What a Red Team Assessment Involves
An objective, a set of rules, and a team that will take any route the rules permit. What you have to have ready, what happens across the weeks, how deconfliction works when your defenders find it, and why the team failing is often the better result.
A red team assessment is a group of people trying to achieve a stated objective against your organisation, using whatever routes the rules permit, while your defenders are usually not told it is happening.
Everything that distinguishes it from a penetration test follows from that sentence. The comparison is in red team versus penetration testing; this is what the engagement actually consists of.
It starts with an objective
An objective, not a scope. Something specific and consequential:
- Obtain a copy of the customer database.
- Execute a transaction in the payment system.
- Gain domain administrator.
- Reach the environment holding cardholder data from outside it.
A good objective is one where success or failure is unambiguous and the consequence is obvious to a board. "Assess our security posture" is a request for a penetration test. Setting the objective well is most of the value you get from scoping, and it is covered in scoping a red team.
Then the rules of engagement
The document that makes the exercise lawful and survivable. It records:
- What is in and out. Which subsidiaries, which countries, which systems are untouchable.
- Which techniques are permitted. Phishing yes, physical entry maybe, calling the service desk maybe, anything affecting availability almost certainly not.
- The trusted agents. The two or three people who know, hold the authorisation, and can stop the exercise.
- The stop condition. What ends it early: an outage, a real incident, the objective achieved.
- The get-out-of-jail letter. A signed document the team carries, especially if physical entry is in scope, naming someone reachable at any hour who will confirm it.
A tester detained by your own security staff at midnight needs a name and a number that answers.
What you have to have ready
Less than buyers expect, and the few items are the ones that delay start dates:
- The trusted agents named, briefed, and genuinely contactable. Two is fragile; three is better, because one of them will be travelling.
- Written consent from any third party whose environment a permitted route crosses: a cloud provider, a managed service provider, a landlord.
- Legal sign-off on the rules of engagement, which on a first engagement takes longer than the scoping itself.
- A decision, in advance, about what happens to individual staff who fall for something. Agreeing that nobody is named before the exercise is far easier than agreeing it afterwards.
What happens, in order
Reconnaissance
Weeks, sometimes, and almost all of it without touching you: staff on professional networks, job advertisements naming your stack, code and credentials in public repositories, documents with metadata, your address ranges and subdomains, physical layout and access routes.
This phase alone frequently produces findings you would rather not have.
Initial access
Getting a foothold. Phishing a person, exploiting something exposed, walking into a building, compromising a supplier, or a credential found in the previous phase. Teams normally rank several routes and try them in order of likely success and lowest noise. The routes that actually work are in how red teams get in.
Establishing and expanding
Persisting quietly, understanding the internal environment, and moving toward the objective: credentials, lateral movement, privilege escalation. This is where the exercise most often gets caught, and a detection at this stage is a good outcome. The detail is in after the foothold.
Reaching the objective
Demonstrating it, not exploiting it. A team that reaches the customer database extracts enough to prove access and stops.
The debrief
Usually the most valuable hours of the whole engagement: the red team and your defenders in a room, walking the timeline together. Here is when we did that. Did you see it? What did it look like on your side? Why did the alert not fire?
The ordering of the phases, and how long each tends to run, is in the phases of a red team engagement.
Deconfliction, which is the process nobody explains
Your defenders are not told, so at some point they may find something and begin responding to it as a real incident. That is the exercise working, and it needs a procedure.
A trusted agent can be asked, at any hour, one question: is this us? The red team keeps a log precise enough to answer it, which means every action recorded with a timestamp, a source address and what was run. Without that log the question cannot be answered honestly, and the honest answer matters more than the exercise.
Three situations end the quiet part early, and all three should be written down before the engagement starts:
- The response is about to cost money. Pulling a production system offline, invoking a supplier's incident retainer, notifying a regulator. The exercise is disclosed before any of those happen.
- A real intruder is found. Red teams do occasionally walk into somebody else's compromise. The exercise stops that morning and becomes an incident response.
- Something breaks. Rare, because availability is almost always out of scope, and the stop condition exists for the times it is not.
What you hold at the end
A narrative report: the story of the engagement in order, with evidence. What was attempted, what worked, what failed and why, what your monitoring saw, and where a response would have stopped it.
Alongside it, findings written up conventionally so they can be fixed, and a detection timeline that maps every action taken against whether it was logged, alerted or noticed.
That detection timeline is the deliverable people underestimate. It converts "our monitoring is good" into a list of exactly which techniques produced no alert. What it says about your defenders is in what the exercise tells you about detection, and the full report structure is in what a red team report contains.
What a good outcome looks like
Buyers frequently assume the engagement has failed if the team does not reach the objective. The opposite is closer to the truth.
A team stopped at initial access by a control that worked, or caught during lateral movement by an alert somebody acted on, has produced the most valuable result available: evidence that the machinery works, with a timeline showing exactly where it engaged. That is the finding you were paying for. An engagement where the team walks to the objective unchallenged in four days is the cheap outcome to obtain and the expensive one to act on.
Treat the report as a measurement of detection and response instead of a scoreboard, and either result is worth what it cost.
Before you buy one
Be honest about whether the answer would change anything. A red team that succeeds through an unpatched host and a reused local administrator password has told you what a much cheaper exercise would have. The engagement earns its cost when your hygiene is already sound and the open question is detection and response. Where a collaborative exercise serves you better first, see purple team: when it beats a red team.
What that costs is in what a red team engagement costs. Whether an Indian regulator expects one is in red teaming under the RBI's 2026 Directions.
About the author
Siddarth G
Practice Director โ Cybersecurity
Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.
Continue reading
All articles โChoosing a Red Team Provider
Every firm answers yes to every capability question. Six questions where the generic yes runs out, and what a real answer sounds like.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.