Penetration Testing vs Red Teaming: Choosing the Right Approach

When you’re assessing a building’s level of security, you’re not just looking at one thing. It’s great knowing that the front door has a series of unpickable locks bolted onto it, all of which have only one key in existence, but it’s not really going to do anything if you’re missing an entire external wall, essentially turning your living room into an open deck.

In other words, security checks are a multifaceted thing. You stroll the perimeter to check the fence, make sure the security lights and cameras are working, check the windows lock and that the front doors can’t be picked with a kit bought for $20 on Amazon. You’ll make sure any kids living inside know not to open the door to strangers no matter how insistently they knock. A security expert will look at even more elements, like possible hiding spots in the front yard or letterbox vulnerabilities.

The exact same thing needs to be said (and understood) for a business’s security. You can’t just look at your firewall and decide you’re safe – and, more so than in the previous example, you really will want a security expert’s keen eye to check on things regularly.

Two of the most effective techniques for testing security are penetration testing and red teaming, but a lot of business owners still don’t understand the differences (and different benefits) offered by the two.

What’s the difference?

Penetration testing is the process of using common (and, at times, more specialist) hacking techniques against your own company. A security team or agency will, within a predetermined timeframe, deploy a wide variety of approaches in an attempt to gain access to your private systems. The idea is to find as many potential vulnerabilities as possible. They will then utilise advanced penetration reporting tools to produce a clear, actionable assessment on your cybersecurity.

Team members within your company generally know when the tests are taking place, so penetration testing isn’t considered a ‘stealthy’ exercise. However, social engineering (such as sending fake phishing emails) is still part of the approach.

Red teaming, however, is a more targeted process. There’s a more specific objective, such as stealing data, and internal teams don’t tend to know when the test is taking place. The idea is to identify individuals’ abilities to detect attempts at accessing a company’s private systems, whether electronically or physically. Essentially, red teams emulate real-world threat actors who have a very specific goal and who will work incredibly hard to realise it.

Which is right for you?

In an ideal world, both.

Most enterprises begin with penetration testing, and get regular tests conducted at least every year. Remember: a penetration test report is only relevant to the company’s web apps, network segments, or APIs at that specific point in time. Things change, vulnerabilities can arise in seemingly mundane updates, and checks need to be done again and again in order to ensure you’re safe.

Red teaming is usually treated as a secondary measure once regular penetration testing is in place. First, with penetration testing, make sure that the foundations are solid and strong enough to hold what’s built on top of them; then, with red teaming, conduct your inspections on the above-ground detail.

Both tests look for different types of vulnerabilities, and you can’t afford to let either one slip.