Choosing a Red Team Provider
Every firm answers yes to every capability question. Six that are harder to answer generically, and what a real answer sounds like.
Capability questions do not discriminate. Every firm does red teaming, has certified people and follows a methodology. The questions below are harder to answer without having done the work.
1. Given this objective, what would you try first — and what if it failed?
The single most useful question, and it costs nothing.
A team that has run these describes a sequence: what reconnaissance would target, which routes they would rank and why, what the fallback is. A team selling a penetration test under a different name describes a methodology and a toolset.
2. Who is actually on the team?
Names, and what each person does. Red teaming is small-team work and the outcome depends heavily on the individuals. A proposal that describes a capability rather than people is describing a bench you may not get.
Ask specifically whether the people who scoped it will run it.
3. How many team-weeks, and how many people?
The unit that makes proposals comparable. A "10-day red team" and a "4-week" may be similar money and very different exercises. Details in what a red team engagement costs.
4. Is the detection timeline a deliverable?
If it is not in the proposal it will not be in the report, and half the value of the exercise goes with it. Same for the joint debrief with your defenders, which is usually the cheapest line item and the most useful hours.
5. What have you not been able to do?
An honest team will describe an engagement where they did not reach the objective, or were caught in the first week, and what they learned. A team claiming an unbroken record is either selling to organisations with no defences or is not telling you about the other ones.
6. What happens if you break something?
Rare, and it happens. What matters is whether there is a rehearsed answer: who is called, how quickly, what the stop conditions are, what insurance exists. A team that has not thought about it has not run many.
On credentials
Certifications and accreditations are a floor rather than a differentiator — useful for excluding, weak for choosing. Where an accreditation is genuinely load-bearing is when an external requirement names it, in which case it is a prerequisite rather than a quality signal.
For Indian engagements, whether CERT-In empanelment applies is a question about the instrument that binds you, not about the vendor. Establish it before commissioning rather than discovering afterwards that a competent engagement produces a document your auditor will not accept.
The question to ask yourself first
Before comparing anyone: what would we do differently depending on the result? If the honest answer is nothing, no provider is the right one yet. Buy the exercise that would change something — which for most organisations, most of the time, is a purple team.
That last sentence costs us engagements and it is the correct advice.
Continue reading
All articles →Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.
What the Exercise Tells You About Detection
The findings are about your systems. The timeline is about your team. Read from the defender’s side, a red team report is a much more uncomfortable document.