Skip to content
Client access

Red Team

Red Team or pentest: which one your organization needs, and when

Both simulate attacks, but they answer different questions. How to choose between a penetration test and a Red Team exercise based on your organization’s maturity.

Kamaya Secure team 4 min read

When a board asks us to “hack us and see how secure we are,” that sentence almost always blends two different questions. The first is what weaknesses our systems have. The second is whether we would notice a real attack and stop it in time. A penetration test answers the first one well. A Red Team exercise is designed for the second.

Mixing them up is costly. A Red Team hired too early ends up finding the same basic flaws a pentest would have listed for less money, and a pentest hired when the organization already needs to measure its detection delivers an accurate report that does not answer the board’s question.

Key takeaways

  • Pentest: defined scope, focused on coverage. It looks for as many exploitable vulnerabilities as possible in a specific system.
  • Red Team: broad scope, focused on a mission. It emulates a specific adversary and measures prevention, detection and response across the organization.
  • Rule of thumb: if you do not yet have a vulnerability management process and working security monitoring, start with pentests. Once you do, a Red Team tells you whether they work.

What each one really is

Penetration test

A pentest assesses a defined scope —a web application, an API, a network segment, a cloud environment— over a limited period. The client’s security team knows the test is taking place and often provides access or credentials so testers can go further in less time. The result is a prioritized list of vulnerabilities with evidence, impact and remediation guidance, based on methodologies such as OWASP WSTG, PTES or OSSTMM.

The measure of success is coverage: how much of the scope was tested and how many real weaknesses were found.

Red Team exercise

A Red Team starts from a business objective —for example, “gain access to the payments platform” or “read the CEO’s email”— and emulates an adversary using the tactics, techniques and procedures (TTPs) a real attacker would use against your industry, mapped to MITRE ATT&CK. It may combine open-source reconnaissance, social engineering, exploitation of exposed services, lateral movement and persistence.

Only a small group inside the organization (the white team) knows the exercise is underway. The defense team works as on any other day. That way, beyond technical flaws, the exercise measures what a pentest cannot: how long it took the organization to detect the activity, whether it escalated correctly and whether it contained it.

Key differences

AspectPentestRed Team
Question it answersWhat vulnerabilities does this system have?Do we detect and stop a real adversary?
ScopeDefined and limitedBroad, driven by an objective
Defense team awarenessInformedWhite team only
StealthNot a priorityPart of the test
Typical durationDays to a few weeksSeveral weeks
Main outputPrioritized list of vulnerabilitiesAttack chain, detection times and response gaps
Required maturityLow to mediumMedium to high

When to start with a pentest

A pentest is the right starting point if any of these apply to your organization:

  • There is no reliable inventory of internet-facing assets.
  • The application or system about to launch, or the one that concentrates the most risk, has never been assessed.
  • There is no formal process to fix vulnerabilities and verify that the fix worked.
  • A regulator, a customer or an audit (for example, PCI-DSS or a third-party review) requires evidence of technical testing on a specific scope.
  • A major change is coming: a cloud migration, a new digital banking channel, an API integration with third parties.

In these cases, a Red Team would quickly find the same foundational weaknesses, and much of the budget would go into proving what was already known.

When to move to Red Team

A Red Team adds value once the organization has done the groundwork and needs to validate its defensive capability as a whole:

  • There is a monitoring service (in-house or outsourced SOC) and endpoint detection tools (EDR).
  • Periodic pentests no longer find critical issues in the main systems.
  • There is a documented incident response plan that has never been tested under real conditions.
  • The board or risk committee needs evidence that the investment in detection and response is working.

A good Red Team exercise is not measured by whether the team “got in.” It is measured by what the organization learns about its own ability to detect and respond.

A maturity path, not a one-time choice

In practice, both services coexist in an offensive security program that evolves with the organization:

  1. Per-system pentests to set a baseline and fix what is critical.
  2. Periodic and regression pentests after every relevant change, with retesting of fixes.
  3. Purple Team exercises, where attackers and defenders work together technique by technique to tune detection.
  4. Objective-driven Red Team to measure prevention, detection and response end to end.

What to ask for in the proposal

Whichever service you choose, a serious proposal should make clear:

  • Scope and objectives in writing, including what is explicitly out of scope.
  • Rules of engagement: schedules, permitted techniques, sensitive systems and how testing stops if something affects operations.
  • An immediate escalation channel if a critical vulnerability or evidence of a prior compromise is found.
  • Deliverables: an executive report for the board, a technical report with reproducible evidence and, for Red Team, a timeline of the attack compared with what the defense team detected.
  • Retesting of fixes, either included or clearly priced.
  • Team credentials (for example, OSCP or CRTP) and experience in your type of environment.

How we can help

At Kamaya Secure, the same team of certified pentesters in Lima delivers both services. If you are not sure where to start, we help you define the scope based on your current maturity before we quote. Learn more about our Penetration Testing and Red Team & Ethical Hacking services.

Insights

More insights

OT/ICS

IT/OT segmentation in mining: where to start

The convergence of corporate and industrial networks opens paths an attacker can exploit. A six-step roadmap to bring order with IEC 62443 without stopping operations.

Kamaya Secure logo on an office wall

Want to apply this in your organization?

Tell us where you are today. Our team will help you define the right scope and next steps, with no commitment.

Chat on WhatsApp (opens in a new tab)