Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryPenetration Testing

Red teaming

Red teaming is a goal-based, covert attack simulation that tests detection and response, not just vulnerabilities. Definition, frameworks, difference to a pentest.

Updated This page as Markdown

In short

Red teaming is an attack simulation in which a team pursues a defined objective, for example reaching the production network or exfiltrating a data set, using any realistic means over several weeks, while the defenders (the blue team) are not told. It tests people, processes and detection, not just technical vulnerabilities. Frameworks such as TIBER-EU and the threat-led penetration tests of DORA formalise it for the financial sector.

What is red teaming?

Red teaming is a covert, objective-driven attack simulation. The red team gets a goal (“obtain domain admin”, “read the recipe database”, “send a command to a field device”) and a time frame of several weeks, then uses whatever a real adversary would: phishing, physical access, stolen credentials, vulnerabilities in exposed systems, lateral movement inside the network. Only a small control group (the white team) knows the exercise is running. The defenders, the blue team or SOC, are measured on whether and how fast they detect and contain it.

NIST defines a red team as a group authorised and organised to emulate a potential adversary’s attack or exploitation capabilities against an enterprise’s security posture. The emphasis is on emulation and posture: the question is not “which vulnerabilities exist” but “would we notice and stop an attacker”.

Where is it defined?

The most concrete definitions come from the financial sector. TIBER-EU, published by the European Central Bank, describes threat-intelligence-based ethical red teaming with its phases (preparation, testing, closure), its roles (white team, threat intelligence provider, red team provider) and its deliverables. DORA, Regulation (EU) 2022/2554, makes threat-led penetration testing mandatory for designated financial entities at least every three years (Article 26), and the technical standards for it build on TIBER-EU. MITRE ATT&CK is the shared vocabulary for the tactics and techniques that are used and detected.

Outside finance, NIS2 does not mention red teaming by name. Article 21(2)(f) asks for procedures to assess the effectiveness of the security measures, and a red team exercise does that better than any audit.

What it means in practice

A red team exercise pays off when you already have detection in place. Three observations from engagements:

  • It measures the SOC, not the firewall. The deliverable is a timeline: when the red team did what, what the blue team saw, how long until containment. If nobody is watching, the result is known in advance and a penetration test is the better use of the budget.
  • The objective shapes everything. “Reach the engineering network” leads to a very different exercise than “exfiltrate customer data”. Choose objectives from your own risk analysis, not from a template.
  • Rules of engagement are the safety net. Which systems are out of bounds, when to stop, how to deconflict with a real incident, who can abort. In OT environments the rules are strict: the red team shows that it could reach the controller, it does not write to it.

Zyberum runs red team exercises for IT environments and, with adapted rules, for production networks and vehicle fleets. Every exercise needs written authorisation from the management body, not just from the IT department.

Common misunderstandings

Red teaming is not a bigger penetration test. A pentest covers a scope broadly and reports all findings; a red team takes the one path that works and stays quiet. Doing a red team exercise before the first pentest wastes money: the team will walk in through a bug a pentest would have found in a day. It is also not purple teaming, where red and blue work together openly to tune detections; that is a useful follow-up, not the same thing.

FAQ

Frequently asked questions

How is red teaming different from a penetration test?

A penetration test covers a defined scope as completely as possible and reports every vulnerability; the defenders know it is happening. A red team exercise pursues one objective by any realistic path, stays covert and measures whether the organisation detects and stops the attack. The pentest finds bugs, the red team tests the response to an attacker.

When is my company ready for a red team exercise?

When you have had penetration tests, fixed the critical findings and run some form of detection, whether an internal team or a managed SOC. Without detection the outcome is known in advance. For a first engagement a penetration test, or a purple team exercise in which attackers and defenders work together, delivers more.

Is red teaming legal in Germany?

Yes, with written authorisation from the management body and clear rules of engagement. Phishing of employees, physical intrusion and the use of attack tools touch § 202a to § 202c StGB and labour law, so the authorisation, the exclusions and the handling of personal data have to be agreed before the first step.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab