1. Home
  2. Insights
  3. Red teaming
Red teaming

Red teaming vs penetration testing: what is the difference?

The two terms get used interchangeably, usually by people selling one of them. They answer different questions, produce different outputs and are appropriate at different stages of maturity. Confusing them leads to engagements that are expensive and unsatisfying.

A penetration test is bounded and technical

A red team is goal-based and unbounded

The measurement is completely different

Red teaming tests people and process, which is uncomfortable

When each one is appropriate

Where the two meet: purple teaming

Questions to settle before you buy either

  • What is the objective, and who decided it?
  • What is explicitly out of scope — and why?
  • How will success be measured at the end?
  • Will social engineering or physical access be included?
  • How many people inside the organisation will know this is happening?
  • What are the rules of engagement for something genuinely dangerous?

Start with the gaps, not the shopping list.

Book a 30-minute review. We will look at what you have and tell you the three things worth doing first.

Book a security review