root64Offensive Security. Cyber Resilience. Trusted Expertise.
Insight

Do you need a red team, or a penetration test?

The two are sold interchangeably and answer completely different questions. Buying the wrong one is expensive.

ROOT64 / FIELD NOTES19 August 20265 min · Root64

The words get used loosely, often deliberately, because red teaming sounds more advanced and prices higher. They are not tiers of the same service. They answer different questions and produce different documents.

Different questions

A penetration test asks: can this system be broken into, and how? Coverage is the goal. The tester works systematically through the attack surface to find as much as possible in the time available, and your team usually knows it is happening.

A red team exercise asks: if someone got in, would we notice, and what would we do? Stealth is the goal. The team pursues one defined objective by whatever agreed route works, and your defenders are not told, because the thing being measured is their real behaviour.

A penetration test measures your systems. A red team exercise measures your organisation.

Different outputs

A penetration test produces a finding register: a list of weaknesses, scored, with fixes. A red team exercise produces a timeline: what we did, when we did it, what your tooling saw, what your people did about it, and where the process broke.

You cannot fix a detection gap with a patch, and you cannot fix an injection flaw with a better runbook. The reports are not interchangeable.

Red teaming is the wrong first purchase

If you have never had a penetration test, a red team exercise will find the same basic issues at several times the cost, because the team will simply walk in through the front door and stop. You will have paid a premium to learn something a cheaper engagement would have told you in week one.

There is a readiness bar. Roughly: known vulnerabilities have been tested and largely remediated, some form of endpoint and log monitoring is in place, and someone is responsible for looking at the alerts. Below that bar, red teaming is theatre.

What sits between them

Assumed-breach testing starts the tester inside the network on a standard workstation, skipping the initial access phase. It costs less than a full red team exercise and answers most of the internal question — how far can someone get from a compromised laptop.

Purple teaming runs the same techniques openly, with your defenders in the room watching their own tooling react. It builds detection faster than a covert exercise, though it does not test whether anyone would have noticed unprompted.

A simple way to choose

  • You are launching or significantly changing an application — penetration test
  • A customer or auditor is asking for evidence of testing — penetration test
  • You have built a security team and want to know if it works — red team
  • You have monitoring but have never seen it catch anything real — red team, or purple team first
  • You want to know how far an attacker gets from one compromised laptop — assumed breach
  • You are not sure your basics are covered — penetration test, and revisit this in a year

A provider willing to tell you that you do not need the more expensive engagement is worth more than the engagement.


All insights

Your next move

Start a conversation

Contact us