All research

Red team or penetration test: which do you need?

Short answer: A penetration test finds and ranks as many exploitable weaknesses as it can inside a defined scope, with your team's knowledge. A red team pursues one objective the way a real attacker would, quietly, to test whether your defenders detect and stop it. If you have never had security testing or need to satisfy an auditor or insurer, you want a penetration test. A red team is what you graduate to once you have a security team worth testing.

Sales decks use "red team" and "penetration test" as if they were the same premium service with two names. They are not. They answer different questions, run on different scopes, and cost differently for good reasons. If you are buying, confusing the two is an easy way to pay red team money for a job a pentest would have done, or to buy a pentest when the question you actually have is whether anyone would notice an attacker inside. Here is the honest difference.

What a penetration test is for

A penetration test answers one question: what in this defined scope can an attacker exploit, and how bad is it. Testers work through the systems you put in bounds, find weaknesses, and where the rules allow, prove real impact by chaining them together. The US National Institute of Standards and Technology, in its testing guide NIST SP 800-115, describes penetration testing as security testing in which assessors mimic real-world attacks to identify ways to get around the security features of an application, system, or network.

The point is coverage. A good pentest tries to find as many exploitable issues as it can inside the scope during the testing window. Your team usually knows it is happening, because the goal is depth of findings, not secrecy. You come out with a ranked list of what is wrong and what to fix first.

What a red team is for

A red team engagement answers a different question: if a real attacker came for a specific objective, would your people, process, and technology stop them, and would anyone even notice. NIST defines a red team exercise as a simulated adversarial attempt, reflecting real-world conditions, to compromise an organization's missions or business processes and assess the security capability of the system and the organization.

Read that carefully. A red team is not measured by how many vulnerabilities it lists. It is measured against an objective, for example reaching a specific database or a payment system, using whatever path works: an unpatched service, a phishing email, a physical door, a reused password. It emulates how genuine adversaries operate, often mapped to a public knowledge base of attacker behavior like MITRE ATT&CK. Stealth is part of the test, because one of the things being tested is your detection and response.

Regulators treat it this way too. The European Central Bank's TIBER-EU framework, published in 2018, uses threat-intelligence-led red teaming to test the resilience of financial firms against realistic attacks, precisely because it measures response, not just exposure.

The real differences, side by side

 Penetration testRed team
GoalMaximize exploitable findings in scopeReach one objective and report how far it got
ScopeA list of assets and techniquesAn objective and rules, with far more paths allowed
StealthUsually known to your teamHidden, because it tests whether you catch it
What it testsYour systemsYour defenders as much as your systems
Cost and durationShorter, less expensiveLonger, quieter, more expensive
Best forFirst testing, audits, insurers, enterprise customersMature teams checking their detection and response

Assumed breach: the useful middle

Not every red team starts from zero. A common variant is "assumed breach," where you hand the team a foothold, say one laptop or one set of employee credentials, and ask how far they can get from there. It skips the slow initial-access phase and puts the budget into testing what happens after an attacker is already inside, which for most companies is the scarier and more realistic question.

Which one your company actually needs

Here is the part most vendors will not say plainly. A red team tests your blue team. If you do not have a blue team, that is, people and tooling watching for and responding to intrusions, there is very little for a red team to measure, and you will pay a premium to be told what a pentest would have told you cheaper. Detection you do not have will not detect the red team either.

So, roughly:

Maturity is the deciding factor. Red teaming is what you graduate to once the basics are covered, not where you start.

Start by knowing your surface

Whichever direction you are heading, the first honest step is the same: know what an attacker can already see about you from the outside, because that is where any of them, pentester or red teamer, begins.

Our $100 check is that first look, done properly: a focused review of your external attack surface, on scope you have verified you own and authorized in writing, reviewed by a senior operator and delivered with a 30-minute readout. Be clear on what it is. It is not a red team, and it is not a full penetration test. It is the cheap, honest starting point that tells you which of those you actually need next, with the evidence in front of you.

Red team vs penetration test: quick answers

What is the difference between a red team and a penetration test?

A penetration test finds and ranks as many exploitable weaknesses as it can inside a defined scope, usually with your team's knowledge. A red team pursues a single objective the way a real attacker would, quietly, to test whether your defenders detect and stop it. A pentest tests your systems; a red team tests your systems and your people.

Is a red team more thorough than a penetration test?

Not exactly. A red team is deeper on a narrow path to one objective and on your detection and response, but a penetration test is broader on finding exploitable issues across the scope. They answer different questions, so "more thorough" depends on which question you have.

Which should a small company get first?

Almost always a penetration test, or a cheaper attack-surface check before that. A red team measures your blue team, so if you do not yet have people and tooling watching for intrusions, there is little for it to measure and you will pay a premium to learn what a pentest would have told you.

Does an auditor or insurer asking for a "red team" really mean a red team?

Often they mean a penetration test and use the words loosely. Confirm the exact requirement in writing before you buy, because the price difference is large.

Related reading

Not sure which you need?

Most companies need a penetration test, not a red team, and often the cheapest first step is just seeing your exposure. Our $100 check is that first look.

Book a $100 check