Guide

Red Team vs Penetration Test.

A pentest answers, 'how exploitable is this scope?' A red team answers, 'would my SOC notice an adversary working a specific objective against me?'

File · Answer first

Answer first

Pick by the question you actually need answered. If you want to know how exploitable a defined scope is, that is a pentest, and you should buy it first. If you already trust the exposure picture and want to know whether your SOC would catch an adversary working a goal across digital, physical, and human vectors, that is a red team. Run them out of order and the red team mostly returns hygiene findings a pentest would have surfaced cheaper. Below is where each one earns its budget.

File · Where each

Where each one fits

  • [01] Pentest: annual compliance, release validation, scoped technical exposure.
  • [02] Red team: testing SOC and IR maturity, validating detection investments, demonstrating worst-case adversary impact to the board.
  • [03] Pre-requisite for red team: a functioning SOC and IR program. Red-teaming a program that has not yet been pentested is like stress-testing an engine that has not been tuned. The result is noisy and the lesson is wrong: you get hygiene findings a pentest would have produced faster.

File · Related services

Related services

Penetration testing · Red teaming · Choosing a pentest vendor

File · FAQ

Frequently Asked Questions

Q1 Which should I do first?

Pentest first. Red team once your detection and response program is mature enough to learn from it.

Q2 How long is a red team?

In our engagements, red teams run 6 to 12 weeks and pentests run 2 to 6, with the exact window set at scoping against the objective and the surface.

Q3 Can you run both at once?

We can, but the lessons are clearer if they are separated in time.

Talk to an Operator

Ready to See Your Environment the Way Attackers Do?

Real operators. Real attack paths. Real business impact. Talk to us about your security goals.