Lesson 1 of 4
Objective-based testing, and when you are ready for it
What a red team answers, what it costs, and the signs you should buy something else first.
14 min 3-question quiz 3 guides to read next
On this page
A red team exercise is an objective-based assessment of the whole organisation: people, process and technology, with detection and response explicitly in scope.
What makes it different
A penetration test asks whether a path exists. A red team asks whether a path can be walked without being stopped. That means stealth matters, the clock matters, and the blue team is part of the system under test — usually without being told.
Objectives are concrete and chosen with the business: obtain the design files for the next product, initiate a payment, access the customer database, demonstrate control of the production deployment pipeline.
When you are not ready
Be honest about this, because the exercise is expensive and the answer may already be known:
- No asset inventory, or known unpatched internet-facing systems. A red team will walk in the front door and teach you nothing.
- No central logging, or no one watching alerts outside working hours.
- A backlog of unfixed findings from previous tests.
In each case the money buys more by going into the gap you already know about. The useful sequence is: know what you have, fix what you know, detect what matters, then test the detection.
Flavours
Full red team, covert, long, objective-driven. Assumed breach, starting from a foothold — far cheaper, and it tests the part most organisations are actually weak at. Purple team, collaborative and iterative. Adversary emulation, reproducing a specific threat actor's documented behaviour.
For most organisations, assumed breach and purple teaming produce more improvement per pound than a covert full-scope exercise, which is often bought for the narrative rather than the outcome.
Safety
A trusted agent inside the client who knows the exercise is running, pre-agreed stop conditions, and a way to prove rapidly that an alert is the exercise rather than a real intrusion — otherwise you have caused an incident rather than tested one.
Check your understanding
3 questions · pass with 2 correct
Enrol for free to save your progress, unlock every lesson and earn a certificate.
Sign in to enrolFurther reading
Guides that go deeper on this lesson.
-
Red Teaming LLM Applications for Security
Planning and running adversarial security tests against AI applications, and turning findings into fixes.
1 min read
-
What a Penetration Test Is, and Is Not
A penetration test is a time-boxed, authorised attempt to reach a defined objective — not a full inventory of every weakness you have.
2 min read
-
Building a Secure AI Programme
How organisations can organise AI security: ownership, inventory, policy, controls and continuous improvement.
1 min read