Skip to main content

What a Red Team Engagement Costs

Quotes for the same objective can differ threefold. The objective itself is the largest lever, duration and access routes explain most of the rest, and the authorisation work is priced badly or not at all.

By Siddarth G
August 19, 2026 Last updated 6 min read

Ask three firms to price the same objective and the quotes can differ by a factor of three. Almost always they are describing different work, and the cheapest is describing the least.

Red teaming is quoted in team-weeks. That alone explains most of the gap with a penetration test: you are buying several people for several weeks, and much of that time is deliberately unhurried.

The objective is the largest lever, and it is set before anyone quotes

A red team is bought against an objective. "Reach the payment authorisation service", "obtain and use a domain administrator credential", "exfiltrate a file from the HR share without being blocked". Everything downstream is priced from that sentence.

Which means a vague objective is quoted as a guess, and the guess is padded. A brief that says "test our security" gives the firm no way to size the work, so it prices for the widest reasonable reading and you pay for the uncertainty. A brief naming one or two concrete objectives gets a narrower quote from everyone, and the quotes become comparable for the first time. Setting that objective is the subject of scoping a red team.

What moves the number

Duration

The largest driver after the objective, and the one most often cut to win a deal. A red team compressed into one week is a penetration test wearing the name: there is no time for patient reconnaissance, no time to wait out a detection, no time for a second route after the first fails.

Patience is the product. A quote that halves the duration is pricing a smaller exercise.

Team size and composition

A credible engagement needs more than one person: someone strong on initial access, someone on internal movement, someone who understands your platform, and an engagement lead. Some objectives need a specialist: an operational technology environment, a mainframe, a particular cloud. A specialist for two weeks is a line item, and a firm that has one is quoting differently from a firm that does not.

Which initial access routes are in scope

Each one adds cost, and the cheap quote is usually cheap because it includes only the first:

  • External only. The perimeter, exposed services, published credentials.
  • Phishing. Infrastructure, convincing pretexts, and the staff time to prepare them.
  • Physical. People on site, travel, reconnaissance, and real risk to the individuals involved. See physical penetration testing.
  • Voice and service desk. Pretexting your own helpdesk into a password reset. Often the single most effective route, and the one that raises the most sensitive questions about how results are reported. The consent position is in social engineering assessments and the consent they require.

How many environments

An objective inside one corporate network is one exercise. An objective requiring a route through a subsidiary, a supplier, or a separately administered cloud is several. Each additional environment also carries an authorisation cost, covered below, which buyers routinely discover after signing.

Whether detection is being measured

If the point includes what your defenders saw, the team must log every action against a timeline and produce that mapping. That is real analyst effort after the exercise ends, and it is the deliverable most worth paying for. What it produces is described in what the exercise tells you about detection.

The authorisation work, which is priced badly or not at all

Rules of engagement are legal work before they are technical work, and on a first engagement they take longer than buyers expect. Four things generate real effort:

  • Written authority for the physical element. Whoever walks into your building carries a letter naming who authorised it and who to call at three in the morning. Producing that letter means a conversation with the people who control the building.
  • Third-party consent. Testing a route that crosses into a cloud provider, a managed service provider or a supplier needs their agreement. That is your paperwork, on your timeline, and it is the single most common cause of a start date moving.
  • Stop conditions and the escalation path. Who can halt the exercise, on what signal, and how quickly they can be reached.
  • What happens to anything found in passing. A red team that stumbles on a live compromise stops being a red team that morning.

A proposal that does not price this is either absorbing it or has not thought about it. Ask which.

What does not move it much

The number of systems. Red teaming is not priced by asset count. That is penetration testing's unit. An objective inside a large estate and the same objective inside a small one cost similarly, because the work is reaching the objective, not covering the estate.

CERT-In empanelment. It does not change the scope of the work, and it is not a premium line. It decides whose report an Indian regulator or auditor will accept, so it belongs in the eligibility question at the start instead of the pricing conversation at the end. Empanelment attaches to the firm for a defined period, and the question a supervisor asks is whether the firm held it on the days the work was performed. Security Brigade has been CERT-In empanelled continuously since 2008.

What is frequently excluded

Three things sit outside the quoted number often enough to be worth naming in the request:

  • The retest. A red team ends with findings that take months to close, so a retest at the original scope is usually a separate engagement. Decide which you want before comparing prices.
  • Remediation support. Time with your engineers while they fix what was found. Cheap to add at the start and awkward to add later.
  • The joint debrief. Sometimes billed, sometimes assumed, and it is where most of the learning transfers.

Comparing quotes that are not comparable

Five questions make otherwise incomparable proposals line up:

  • How many team-weeks, and how many people? Convert everything to this. A "10-day red team" from one firm and a "4-week" from another may be the same money and very different exercises.
  • Which initial access routes are included? Named explicitly.
  • Is the detection timeline a deliverable? If not, half the value is missing.
  • Is a joint debrief with our defenders included? The most valuable hours are frequently the cheapest line item.
  • Who is actually on the team? Names and experience, not a capability statement.

What the finished report should contain is in what a red team report contains, and the wider provider question in choosing a red team provider.

Buying one because a regulator asked

Worth separating from the rest, because it changes what you should pay for. In the RBI's 2026 Directions red teaming is written as something a regulated entity may undertake, at paragraph 162 of the commercial banks instrument, and the equivalent provisions in the small finance banks, payments banks and credit information companies instruments use the same word. That makes a red team a risk decision and not a compliance line item, so buying the cheapest exercise that can be described as a red team achieves nothing at all. The paragraph-level reading is in red teaming under the RBI's 2026 Directions.

The honest sizing question

Before comparing anything, ask whether the exercise is the right purchase at all. If your last penetration test surfaced unpatched hosts and weak internal credentials, a red team will reach its objective through those and charge several times as much to tell you so.

The engagement is worth its price when hygiene is sound and the open question is whether anyone would notice. What that engagement involves is in what a red team assessment involves, and where a cheaper exercise serves you better is in purple team: when it beats a red team.

About the author

Siddarth G

Practice Director โ€” Cybersecurity

Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.