Red teaming
A comprehensive exercise that imitates a real attacker's goals and methods to test not only an organisation's weaknesses but also its ability to notice and respond to an attack.
- 01
Why it matters
A penetration test finds flaws in specific systems; red teaming answers the question “can the data be reached, and if so, will anyone notice?” Social engineering, physical access and technical attacks can be combined. It makes sense for mature security programmes; if the basics are missing, they come first.
- 02
Example
The red team's objective is to extract a sample record from the customer database. The team enters the VPN with an employee's leaked password and reaches the target in two weeks, while the security team notices only one alert on the last day. The report focuses mainly on detection gaps.
- 03
Common mistake
Treating red teaming as a win-or-lose game. The goal is not to beat the defenders but to find and close gaps; results should be reviewed together with the defence team.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.