Skip to content

Lesson 1 of 4

Free preview

Objective-based testing, and when you are ready for it

What a red team answers, what it costs, and the signs you should buy something else first.

14 min 3-question quiz 3 guides to read next

On this page
  1. What makes it different
  2. When you are not ready
  3. Flavours
  4. Safety

A red team exercise is an objective-based assessment of the whole organisation: people, process and technology, with detection and response explicitly in scope.

What makes it different

A penetration test asks whether a path exists. A red team asks whether a path can be walked without being stopped. That means stealth matters, the clock matters, and the blue team is part of the system under test — usually without being told.

Objectives are concrete and chosen with the business: obtain the design files for the next product, initiate a payment, access the customer database, demonstrate control of the production deployment pipeline.

When you are not ready

Be honest about this, because the exercise is expensive and the answer may already be known:

  • No asset inventory, or known unpatched internet-facing systems. A red team will walk in the front door and teach you nothing.
  • No central logging, or no one watching alerts outside working hours.
  • A backlog of unfixed findings from previous tests.

In each case the money buys more by going into the gap you already know about. The useful sequence is: know what you have, fix what you know, detect what matters, then test the detection.

Flavours

Full red team, covert, long, objective-driven. Assumed breach, starting from a foothold — far cheaper, and it tests the part most organisations are actually weak at. Purple team, collaborative and iterative. Adversary emulation, reproducing a specific threat actor's documented behaviour.

For most organisations, assumed breach and purple teaming produce more improvement per pound than a covert full-scope exercise, which is often bought for the narrative rather than the outcome.

Safety

A trusted agent inside the client who knows the exercise is running, pre-agreed stop conditions, and a way to prove rapidly that an alert is the exercise rather than a real intrusion — otherwise you have caused an incident rather than tested one.

Check your understanding

3 questions · pass with 2 correct

1. Which sign means an organisation is not ready for a covert red team?
2. What is an assumed-breach exercise?
3. Why is a trusted agent needed?

You'll see your score; enrol to have it count towards your certificate.

Enrol for free to save your progress, unlock every lesson and earn a certificate.

Sign in to enrol

Further reading

Guides that go deeper on this lesson.