Red teaming
Red teaming vs penetration testing: what is the difference?
The two terms get used interchangeably, usually by people selling one of them. They answer different questions, produce different outputs and are appropriate at different stages of maturity. Confusing them leads to engagements that are expensive and unsatisfying.
A penetration test is bounded and technical
A red team is goal-based and unbounded
The measurement is completely different
Red teaming tests people and process, which is uncomfortable
When each one is appropriate
Where the two meet: purple teaming
Questions to settle before you buy either
- What is the objective, and who decided it?
- What is explicitly out of scope — and why?
- How will success be measured at the end?
- Will social engineering or physical access be included?
- How many people inside the organisation will know this is happening?
- What are the rules of engagement for something genuinely dangerous?
Start with the gaps, not the shopping list.
Book a 30-minute review. We will look at what you have and tell you the three things worth doing first.