Red teaming is an authorized exercise in which a team of testers, the red team, behaves like a real attacker against an organization to find out whether its defenders can detect, investigate and stop them. Unlike a test that tries to list every weakness, a red team exercise usually has a goal, such as reaching a sensitive system or dataset, and pursues it quietly by whatever routes are allowed in the rules of engagement. The result shows how people, processes and technology hold up together under realistic pressure.
At a glance
- Red teaming simulates a realistic, goal-driven attacker, not a checklist of vulnerabilities.
- It tests detection and response as much as prevention: did anyone notice, and what did they do?
- Scope can include technical attacks, phishing and other social engineering and, in some engagements, physical entry.
- Most defenders are not told in advance; a small group of leaders approves and oversees it.
- It generally fits organizations that already have security monitoring in place to test.
What problem it solves
Organizations spend heavily on security tools, monitoring services and policies, but rarely see them tested against a determined attacker. A penetration test can show that a system has weaknesses; it usually doesn’t show whether the security operations team or provider would notice someone exploiting them, or how long it would take.
Red teaming answers that question. It reveals gaps between what a business believes its defenses do and what actually happens: alerts that fire but go unread, logs that aren’t collected, escalation paths that stall, or staff who can be talked into handing over access. That evidence helps leaders prioritize spending and hold internal teams and providers to account.
How it works
Planning and rules of engagement. The organization and the red team agree goals, what is in and out of scope, which techniques are allowed (for example, whether phishing or physical access attempts are included), who knows about the exercise, and how to stop it quickly if needed.
Reconnaissance. The red team gathers information as an attacker would: public information about staff and systems, exposed services and possible entry points.
Attack. Testers try to get in and move toward the goal, often modelling the tactics, techniques and procedures (TTPs) of attacker groups relevant to the industry. They try to stay undetected, which tests monitoring as much as defenses.
Observation. The small group that knows about the exercise tracks what defenders saw and how they responded, for example in the security operations center (SOC).
Reporting and debrief. The red team explains the path it took, where it was or wasn’t detected, and what to fix. Many organizations then run a purple team session, with attackers and defenders working together to improve detections.
When it matters for buyers
- When you’ve invested in monitoring and want proof it works. A red team exercise tests whether your SOC or managed detection and response (MDR) provider catches a realistic intrusion.
- When regulators or major customers expect it. Some sectors and large customers ask for threat-led testing; requirements vary by industry and country.
- When penetration tests stop finding much. Red teaming shifts the question from “what’s vulnerable?” to “would we notice?”
- After significant change. Mergers, new remote access setups or a new security provider are good moments to test how defenses work together.
- When planning budgets. Findings give concrete evidence for where to invest. Our penetration testing overview covers how offensive testing services are scoped and bought.
Questions to ask vendors
- What experience do your testers have, and which certifications or references can you share?
- How do you design the scenario: which attacker types and techniques will you model, and why?
- What is in scope (technical, social engineering, physical), and what is excluded?
- How do you avoid disrupting production systems, and how quickly can you stop on request?
- How do you protect any data or credentials you obtain during the exercise?
- What does the report include, and do you offer a purple team follow-up to improve detection?
- How is the engagement priced: fixed fee, duration or scenario?
How it differs from penetration testing
Penetration testing aims to find and confirm as many weaknesses as possible within a defined scope, such as an application or network, often with defenders aware of the test. Red teaming is narrower in goal and broader in method: it pursues a specific objective by any allowed route, including people and processes, and tests whether the organization detects and responds. A pen test answers “where are we weak?”; a red team answers “would we catch an attacker who used those weaknesses?” Both are useful, and many organizations do regular pen tests and occasional red team exercises. A tabletop exercise, by contrast, is a discussion-based walkthrough of a scenario with no live attack at all.
