Operational resilience
Seven signs it's time for a red team, not another penetration test
A penetration test finds weaknesses in the systems you scope. A red team tests whether your organisation would notice and stop a real attacker. Seven signs you have outgrown annual penetration testing, the signs you are not ready yet, and what to ask a red team provider.
A penetration test and a red team exercise are often bought as if they were bigger and smaller versions of the same thing. They are not. A penetration test looks for as many weaknesses as possible in the systems you put in scope, usually with your team aware it is happening. A red team pursues a specific objective, such as reaching your payment systems or client files, by whatever route a real attacker would use, and usually without your defenders being told.
The penetration test asks what is vulnerable? The red team asks would we notice, and could we stop it? Here are seven signs that the second question is now the one that matters.
1. Your penetration tests keep coming back with the same findings
If each year's report lists the same medium-risk issues, or very little at all, the test is no longer telling you much that is new. That can mean your estate is in good shape, or that the scope has stopped reflecting how an attacker would actually come at you. Either way, more of the same test is unlikely to change your risk.
2. You pay for detection and response but have never seen it work
Many organisations now run managed detection and response or a managed SOC, and have only ever seen it handle routine alerts. A red team is the closest thing to a real intrusion you can control. It shows whether the service spots a careful attacker, how quickly it escalates, and whether the pre-agreed response actions actually happen.
3. Your board is asking "could that happen to us?"
After a peer suffers a serious incident, boards rarely want a list of vulnerabilities. They want to know whether the same attack would succeed here. A red team built around that scenario gives a direct answer, and a timeline the board can follow: what the attacker did, what was noticed, and when.
4. A regulator or framework expects threat-led testing
Some regulated firms are expected to go beyond penetration testing. In UK financial services, CBEST is the Bank of England's intelligence-led testing framework for firms and infrastructure it selects. Under DORA, financial entities that meet the criteria must carry out threat-led penetration testing at least every three years. Even where neither applies, firms building their operational resilience under the FCA's rules are increasingly expected to show that their response has been tested, not just written down.
5. Your biggest risk is people and process, not one system
Penetration tests are scoped to systems. Many real intrusions begin with a convincing phishing email, a call to the IT helpdesk asking for a password reset, or someone walking into an office behind an employee. If those are the routes that worry you, they need to be in scope, and a red team is designed to include them.
6. Your incident response plan has only been tested on paper
Tabletop exercises are valuable, but everyone in the room knows it is an exercise and has time to think. A red team tests the plan under real conditions: whether the right people are called, whether they can be reached out of hours, and whether decisions such as isolating systems get made in time.
7. You have fixed the basics
The best sign you are ready is that previous penetration test findings have been remediated, patching and multi-factor authentication are in place, and you know what is on your network. At that point, the remaining risk sits in how well you detect and respond, and that is what a red team measures.
Signs you are not ready yet
A red team against an organisation with obvious gaps produces an expensive report confirming what you already knew. Stay with penetration testing, and fix the findings, if:
- critical or high findings from your last penetration test are still open;
- you do not have an up-to-date picture of your systems and accounts;
- there is no monitoring in place for the red team to test;
- nobody owns the response to what the exercise finds.
If you have just introduced monitoring, a purple team exercise is often the better next step: testers and defenders work together, running attack techniques openly and checking each one is detected, before you test the service unannounced.
What to ask a red team provider
- How will you build the scenarios? Good exercises start from threat intelligence about who targets organisations like yours, not a generic playbook.
- What are the rules of engagement? You should agree in writing what is in and out of bounds, including people, premises and production systems.
- Who is in the control group, and how is the exercise stopped? There must be a way to separate the exercise from a real incident at any hour.
- What will the report show? Look for a timeline of what the testers did set against what your defenders saw and did, not just a list of vulnerabilities.
- What accreditations does the team hold? Ask which schemes cover intelligence-led red team work, such as those run by CREST, and for financial firms whether the team can deliver CBEST where it applies.
- Will you replay the exercise with our defenders? The most useful learning often comes from walking through the timeline together afterwards.
Where Threat Protect fits
We arrange tester-led penetration testing and red teaming through independent specialist testers. We help you decide which test you need, and when, set the objectives and rules of engagement with you, and turn the findings into a remediation plan that gets done, not filed. Where we also provide your managed detection and response, the exercise becomes a direct test of that service, and the results feed your continuous compliance evidence.
If you are deciding between another penetration test and a red team, book a call and bring your last report. We will tell you which one would teach you more.
Further reading
- Penetration testing, NCSC
- CBEST threat intelligence-led assessments, Bank of England
- Regulation (EU) 2022/2554 (DORA), Articles 26 and 27, EUR-Lex
Frequently asked
Questions readers ask before getting in touch.
- A penetration test looks for as many weaknesses as possible in a defined set of systems, usually with your team aware it is happening. A red team exercise pursues a specific objective, such as reaching payment systems or client data, using whatever route a real attacker would, and usually without your defenders being told. The penetration test asks what is vulnerable; the red team asks whether you would detect and stop an attack.
- No. Penetration testing still finds and prioritises specific weaknesses, and many frameworks and contracts expect it. A red team is an addition for organisations whose basics are in place and who now need to test detection, response and people as well as technology.
- Longer than a penetration test. Allow for scoping, threat intelligence to build realistic scenarios, an active phase that commonly runs for several weeks, and time afterwards to replay the timeline with your defenders. The exact length depends on the objectives and how much of the organisation is in scope.
- A small control group, sometimes called the white team: usually a senior sponsor, someone who can stop the exercise, and whoever needs to separate it from a real incident. Your security operations team and service providers are normally not told, because their response is part of what is being tested.
- A collaborative exercise where the attacking testers and your defenders work together, running techniques openly and checking whether each one is detected. It is a good step between penetration testing and a full red team, especially when you have just introduced managed detection and response.
Talk to us
Want to talk through how this applies to your company?
A 30-minute call with a senior advisor. No pitch. We will read your situation against what is in this piece and tell you the smallest sensible next step.