Red team vs pentest
A pentest aims to find as many vulnerabilities as possible in a defined scope, usually in days or weeks, and the defenders often know it is happening. A red team exercise has a specific objective, such as reaching sensitive data, uses any realistic technique including phishing and physical access, and is usually unannounced so that detection and response can be tested.
Blue team and purple team
The blue team is the defenders, such as the SOC. In a purple team exercise, red and blue work together openly: the red team runs techniques step by step and the blue team checks whether each one is detected, improving detection as they go.
Who needs it
Red teaming is most useful for organisations that already have solid basic controls and monitoring in place. For companies earlier in their security journey, pentesting and attack surface management usually bring more value first.
Regulatory context
Under DORA, some financial entities must carry out threat led penetration testing (TLPT), a form of red teaming based on the TIBER-EU framework.




