Security-exercise buyer guide

Penetration test, threat-led test, purple team or red team?

Compare penetration testing, threat-led penetration testing, purple teaming and red teaming by objective, realism, collaboration, governance and readiness.

Compare the approaches

Similar category.
Different job.

Each route can be appropriate. The useful comparison is what it is designed to prove, the work your team must own and what happens after something is found.

01
FIND WEAKNESSES

Penetration test

Investigates an agreed technical scope for exploitable weaknesses, business-logic flaws and attack paths.

Best when
Applications, infrastructure and defined assurance requirements.
Watch for
It does not normally measure organisation-wide detection and response.
02
TEST RELEVANT TECHNIQUES

Threat-led test

Uses the tactics and techniques of relevant threat actors to shape a controlled technical assessment.

Best when
Organisations that need a more realistic but still bounded test.
Watch for
Threat relevance and scope assumptions should be documented rather than implied.
03
IMPROVE DETECTION

Purple team

Attackers and defenders work together technique by technique to validate and tune defensive coverage.

Best when
Security teams focused on detection engineering and knowledge transfer.
Watch for
Collaboration improves learning but does not measure covert detection in the same way as red teaming.
04
MEASURE RESILIENCE

Red team

A covert, objective-led operation tests whether the wider organisation can prevent, detect and respond to a credible adversary.

Best when
Mature organisations with a defensible baseline and a clear resilience question.
Watch for
It requires stronger governance, deconfliction and operational readiness.

Questions before procurement

Four questions that narrow the choice.

Answer these before comparing suppliers or prices. They expose where ownership, evidence and expectations are still unclear.

Speak to us
  1. 01

    Are we trying to find weaknesses or measure a defence capability?

    Choose a penetration test for the former and a collaborative or covert exercise for the latter.

  2. 02

    Do we have a functioning detection and response team to test?

    If not, establish the technical baseline before investing in a full red-team operation.

  3. 03

    Would collaboration or secrecy produce the more useful evidence?

    Purple teaming maximises learning; red teaming measures performance under controlled uncertainty.

  4. 04

    Who will govern safety and make rapid decisions?

    Complex exercises need a named white cell, deconfliction, exclusions, stop conditions and escalation routes.

Side-by-side view

Compare what changes in practice.

The descriptions are category-level guidance, not claims about every provider. Confirm the precise scope, people, technology, evidence and exclusions before appointing anyone.

Decision factorPenetration testThreat-led testPurple teamRed team
Primary questionWhat is exploitable?Can relevant techniques work?Can we improve detection?Can an adversary reach the objective?
ScopeDefined technical systemsDefined and threat informedSelected techniques and controlsObjective led across agreed attack surfaces
Defender awarenessUsually knownUsually knownCollaborativeRestricted to the white cell
Operational realismModerateModerate to highControlled and transparentHighest within agreed safety limits
Detection improvementSecondaryCan be reviewedCore outcomeMeasured through observed response
Governance burdenStandard rules of engagementEnhanced threat and scope controlWorkshop and evidence coordinationWhite cell, deconfliction and escalation
Baseline maturitySuitable at most maturity levelsEstablished technical baselineActive defensive capabilityMature prevention, detection and response
Typical outputFindings and remediationThreat-relevant attack pathsDetection gaps and tuned controlsObjective evidence and resilience improvements

Our suggestion

Use a penetration test to find exploitable weaknesses in a defined technical scope. Use a threat-led test when relevant attacker techniques should shape that scope. Use purple teaming to improve detections collaboratively. Use red teaming when a mature organisation needs to measure whether people, processes and technology can stop a covert attacker reaching an agreed objective.

Where Pentesys fits

Feel like you need some help?

Pentesys selects the least complex exercise that can answer the resilience question. Scope, rules of engagement, evidence, technique coverage and the resulting improvement backlog remain connected through the Pentesys Portal.

  • 01Objective-led scoping
  • 02Threat-informed techniques
  • 03Explicit safety and governance
  • 04Detection and improvement evidence

FAQ

Common Questions

Should every organisation commission a red team?

No. Red teaming is most useful when a reasonable security baseline and detection capability already exist. A penetration test may produce more immediate value where fundamental technical weaknesses are still unknown.

Is purple teaming easier than red teaming?

It is different rather than simply easier. Purple teaming reduces secrecy to accelerate learning, while red teaming preserves controlled uncertainty to measure real detection and response.

Where does TIBER fit?

TIBER-aligned work adds a formal intelligence-led and governance framework for relevant organisations. It is not merely a larger red team and should be scoped with the appropriate regulatory and internal stakeholders.

Trusted experience

Supporting recognised organisations.

Royal Ballet and Opera logo
Royal Ballet and Opera
Rightmove logo
Rightmove
Fortis logo
Fortis
Orange logo
Orange
Small Luxury Hotels of the World logo
Small Luxury Hotels of the World
AI Incumbency logo
AI Incumbency
Pentesys has continuously performed admirably during our collaboration, giving us faith in their knowledge. They delivered work that above our expectations by approaching each project with a deep understanding of our specifications. Their team demonstrated a remarkable degree of proficiency by effectively pinpointing weaknesses and offering practical suggestions to reduce possible hazards.
MDFortis Cyber Security Limited
Unlike previous pentests that produced generic outputs, this engagement gave us clear, prioritised actions with real-world attack scenarios. The platform visibility into assets, vulnerabilities and remediation progress has helped us mature our security posture significantly. The team were professional, responsive, and genuinely cared about improving our security rather than just ticking a box.
Head of ITHealthcare Technology Company
The red team and external attack surface management work highlighted blind spots we didn't know existed. What stood out was the strategic guidance alongside the technical delivery – helping us shape a longer-term security roadmap rather than a one-off engagement. This felt like a partnership, not just a transactional assessment.
CISOSaaS Provider
Pentesys has continuously produced excellent work. Their group demonstrated extraordinary technical proficiency by spotting crucial flaws and offering clever fixes that greatly strengthened our security stance. Their meticulous approach and attention to detail ensured that every facet of the project was covered in full.
IT Security SpecialistRightmove PLC
We engaged Pentesys and the team for a complex penetration test and adversary simulation. The quality of the technical findings, realism of the attack paths, and clarity of reporting were outstanding. The recommendations were practical and mapped clearly to business risk, which made board-level conversations much easier. We've since built Pentesys into our ongoing security assurance programme.
CTOUK Financial Services Provider

Assurance that joins up

Recognised expertise, built around your environment.

Pentesys combines independent assurance, qualified testers and practical integration with the systems your teams already use.

The next useful step

Choose the smallest scope that answers the question.

Tell us what you need to prove, what has already been tested and what your stakeholders expect. We’ll recommend a proportionate route.

Design a realistic attack exercise