What the Exercise Tells You About Detection
The findings are about your systems. The timeline is about your team. Read from the defender’s side, a red team report is a much more uncomfortable document.
Most of a red team report describes what the attackers did. The half worth more describes what you did, and it is usually read too quickly.
Three ways detection fails, and they need different fixes
No data. The activity produced no log anywhere — an unmonitored system, a log source that was never onboarded, a network segment nothing watches. The fix is collection, and it costs money.
Data, no alert. The evidence was collected and nothing drew attention to it. This is the largest category in most engagements, and it is the cheapest to fix — usually a rule that does not exist or a rule scoped to the wrong source. It is also the most demoralising to read, because the answer was sitting in the platform the whole time.
Alert, no response. Something fired and nothing happened. Acknowledged and closed, lost in volume, or raised at 02:00 to a rota that does not operate at 02:00. This is the only one that is not a tooling problem at all, and it is the one that most often survives another year of spending.
A report that says "not detected" without distinguishing these three has given you a number instead of a diagnosis.
"We had no alerts" is not the finding
Teams frequently conclude the exercise proves their monitoring is useless. It usually proves something narrower: that the specific techniques used, against the specific systems touched, within that window, were not caught.
Two honest caveats belong on any conclusion drawn from one red team. It tested one route — a different objective would have exercised different detections. And a team that got caught early may simply have been unlucky rather than facing a strong defence.
Breadth is what purple teaming is for. A red team gives depth on one path; purple gives coverage across many. Concluding your whole detection posture from a single narrative overreads the evidence.
What to do with it
Take the timeline and, for every action marked undetected, decide which of the three failure modes it was. That classification is the actual work product, and it converts a narrative into a funded plan: collection gaps go to engineering, rule gaps to the detection team, response gaps to whoever owns the rota.
Then re-run the specific techniques and confirm they now fire. That is a purple team exercise, it is cheap, and it is how the money already spent turns into something measurable.
The thing worth protecting
Nobody being blamed. A red team report names the moment a person did not challenge a stranger, or an analyst closed an alert. If the exercise produces disciplinary consequences it will be the last honest one you get, because everyone who might have reported something ambiguous will now stay quiet.
Continue reading
All articles →Choosing a Red Team Provider
Every firm answers yes to every capability question. Six that are harder to answer generically, and what a real answer sounds like.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.