Red teaming
Red teaming is a goal-based, covert attack simulation that tests detection and response, not just vulnerabilities. Definition, frameworks, difference to a pentest.
Updated This page as Markdown
In short
Red teaming is an attack simulation in which a team pursues a defined objective, for example reaching the production network or exfiltrating a data set, using any realistic means over several weeks, while the defenders (the blue team) are not told. It tests people, processes and detection, not just technical vulnerabilities. Frameworks such as TIBER-EU and the threat-led penetration tests of DORA formalise it for the financial sector.
What is red teaming?
Red teaming is a covert, objective-driven attack simulation. The red team gets a goal (“obtain domain admin”, “read the recipe database”, “send a command to a field device”) and a time frame of several weeks, then uses whatever a real adversary would: phishing, physical access, stolen credentials, vulnerabilities in exposed systems, lateral movement inside the network. Only a small control group (the white team) knows the exercise is running. The defenders, the blue team or SOC, are measured on whether and how fast they detect and contain it.
NIST defines a red team as a group authorised and organised to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture. The emphasis is on emulation and posture: the question is not “which vulnerabilities exist” but “would we notice and stop an attacker”.
Where is it defined?
The most concrete definitions come from the financial sector. TIBER-EU, published by the European Central Bank, describes threat-intelligence-based ethical red teaming with its phases (preparation, testing, closure), its roles (white team, threat intelligence provider, red team provider) and its deliverables. DORA, Regulation (EU) 2022/2554, makes threat-led penetration testing mandatory for designated financial entities at least every three years (Article 26), and the technical standards for it build on TIBER-EU. MITRE ATT&CK is the shared vocabulary for the tactics and techniques that are used and detected.
Outside finance, NIS2 does not mention red teaming by name. Article 21(2)(f) asks for procedures to assess the effectiveness of the security measures, and a red team exercise does that better than any audit.
What it means in practice
A red team exercise pays off when you already have detection in place. Three observations from engagements:
- It measures the SOC, not the firewall. The deliverable is a timeline: when the red team did what, what the blue team saw, how long until containment. If nobody is watching, the result is known in advance and a penetration test is the better use of the budget.
- The objective shapes everything. “Reach the engineering network” leads to a very different exercise than “exfiltrate customer data”. Choose objectives from your own risk analysis, not from a template.
- Rules of engagement are the safety net. Which systems are out of bounds, when to stop, how to deconflict with a real incident, who can abort. In OT environments the rules are strict: the red team shows that it could reach the controller, it does not write to it.
Zyberum runs red team exercises for IT environments and, with adapted rules, for production networks and vehicle fleets. Every exercise needs written authorisation from the management body, not just from the IT department.
Common misunderstandings
Red teaming is not a bigger penetration test. A pentest covers a scope broadly and reports all findings; a red team takes the one path that works and stays quiet. Doing a red team exercise before the first pentest wastes money: the team will walk in through a bug a pentest would have found in a day. It is also not purple teaming, where red and blue work together openly to tune detections; that is a useful follow-up, not the same thing.
FAQ
Frequently asked questions
How is red teaming different from a penetration test?
A penetration test covers a defined scope as completely as possible and reports every vulnerability; the defenders know it is happening. A red team exercise pursues one objective by any realistic path, stays covert and measures whether the organisation detects and stops the attack. The pentest finds bugs, the red team tests the response to an attacker.
When is my company ready for a red team exercise?
When you have had penetration tests, fixed the critical findings and run some form of detection, whether an internal team or a managed SOC. Without detection the outcome is known in advance. For a first engagement a penetration test, or a purple team exercise in which attackers and defenders work together, delivers more.
Is red teaming legal in Germany?
Yes, with written authorisation from the management body and clear rules of engagement. Phishing of employees, physical intrusion and the use of attack tools touch § 202a to § 202c StGB and labour law, so the authorisation, the exclusions and the handling of personal data have to be agreed before the first step.
Sources
Related pages
- GlossaryPenetration testA penetration test is an authorised, mostly manual attack on a system to find and prove exploitable vulnerabilities. Definition, types, process and the report.
- GlossaryPhishingPhishing is social engineering by message: attackers pose as a trusted sender to steal credentials or trigger actions. How it works, the variants, and what stops it.
- GlossarySOC (Security Operations Center)A SOC monitors systems around the clock, detects attacks and coordinates the response. What it consists of, what NIS2 expects, and when a managed SOC is better.
- ComparisonsPenetration Test vs Red Team: Scope, Goals and Which One You NeedA pentest finds as many vulnerabilities as possible in a defined scope. A red team checks whether detection and response stop a realistic attacker. Which fits when.
- InsightsPentest Scoping Checklist: What to Clarify Before the TestA checklist for scoping a penetration test: targets, environments, accounts, test depth, exclusions, time window, legal authorisation, deliverables and retest.
- ServicesEnterprise-grade protection. SMB-friendly price.24/7 managed security for SMBs: SentinelOne endpoint protection, SOC analysts, incident response and reports at a fixed monthly price per device.
