Pentesting & red teaming

What is Red teaming?

Definition

A goal-based simulated attack that tests how well an organisation detects and responds to a realistic adversary, often over weeks and across people, process and technology.

How it works

Where a pentest tries to find as many weaknesses as possible in a defined scope, a red team pursues a specific objective, such as reaching a sensitive system, while trying to stay undetected. It tests the defenders as much as the defences.

Red team exercises can include phishing, physical access and social engineering, and are often guided by threat intelligence about real attacker groups.

Key points

  • Objective-led rather than coverage-led
  • Tests detection and response, not just controls
  • Can include phishing and physical access
  • Usually only a small group knows it is happening

Common questions

Is red teaming right for us?

It is most valuable once you have monitoring and response in place to test.

How long does it take?

Usually several weeks, depending on objectives.

Talk to someone who does this every day

Questions about Red teaming? Our team will give you a straight answer.

Contact us