Skip to main content

What a Red Team Assessment Involves

An objective, a set of rules, and a team that will take any route the rules permit. What actually happens across the weeks, and what you hold at the end.

3 min read

A red team assessment is a group of people trying to achieve a stated objective against your organisation, using whatever routes the rules permit, while your defenders are — usually — not told it is happening.

Everything that distinguishes it from a penetration test follows from that sentence. The comparison is in red team versus penetration testing; this is what the engagement actually consists of.

It starts with an objective

Not a scope. An objective — something specific and consequential:

  • Obtain a copy of the customer database.
  • Execute a transaction in the payment system.
  • Gain domain administrator.
  • Reach the environment holding cardholder data from outside it.

A good objective is one where success or failure is unambiguous and the consequence is obvious to a board. "Assess our security posture" is not an objective; it is a request for a penetration test.

Then the rules of engagement

The document that makes the exercise lawful and survivable. It records:

  • What is in and out. Which subsidiaries, which countries, which systems are untouchable.
  • Which techniques are permitted. Phishing yes, physical entry maybe, calling the service desk maybe, anything affecting availability almost certainly not.
  • The trusted agents. The two or three people who know, hold the authorisation, and can stop the exercise.
  • The stop condition. What ends it early — an outage, a real incident, the objective achieved.
  • The get-out-of-jail letter. A signed document the team carries, especially if physical entry is in scope, naming someone reachable at any hour who will confirm it.

That last one is not a formality. A tester detained by your own security staff at midnight needs a name and a number that answers.

What happens, in order

Reconnaissance

Weeks, sometimes, and almost all of it without touching you: staff on professional networks, job advertisements naming your stack, code and credentials in public repositories, documents with metadata, your address ranges and subdomains, physical layout and access routes.

This phase alone frequently produces findings you would rather not have.

Initial access

Getting a foothold. Phishing a person, exploiting something exposed, walking into a building, compromising a supplier, or a credential found in the previous phase. Teams normally rank several routes and try them in order of likely success and lowest noise.

Establishing and expanding

Persisting quietly, understanding the internal environment, and moving toward the objective — credentials, lateral movement, privilege escalation. This is where the exercise most often gets caught, and being caught is a result rather than a failure.

Reaching the objective

Demonstrating it, not exploiting it. A team proving access to the customer database extracts enough to prove it and stops. What is being purchased is proof, not damage.

The debrief

Usually the most valuable hours of the whole engagement: the red team and your defenders in a room, walking the timeline together. Here is when we did that. Did you see it? What did it look like on your side? Why did the alert not fire?

What you hold at the end

A narrative report — the story of the engagement in order, with evidence. What was attempted, what worked, what failed and why, what your monitoring saw, and where a response would have stopped it.

Alongside it, findings written up conventionally so they can be fixed, and a detection timeline that maps every action taken against whether it was logged, alerted or noticed.

That detection timeline is the deliverable people underestimate. It converts "our monitoring is good" into a list of exactly which techniques produced no alert.

Before you buy one

Be honest about whether the answer would change anything. A red team that succeeds through an unpatched host and a reused local administrator password has told you what a much cheaper exercise would have. The engagement earns its cost when your hygiene is already sound and the open question is detection and response.

What that costs is in what a red team engagement costs. Whether an Indian regulator expects one is in red teaming under the RBI's 2026 Directions.