Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Red team

Knowledge hub

Red team

A simulated adversary given a goal and left to reach it however they can.

What it means

A red team is a simulated adversary. You give them a goal, such as reaching a particular database or getting a payment approved, and they reach it however they can within agreed limits.

That includes routes a software test never takes: a convincing phone call, a door held open, a contractor's laptop. The exercise is about the whole organisation rather than one application.

Why it matters

The exercise answers a question no tool can. Would you notice? It measures detection and response: the people, the alerts, and the hour somebody takes to decide that this is really happening. CISA published findings from an assessment of an organisation with a mature security posture. The defenders did not detect the red team at all, including when the team deliberately tried to provoke a response.

It is expensive and occasional, so it works best once the obvious flaws have gone. Run against an application nobody has tested, it produces a report about the first open door.

How it shows up

You can see the difference in the report. A red team report reads as a story: they got in here, moved to there, and nobody raised a ticket for eleven days. An application test reads as a list of specific flaws with the requests that prove them.

Both are useful and neither replaces the other. Cyberlop is not a red team. It tests applications, repeatedly, and leaves the question of whether your alerting works to an exercise built for it. Agree the limits in writing, and decide in advance who inside the business is allowed to know.

Questions people ask

Red team, answered

What is the difference between a red team and a penetration test?

A penetration test looks for flaws in an agreed scope and lists them. A red team pursues a goal and tries not to be seen while doing it.

One produces findings. The other produces a narrative about your defences and the people running them.

What does a red team actually measure?

Detection and response, more than the existence of bugs. The CISA advisory is a good illustration: the technical entry points mattered less than the fact that nobody reacted.

If your answer to would we notice is probably, the exercise will tell you.

Are we ready for one?

If your applications have never been tested and your alerting is new, probably not. The exercise will stop at the first easy door and you will have paid for a conclusion you could have reached cheaper.

Fix the known ground first, then buy the question you cannot answer yourself.

Who inside the company should know?

A small group, named in writing, usually including somebody senior enough to stop the exercise. The defenders should not know, or you are measuring something else.

Somebody must be reachable at any hour, because a genuine incident can start in the middle of yours.

Will a red team test our application thoroughly?

No, and that is not a criticism of it. A red team takes the easiest route to the goal, so it stops looking at your application the moment a phone call works.

Systematic coverage of an application is a different exercise with a different report.

Not a red team, an application test

Cyberlop will not tell you whether your alerting works. It will tell you which requests your application should have refused, with the evidence attached. Talk to us about testing one.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.