Skip to main content

Red Team vs Penetration Testing

A penetration test asks what is broken. A red team asks whether anyone would notice. The difference decides which one you should be buying, and most buyers are quoted the wrong one.

3 min read

These get sold interchangeably and they answer opposite questions.

A penetration test asks: what is broken in this system? It is scoped to a target, works through it methodically, and produces a list of findings. Coverage is the goal.

A red team assessment asks: could someone achieve a specific objective against this organisation, and would anyone notice? It is scoped to a goal rather than a system, takes whatever route works, and produces a narrative. Realism is the goal.

You are buying the second only if you already know the answer to the first.

The differences that actually matter

Objective, not scope

A penetration test starts with a list of assets. A red team starts with an objective — reach the payment system, obtain a copy of the customer database, gain domain administrator, get an operator to run something. Everything else is open, within the rules agreed.

This is the difference buyers most often miss. Asking for "a red team of our web application" is asking for a penetration test with a more expensive name.

Breadth of route

A penetration test stays inside its boundary. A red team uses whatever route is permitted: phishing your staff, walking into an office, an exposed service, a supplier, a misplaced credential in a public repository. The route is a finding in itself.

Who knows

In a penetration test the defenders are usually told, because the point is coverage and blocking the tester wastes the engagement.

In a red team they are usually not, because whether they detect and respond is half of what is being measured. A small group — often two or three people — knows, and holds the authorisation. That group matters: someone has to be able to stop the exercise and vouch for the testers at three in the morning.

Duration

A penetration test is days to weeks. A red team is weeks to months, because patience is part of the simulation. An adversary who fails on Tuesday tries something else on Friday.

What comes back

A penetration test produces findings, each with severity, reproduction steps and remediation. A red team produces a narrative: this is how we got in, this is what we reached, this is what your monitoring saw and when, this is where a response would have stopped us.

A red team report with a severity table and no story has misunderstood the exercise. What you are buying is the timeline.

Which you should buy

A penetration test, if you have not had one recently, if a regulator or customer asks for one, or if you want to know what is wrong with a particular system. It is the right answer far more often than it is sold as.

A red team, if your systems are already tested regularly and fixed, you have a security team or a managed detection service, and the open question is whether that machinery works against someone patient. If your last penetration test found broken access control and unpatched hosts, a red team will tell you what you already know at several times the price.

There is a reasonable middle: a scoped exercise with a defined objective, a few weeks, and defenders informed. Sometimes called purple teaming — covered in purple team: what it is and when it beats a red team.

The question to ask a provider

Give them the objective and ask what they would attempt first, and what they would do if it failed.

A team that has run these describes a sequence — reconnaissance, the routes they would rank, the fallbacks. A team selling a penetration test with a different label will describe a methodology and a toolset.

What the exercise costs, and why the range is wide, is in what a red team engagement costs.