What a Red Team Assessment Involves
An objective, a set of rules, and a team that will take any route the rules permit. What actually happens across the weeks, and what you hold at the end.
A red team assessment is a group of people trying to achieve a stated objective against your organisation, using whatever routes the rules permit, while your defenders are — usually — not told it is happening.
Everything that distinguishes it from a penetration test follows from that sentence. The comparison is in red team versus penetration testing; this is what the engagement actually consists of.
It starts with an objective
Not a scope. An objective — something specific and consequential:
- Obtain a copy of the customer database.
- Execute a transaction in the payment system.
- Gain domain administrator.
- Reach the environment holding cardholder data from outside it.
A good objective is one where success or failure is unambiguous and the consequence is obvious to a board. "Assess our security posture" is not an objective; it is a request for a penetration test.
Then the rules of engagement
The document that makes the exercise lawful and survivable. It records:
- What is in and out. Which subsidiaries, which countries, which systems are untouchable.
- Which techniques are permitted. Phishing yes, physical entry maybe, calling the service desk maybe, anything affecting availability almost certainly not.
- The trusted agents. The two or three people who know, hold the authorisation, and can stop the exercise.
- The stop condition. What ends it early — an outage, a real incident, the objective achieved.
- The get-out-of-jail letter. A signed document the team carries, especially if physical entry is in scope, naming someone reachable at any hour who will confirm it.
That last one is not a formality. A tester detained by your own security staff at midnight needs a name and a number that answers.
What happens, in order
Reconnaissance
Weeks, sometimes, and almost all of it without touching you: staff on professional networks, job advertisements naming your stack, code and credentials in public repositories, documents with metadata, your address ranges and subdomains, physical layout and access routes.
This phase alone frequently produces findings you would rather not have.
Initial access
Getting a foothold. Phishing a person, exploiting something exposed, walking into a building, compromising a supplier, or a credential found in the previous phase. Teams normally rank several routes and try them in order of likely success and lowest noise.
Establishing and expanding
Persisting quietly, understanding the internal environment, and moving toward the objective — credentials, lateral movement, privilege escalation. This is where the exercise most often gets caught, and being caught is a result rather than a failure.
Reaching the objective
Demonstrating it, not exploiting it. A team proving access to the customer database extracts enough to prove it and stops. What is being purchased is proof, not damage.
The debrief
Usually the most valuable hours of the whole engagement: the red team and your defenders in a room, walking the timeline together. Here is when we did that. Did you see it? What did it look like on your side? Why did the alert not fire?
What you hold at the end
A narrative report — the story of the engagement in order, with evidence. What was attempted, what worked, what failed and why, what your monitoring saw, and where a response would have stopped it.
Alongside it, findings written up conventionally so they can be fixed, and a detection timeline that maps every action taken against whether it was logged, alerted or noticed.
That detection timeline is the deliverable people underestimate. It converts "our monitoring is good" into a list of exactly which techniques produced no alert.
Before you buy one
Be honest about whether the answer would change anything. A red team that succeeds through an unpatched host and a reused local administrator password has told you what a much cheaper exercise would have. The engagement earns its cost when your hygiene is already sound and the open question is detection and response.
What that costs is in what a red team engagement costs. Whether an Indian regulator expects one is in red teaming under the RBI's 2026 Directions.
Continue reading
All articles →Choosing a Red Team Provider
Every firm answers yes to every capability question. Six that are harder to answer generically, and what a real answer sounds like.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.