Skip to main content

The engagement

Red teaming is bought by the objective

A penetration test is scoped to an estate and succeeds by covering it. A red team is scoped to a goal and succeeds by reaching it, taking whichever route the rules of engagement leave open. That single difference decides the price, the duration and what the report can tell you.

The work is delivered by Security Brigade, CERT-In empanelled since 2008.

Where the requirement comes from

Three Indian instruments reach red teaming and each uses its own verb. The SEBI CSCRF requires red teaming half-yearly for Market Infrastructure Institutions and Qualified Regulated Entities, at standard DE.DP.S4. The RBI Directions, 2026 provide at paragraph 162 that a commercial bank may conduct red teaming exercises. CERT-In names Red Team Assessment among the engagement types that sit inside an annual ICT audit, in its audit policy guidelines CISG-2025-02.

Which verb applies to you decides whether this is a calendar obligation or a decision. The SEBI position and the RBI one are worked through clause by clause.

What the exercise reaches

In the order it happens, and every step bounded by the rules agreed before anything starts.

  • Reconnaissance against what your organisation publishes about itself, its people and its suppliers.
  • Social engineering by the routes the scenario permits: email, voice, and where separately authorised, the front desk.
  • Initial access by whichever of those routes opens first, which is rarely the one anybody predicted.
  • A foothold, then credentials, then movement toward the thing the objective names.
  • The objective itself, reached and evidenced so that the claim can be checked afterwards.
  • A route out, because an intruder who cannot remove anything has not finished the story.

It will find fewer vulnerabilities than a penetration test of the same scope. That is the exercise working as intended. A red team tests whether your detection and response hold up against somebody pursuing a goal, and it buys depth on one path instead of coverage across all of them. Where the question is coverage, buy the penetration test, and where the question is whether your team would notice, some organisations are better served by running the paths together.

Two units, and a proposal should give you both

A red team is quoted in team-weeks, because you are buying several people for several weeks and a good deal of that time is deliberately unhurried. The effort underneath is the same currency every other engagement is measured in: 25 to 60 tester-days for objective-based, multi-vector, several weeks of elapsed time.

Reporting sits inside that figure. Time on target is the variable that makes the access realistic, so the calendar window is longer than the effort, and the two numbers separate further here than on any other engagement type.

Ask for both on any proposal you receive, ours included. What moves the price goes through the rest.

The evidence you are buying

The attack path, including the parts that failed

Every route attempted, in order, with what stopped the ones that stopped. A path that failed is evidence a control worked, and it is the half most reports leave out.

A detection timeline against each step

What your team saw, when, and what they did about it. Set beside the attacker timeline, this is the answer to the question the exercise was bought to ask.

Findings written as the control that permitted the step

Not a host and a severity score. The thing that let an attacker move is a decision somebody can change, and naming it that way is what makes the report actionable to a defender.

A walkthrough with the people who have to act on it

Step by step with your detection and response team. Where that turns into working the paths together, it has become a purple team, and some organisations should buy that instead.

What the objective does to the size

  • The objective itself. "Reach the payments database" and "obtain domain administrator" are different exercises with different routes.
  • How many objectives. Each additional one adds vectors without reusing much of the path to the last, so the work compounds.
  • Where the exercise starts. An external start spends time getting in that an assumed-breach start spends going deeper.
  • Which routes are permitted. Ruling out a channel narrows the exercise; ruling out several narrows what its result can tell you.
  • Whether physical entry is in scope, which carries its own authorisation and its own people.
  • The white cell and the deconfliction load, which grows with the number of people who must not be told.

Before anything starts

The rules of engagement fix what is in scope, which routes are permitted and what ends the exercise early. A white cell holds the people who know it is happening, deconfliction gives your team a way to ask whether an alert is us, and a signed authorisation covers everybody doing the work. Social engineering against your own staff carries its own consent position, and CERT-In's guidelines require that general-staff testing be handled so that no individual is identified or penalised.

The scoping template sets out the fields to fix before a provider quotes, and the objectives and rules of engagement are worked through in full.

Name the objective

What somebody should not be able to reach, and who is not to be told the exercise is running. Those two answers shape everything else about the engagement.

Talk to our team