ESSENTIAL GUIDANCE · COMPLETE GUIDE · 16 min read
Part of Adversary insights →Red teaming explained: when your organisation is ready and what an exercise proves
How red, purple and threat-led exercises differ, when to use them, how they are governed and how to measure defensive improvement.
How red, purple and threat-led exercises differ, when to use them, how they are governed and how to measure defensive improvement.
Need an acronym translated?Open the cyber glossary →Red teaming tests the whole defence
A red-teami exercise simulates a credible adversary pursuing an agreed objective. Instead of asking only whether a defined system contains vulnerabilities, it examines whether people, processes and technology prevent, detect and contain a realistic attack pathi. The objective might involve access to sensitive data, control of a critical identity or another carefully governed outcome. Success is not a dramatic breach narrative; it is reliable evidence about how the organisation responds under pressure.
Penetration tests and red teams are not interchangeable
A penetration test examines an agreed technical scope and seeks relevant weaknesses within it. A red team begins with an objective and may use multiple routes across technology, identity, people and physical controls where authorised. Penetration testing usually produces a vulnerability-led remediation plan. Red teaming produces an attack narrative, detection evidence and cross-team improvement backlog. If basic weaknesses remain unknown, a penetration test often provides better value first.
Red, purple and threat-led exercises
A covert red team measures how defenders perform without full prior knowledge. A purple teami makes collaboration explicit: operators and defenders work through techniques together, observe telemetry and improve detections. Threat-led penetration testingi uses intelligence about relevant actors to shape realistic scenarios and objectives under stronger governance. Frameworks such as TIBER-EUi and CBESTi define particular regulated approaches; alignment should not be confused with formal participation or regulatory recognition.
Readiness is an organisational question
Red teaming creates the most value when asset visibility, vulnerability management, monitoring and incident response already operate at a reasonable baseline. The organisation needs executive sponsorship, a trusted control group, capable defenders and a commitment to act on findings. A good readiness conversation asks what decision the exercise will support, whether the target objective matters and whether teams have the capacity to learn and remediate afterwards.
Threat intelligence creates realistic scenarios
Threat-led work connects important business services to adversaries that have the intent and capability to target them. Intelligence informs likely objectives, entry routes, tactics and operational patterns. It should create a defensible thread from the business service to the threat scenario and the testing activity. Generic imitation of famous attackers adds little if the techniques are unrelated to the organisation's sector, technology or risk.
Rules of engagement make realism safe
Objectives, boundaries, exclusions, communication, deconfliction, escalation routes and stop conditionsi must be agreed before activity begins. A small white celli or control group usually oversees the engagement on a need-to-know basis. Destructive actions should be excluded unless explicitly authorised, and production risk must be continually managed. Strong governance does not weaken the test; it makes realistic activity possible without transferring unacceptable risk to customers or critical services.
Measure detection and response, not theatre
Useful evidence includes which actions were prevented, detected or missed; alert quality; escalation; containment decisions; and the time taken to interpret each stage. Map activity to a recognised technique framework where appropriate, but do not confuse coverage counts with resilience. The important question is whether defenders recognised the attack path, understood its consequence and acted before the agreed objective was reached.
The exercise ends with improvement and replay
The output should include a controlled attack narrative, evidence, detection gaps, response observations and prioritised actions with owners. A collaborative replay can help defenders reproduce missed techniques and tune controls while the evidence is fresh. Repeat testing should focus on material improvements and changing threats rather than recreating the same performance. This turns the engagement into an improvement cycle instead of a one-off test.
How Pentesys Adversary is positioned
Pentesys Adversary supports proportionate threat-led penetration testing, purple teaming, red-team operations and TIBER-aligned exercises. The starting point is the resilience question, followed by an agreed level of realism, collaboration and governance. Scope, rules, evidence, technique coverage and the owned improvement backlog are retained in the Pentesys Portal, keeping Adversary connected to Expose intelligence, Validate findings and Foundation assurance.
This guide covers the essentials. Continue into our technical analysis for a firmer position, practical implications and recommended action.
Read “Internal security is defined by attack paths, not network boundaries” →



