Blog
How to Get Started with Red Teaming – Expert Tips
Find out about the different types of red teaming , plus hot tips for how to get the best out of a red team engagement


So, to start from the top: what makes a red team engagement different than a penetration test ? The short answer is: pen testing is out to give you a comprehensive list of vulnerabilities that you need to fix. Red teaming is out to circumvent your defences the way a real attacker would, delivering very valuable insights in the process.
The longer answer here is better: red teams are threat driven, meaning we use real threat intelligence as an ongoing guide for operations. This doesn't mean we simply follow a set play book with no deviation like a robot. Rather, we apply the same processes and approaches used by real threats to modify our techniques based on our target whilst adhering to the threat's ultimate operational goals and capabilities. Red team engagements are goal orientated, which ensures the attacking team remains focused on key areas that matter to the client.
A penetration test on the other hand seeks to find, evaluate, exploit and categorise all vulnerabilities in as short a time as possible whilst covering the maximum number of systems. A Red Team often follows the path of least resistance to achieve its objectives and is after depth over breadth in terms of coverage. Red Teaming is designed to take a holistic view of your defences at each level and the depth of detail in findings and recommendations should be apparent over normal penetration testing results.
Context is king. Within a red team engagement, we look to work within the confines of your technical and procedural controls. We do not ask for exceptions to be made and whitelisting actions to be taken, unless required based on time or financial restrictions (we call these fall backs or dechaining events). We provide you with insights into the wins and losses across an attack chain. If your defences excel in repelling initial access but your internal network is more of a chocolate fondant, then the Red Team will highlight this.

Detection and response matters! Red teams are not a red team without a counter or opposite, be that an external MDR, a dedicated internal security team, or even a growing security function. The red team provides an ideal opportunity to evaluate and enhance the protection offered by these services. All reports do (or should) contain detailed detection guidance where appropriate around the techniques and approaches used during the assessment. The red team should help to highlight detection gaps and provide realistic context on these blind spots. No one can (or will ever) detect everything, but what areas of the attack chain within a scenario should be focused on, where the attacking team are at their most vulnerable. An experienced red team will be able to provide this insight.
Maturity, objectives and complexity are the guiding principles I use when designing scenarios and proposals. These differ from the quantity-driven approaches often taken in a penetration test, in which complete coverage is wanted or samples are taken. With these principles we can provide project delivery estimates and costing that deliver the best value for a client and align outcome expectations early on. Red teams often work with wide scopes and targeted objectives. This wide to narrow approach ensures the attacking team have all the opportunities possible to achieve objectives in the same way a real attacker would, but their approaches and goals keep the engagement on track and stop it from drifting off course.

The other side of the coin might be that you haven't had any form of testing done but want to look to explore red teaming. With all organisations I would always suggest that the basics are done before jumping in for a red team, though the waters are a bit less clear these days with some less reputable security providers selling penetration testing as red teaming and vice versa. But I'd always say red teaming is an evaluation of the organisation as a whole, and that a true sign of maturity is the basics done and done well. So, start small, ensure you have a handle on vulnerability management, carry out penetration testing, and align your systems and networks with hardening best practices. From there detection and prevention should also be considered, with these basics in hand and a good understanding of your security operation you should look to add in red team engagements in tandem with other tests or in isolation. This might mean starting with assumed breach or a tailored end- to-end red team.
I hope this blog has provided a small insight into the different engagement options and approaches possible with red teaming. If you just don’t know if you need it or how to start, don’t be afraid to get in touch. We can have an impartial conversation around engagement options: we don’t want to sell you something that won’t give you value, so we’re always happy to discuss options and suggest relevant testing approaches.
Share your challenge with us and we’ll help you find the right level of support for your business.














