Skip to main content
Working document · Print it and fill it in

Red Team Engagement
Scoping Template

A red team is defined by its objective and its rules of engagement, not by a service catalogue. A penetration test is scoped by an estate; a red team is scoped by a question and a register of what is authorised, and the estate is whatever the question happens to touch. This is the pack that gets you from the first to the second.

12
Sections in the pack
4
Objective archetypes
6
Regulatory instruments cited

Red Team Engagement Scoping Template

Enter your work email for the printable pack — the objective statement, the scenario register, the rules of engagement, the white cell and its communications plan, the detection log, the worksheet you issue, and the report contents gate.

By downloading, you agree to receive relevant communications. We respect your privacy.

What it settles

Six decisions, and each one constrains the next

That ordering is the reason the pack works and the reason an exercise scoped backwards does not. Settle the objective and the rest narrows; settle the systems first and the objective gets written afterwards, for the executive summary.

01

The objective, and the three others it is not

Whether detection works, how far an intruder gets from an assumed-breach position, whether one named business outcome can be achieved, and whether the response process holds end to end are four different exercises. They have different starting positions, different durations and different reports, and choosing between them is the decision that governs everything after it.

02

The scenario, and the evidence behind it

A generic kill chain describes every intrusion and predicts none. The scenario is derived from a relevant adversary’s actual behaviour — motive, capability, sector targeting — and the pack asks you to record the evidence, because the scenario is the first thing an auditor and a sceptical engineer each question.

03

Rules of engagement

The register that authorises and bounds: scope and explicit exclusions, permitted and prohibited techniques, data handling, production safety, and the escalation and stop conditions — including the one everybody omits, which is what happens when the exercise finds a genuine compromise that has nothing to do with it.

04

The white cell, and who is not told

A small named group positioned high enough in the escalation chain to halt the exercise, a deconfliction contact reachable at any hour, and a closed vocabulary for classifying an escalation — exercise activity, genuine incident, unresolved, compromised, halted.

05

What the defenders are measured on

Agreed before the window opens, or the measurement gets invented afterwards from whatever happened to be captured. Time to detect and time to contain are the outputs that a security programme can be managed against, and both need a log line and a synchronised clock behind them.

06

What the report has to contain

The attack path narrative including the paths that failed, the detection timeline set against each attack step, findings expressed as the control that permitted the step rather than as a host and a CVE, and recommendations a defender can put into a backlog on Monday.

Contents

Twelve sections, eleven of them things you fill in

It is a working document, not a guide. Section 1 is the only one with nothing to answer, because it is the boundary you read before answering anything. Section 10 detaches and goes to the provider; sections 11 and 12 are what you hold them to when the work returns.

1. What defines the exercise

The boundary, stated before anything is filled in: what a red team is scoped on, why the objective is written first, and what this pack deliberately does not contain.

2. Choosing the instrument

Red team, penetration test and purple team against the question each answers — one table, because buying the wrong one is the expensive mistake and it is made early.

3. The objective statement

Four worked archetypes, then the fields: the objective in one sentence, who asked it, the flags, and what a pass looks like for the defenders.

4. Threat scenario selection

Seven evidence tests, then a register — scenario, actor class and motive, the source and date of the evidence, the entry vector, and the flag it pursues.

5. Rules of engagement

Scope and exclusions with an owner and an authorisation reference per line, four groups of permissions and prohibitions, and seven escalation and stop conditions.

6. Authorisation

The authorising officer, board reference, legal review, code name, third-party authorisations and their expiry dates, and the provider qualification record.

7. The white cell

Who is briefed, on what date, and what each of them may say to whom — plus a vocabulary for classifying an escalation, and the communications plan.

8. Detection and response

One row per attack step: executed, first alert, detecting control, analyst action, contained. The rows with no alert are the detection engineering backlog.

9. The regulatory position

SEBI CSCRF, the RBI Directions 2026, CERT-In’s audit guidelines, DORA and TIBER-EU — with the paragraph number and the regulator’s own verb against each.

10. The scoping worksheet

The detachable page you issue: objective, scenario, estate, exclusions, window, starting position, success criteria, reporting format, retest terms, signature.

11. Report contents gate

Eleven report sections, what each has to contain, and two columns — is it in the statement of work, and did it arrive in the report.

12. Closure

The replay, the purple teaming exercise, the remediation owner, the restoration check, and the retest. All of it booked before the window opens.

Threat-led testing under regulation

Read the verb

Frameworks differ on whether they require an exercise or permit one, and the drafting is deliberate. Section 9 of the pack sets each instrument out with its paragraph number and the regulator’s own wording, so a sentence you lift into a board paper can be found in the original.

SEBI CSCRF

Shall DE.DP.S4, guideline 1

Regulated entities “shall conduct red teaming exercises as part of their cybersecurity framework on a half-yearly basis through use of red/ blue teams”, for MIIs and Qualified REs. Guideline 3 sets the condition that matters when you scope it: the red team “shall be independent of the function being tested”.

RBI Directions, 2026

May Paragraph 162

Permissive, in the regulator’s own verb: the bank “may conduct red teaming exercises to identify the vulnerabilities and the business risk, assess the efficacy of the defences and check the mitigating controls already in place by simulating the objectives and actions of an attacker.” Paragraph 151, immediately before it, requires VA at least once every six months and PT at least once in 12 months for critical information systems and those in the DMZ with a customer interface.

DORA

Shall Regulation (EU) 2022/2554, Article 26

Identified financial entities “shall carry out at least every 3 years advanced testing by means of TLPT”, and each test “shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions”. Article 27 sets the tester requirements the pack reprints as a procurement checklist.

TIBER-EU

Operational European Central Bank, January 2025

The framework the Article 26 technical standards were developed in accordance with, and the source of most of the process in this pack: an external threat intelligence provider, three or more intelligence-led scenarios, a minimum of 12 weeks of active testing, and a closure phase built on a replay and a purple teaming exercise. Adoption by an authority is voluntary, and it is a useful scoping reference either way.

Instruments and paragraph numbers were checked against the issuing authorities’ own text on the review date printed in the document. Several of these frameworks apply by entity class and by tier, so confirm which instrument names you before relying on a paragraph number.

What it is, and what it is not

A governance pack for the buyer, not a methodology

There are no techniques in it, no tooling and no attack methodology. Those belong in the provider’s test plan, which is written after the scope is fixed and which the same rules of engagement govern. Where a class of technique is named, it is named as a line an authorising officer ticks or strikes out.

It also names no provider. Every field, register and gate in it is one we would be content to be held to, and it is written to be filled in and issued to whoever you engage — which is the only reason a document like this is worth forwarding to a colleague.

Know the objective, but not the scenario?

Tell us the question the exercise has to answer and which instrument you are held to. The starting position and the duration follow from those two, and they are the fields that decide what the engagement costs.

Describe the exercise