Pentest or Red Teaming? The Wrong First Question
"We need a pentest." – "We want a red teaming engagement."
That's how many inquiries I've seen over the past years begin. And almost as often, the first conversation reveals: the requested assessment doesn't actually match what the company wants to achieve. The type of assessment was chosen before the real question was answered – namely: What do you want to find out through this assessment – and what goal are you pursuing with it?
This isn't academic hair-splitting. Commission the wrong type of assessment and you either pay too much for insights you could have gotten far cheaper – or you receive a report that doesn't answer your most important questions at all.
A Short Series
That's why I'm starting a series on security assessments and how to choose the right one. Three more parts will follow over the next few days:
- Part 2 – The Map: Which types of assessments exist, what each one is designed to achieve – and which type fits which business goal
- Part 3 – The Maturity Staircase: Why the right type of assessment depends on your maturity level – and why elaborate assessments without basic hygiene are money down the drain
- Part 4 – Regulation & Motivation: What NIS2, CRA and DORA actually require – and why compliance is the minimum, not the goal
All the Same Thing? Not at All.
Pentest, red teaming, vulnerability scan, audit, assessment – in everyday conversation, these terms are often used interchangeably. Yet they describe very different types of assessments with very different objectives: a vulnerability scan answers a different question than a pentest, a pentest a different one than a red teaming engagement, and an audit a different one still.
So before talking about a specific assessment, you should ask yourself three questions:
- What do we want to know? Whether we're vulnerable? Whether we would detect an attack and respond to it? Or whether we meet specific requirements?
- Where do we stand today? Do we already have our fundamentals under control – patch management, hardening, access control concepts – or are we just getting started?
- What happens with the results? Who implements the findings, with what budget, in what timeframe?
Just how much the answers to these questions change the choice of assessment is illustrated by two examples from my project experience.
Two Anecdotes from the Field
The AD assessment that was no longer needed. A company commissioned an Active Directory assessment. After the project was completed, the colleague who conducted it said words to the effect of: "I could have written 90% of this report after the first interview, without ever seeing the system – because the conversation already made clear that no hardening of the AD infrastructure had ever taken place." Within the first few hours, he found more findings than could reasonably fit into a final report. The assessment wasn't worthless – but a fraction of the budget would have been enough to reach the same conclusion: harden first, then test.
The red teaming that had it too easy. In another project, the red team gained initial access through an outdated printer. And it didn't stop there: the network contained so many outdated and weakly configured systems that compromising the entire environment became a walk in the park. The catch: a vulnerability scan would have identified exactly these systems – at a fraction of the cost. So the red teaming engagement merely found the easiest path. Its actual strength – uncovering complex attack paths that automated scans cannot detect – never even came into play.
Both companies learned something. But both would have gained more for their security with a different – significantly cheaper – type of assessment: one with a hardening review and clear remediation measures, the other with a vulnerability scan and consistent patch and configuration management. A red teaming engagement would still have made sense afterwards – but then with real insight to gain.
The Right Assessment Beats the Expensive Assessment
That's what this series is about: not which type of assessment is the "best" – but which is the right one for your goal and your maturity level.
Choosing the right security assessment is a consulting service in itself. That's exactly where I support companies: in selecting the most effective measures – whether as part of a Secure Software Development Lifecycle (SSDLC) or in security consulting aimed at increasing resilience. If you're currently facing the question of which assessment you need: get in touch before you commission one – not after.
Soon in Part 2: The map of security assessments – which type of assessment pursues which goal, and which one fits yours.
