ESSENTIAL GUIDANCE · COMPARISON · 7 min read
Part of Adversary insights →Red teaming vs penetration testing
How the scope, objectives and outputs differ—and when each form of testing provides the clearest answer.
How the scope, objectives and outputs differ—and when each form of testing provides the clearest answer.
Need an acronym translated?Open the cyber glossary →Pen tests examine a defined scope
A penetration test seeks as many relevant weaknesses as practical within agreed systems. Its output is usually a prioritised technical remediation plan.
Red teams pursue an objective
A red teami uses a wider set of tactics to test whether an organisation can detect and stop a realistic attack. It examines the connections between people, process and technology.
Choose the question first
Use penetration testing to validate the security of defined assets. Use red teaming when you need to measure resilience against a realistic threat scenario.
This guide covers the essentials. Continue into our technical analysis for a firmer position, practical implications and recommended action.
Read “A testing methodology should protect rigour without constraining curiosity” →



