Red Team or Penetration Test? Choosing the Right Engagement
The two are routinely confused during procurement. Here is how to decide which one answers the question your board is actually asking.
Procurement documents often request a “red team penetration test,” which is two different services with two different objectives. Buying the wrong one wastes budget and produces a report that does not answer the question leadership asked.
A penetration test measures exposure
A penetration test asks: what weaknesses exist in this defined set of assets, and how severe are they? Coverage is the priority. Testers work with knowledge of the environment, use the most efficient path to enumerate issues, and are not concerned with staying undetected.
Choose this when you need to know your vulnerability posture, satisfy a compliance requirement, or validate a new application before release.
A red team measures response
A red team exercise asks: if a capable adversary targeted us, would we notice and could we stop them? Coverage is deliberately sacrificed for realism. Operators pursue specific objectives — access to the payment switch, exfiltration of a customer database — while evading detection.
Choose this when your detection and response capability is already established and you want to test it under pressure. Running a red team against an organisation with no monitoring capability produces a predictable result and very little value.
The maturity sequence
The progression that works is straightforward. Start with penetration testing to reduce your exposure. Build detection engineering and response processes. Validate those with a purple team exercise where offensive and defensive teams work together transparently. Only then commission a full covert red team.
What about assumed breach?
Assumed breach engagements are an efficient middle option. The operator is granted an initial foothold, which removes the unpredictable perimeter phase, and the exercise focuses entirely on lateral movement, privilege escalation, and whether your team detects the activity. For most organisations this delivers the majority of red team value at a fraction of the duration.
A practical test for your own procurement
Ask what decision the report will inform. If the answer is “which vulnerabilities we should fix next quarter,” you want a penetration test. If it is “should we invest more in our security operations centre,” you want a red team.
More insights
What OJK POJK 11/2022 Actually Expects From Your Penetration Test
A practical breakdown of how Indonesian financial institutions can align penetration testing scope, frequency, and reporting with OJK expectations.
IT-OT Boundary Failures in Kalimantan's Energy Sector
Field notes from assessing operational technology environments across mining and power generation sites, and the four boundary weaknesses we find repeatedly.
UU PDP: Translating the Law Into Technical Controls
Indonesia's personal data protection law is written in obligations, not configurations. This is the control mapping we use with clients.