersecurity

Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.