Short answer: A 14,500 Euro red team vs. blue team engagement for a 22-person software company is completely unnecessary and mismatched to your business scale. Those exercises are meant for massive enterprises running a 24/7 internal Security Operations Center; what you actually need at your size is a well-scoped, targeted penetration test and a cloud architecture audit.
Here is the breakdown: The red team tries to breach your organization unannounced like a real adversary, testing not just code vulnerabilities but physical office access and social engineering against staff. The blue team is your internal defense, tasked with detecting the intrusion in real-time logs, locking down systems, and kicking the attacker out. Running a defensive exercise without a dedicated in-house SOC monitoring your environment is like running goalkeeper drills without anyone on the pitch.
In an SME context, these concepts simply boil down to two practical steps. First, an annual penetration test by an external specialist focusing strictly on your web app and cloud API endpoints. Second, making sure your sysadmin centralizes logs, enforces MFA across the board, and periodically tests automated backup restores.
You can get a high-quality application and cloud pentest on the market for between 2,500 and 4,000 Euro. Allocating the remaining 10,000+ Euro to secure coding training for your devs or beefing up your logging infrastructure will do leagues more for your business than this kind of drill.