Skip to main content

What a Red Team Engagement Costs

Quotes for the same objective can differ threefold. What drives the number — duration, team size, physical and social scope — and how to compare proposals that are not describing the same work.

3 min read

Ask three firms to price the same objective and the quotes can differ by a factor of three. Almost always they are describing different work, and the cheapest is describing the least.

Red teaming is priced in team-weeks, not tester-days. That alone explains most of the gap with a penetration test: you are buying several people for several weeks, and much of that time is deliberately unhurried.

What moves the number

Duration

The largest driver, and the one most often cut to win a deal. A red team compressed into one week is a penetration test wearing the name: there is no time for patient reconnaissance, no time to wait out a detection, no time for a second route after the first fails.

Patience is the product. A quote that halves the duration has not made the exercise cheaper; it has made it a different exercise.

Team size and composition

A credible engagement needs more than one person: someone strong on initial access, someone on internal movement, someone who understands your platform, and an engagement lead. Some objectives need a specialist — an operational technology environment, a mainframe, a particular cloud.

Which initial access routes are in scope

Each one adds cost, and the cheap quote is usually cheap because it includes only the first:

  • External only — the perimeter, exposed services, published credentials.
  • Phishing — infrastructure, convincing pretexts, and the staff time to prepare them.
  • Physical — people on site, travel, reconnaissance, and real risk to the individuals involved. See physical penetration testing.
  • Voice and service desk — pretexting your own helpdesk into a password reset, which is frequently the single most effective route and raises the most sensitive questions about how results are reported.

How many environments

An objective inside one corporate network is one exercise. An objective requiring a route through a subsidiary, a supplier, or a separately administered cloud is several.

Whether detection is being measured

If the point includes what your defenders saw, the team must log every action against a timeline and produce that mapping. That is real analyst effort after the exercise ends, and it is the deliverable most worth paying for.

What does not move it much

The number of systems. Red teaming is not priced by asset count — that is penetration testing's unit. An objective inside a large estate and the same objective inside a small one cost similarly, because the work is reaching the objective, not covering the estate.

Comparing quotes that are not comparable

Five questions make otherwise incomparable proposals line up:

  • How many team-weeks, and how many people? Convert everything to this. A "10-day red team" from one firm and a "4-week" from another may be the same money and very different exercises.
  • Which initial access routes are included? Named explicitly, not implied.
  • Is the detection timeline a deliverable? If not, half the value is missing.
  • Is a joint debrief with our defenders included? The most valuable hours are frequently the cheapest line item.
  • Who is actually on the team? Names and experience, not a capability statement.

The honest sizing question

Before comparing anything, ask whether the exercise is the right purchase at all. If your last penetration test surfaced unpatched hosts and weak internal credentials, a red team will reach its objective through those and charge several times as much to tell you so.

The engagement is worth its price when hygiene is sound and the open question is whether anyone would notice. What that engagement involves is in what a red team assessment involves.