
A penetration test is a scoped, time-limited attempt to find and exploit weaknesses in specific systems, so you learn which holes exist and how far each one leads. A red team exercise simulates a real adversary pursuing a goal, usually over a longer period and often with phishing or phone calls in play, to test whether your people and tools notice and stop the attack. A penetration test finds the holes; a red team tests the defenders, and most small businesses need the first long before the second.
Our penetration testing service starts with a free remote external test within an agreed scope. If you are still deciding between testing and scanning, our comparison of penetration testing and vulnerability scanning covers that earlier step.
What is the difference between a red team and a penetration test?
NIST puts both in the same control family. In NIST SP 800-53 Revision 5, control CA-8 describes penetration testing as a specialized assessment that goes beyond automated vulnerability scanning to validate vulnerabilities or measure how well systems resist attack, within set limits of time, resources and skill. Enhancement CA-8(2) says red team exercises extend those objectives to the organization's ability to defend itself, simulating attempts to compromise its mission and business functions with technical attacks and social engineering. NIST adds that penetration testing may be largely laboratory-based, while red team exercises reflect real-world conditions.
| Penetration test | Red team exercise | |
|---|---|---|
| Goal | Find and prove exploitable weaknesses in a defined scope | Test whether the organization detects and responds to a realistic attack |
| Scope | Specific networks, applications or systems agreed in writing | The organization as a whole, aimed at an objective such as reaching finance data |
| Who knows it is happening | IT coordinates it under agreed rules of engagement | A small group; defenders are often not told, so they respond as they would for real |
| Methods | Technical testing within the rules of engagement | Technical attacks plus social engineering by email, phone or in person |
| Length | Bounded by the scope and the agreed testing window | Longer campaigns; one CISA assessment of a federal agency ran about eight months |
| What you get | Findings with severity, evidence and the specific fix | The attack path, what defenders saw or missed, and gaps in detection and response |
| What it measures | How resistant your systems are | How well your monitoring, people and response work together |
| Prerequisites | Written authorization and a defined scope | Working monitoring and response, and earlier test findings already fixed |
| NIST SP 800-53 control | CA-8, Penetration Testing | CA-8(2), Red Team Exercises |
What does a penetration test tell you?
Which weaknesses an attacker could actually use and what each one leads to. NIST describes the usual method: analysis of the system before testing, identification of likely vulnerabilities, then testing designed to see whether they can be exploited, with all parties agreeing the rules of engagement first. The result is evidence rather than a scanner's guess, and it ends with a ranked list of fixes.
Buyers usually compare four kinds of penetration test: external network tests from the internet, internal network tests from a foothold inside, web application tests, and social engineering tests such as phishing. Each answers a narrower question than a red team does. None of them tells you whether your monitoring would have noticed the attack, because the defenders usually know a test is under way.
What does a red team exercise tell you?
Whether your defense works when nobody warns it. CISA's advisory AA24-193A, published July 11, 2024, describes a red team assessment of a federal civilian agency that ran about eight months and began as a no-notice, long-term simulation of nation-state operations. The team got in through an unpatched web server and through phishing, then reached full domain compromise.
The findings were about defense, not just vulnerabilities. The red team went undetected throughout the first phase. Endpoint detection tools quarantined several of its tools, including the first phishing payload, but daily procedures did not always include reviewing those alerts. Logs were not collected, kept and analyzed well enough, and defenders looking for known indicators missed other attacker behavior. A later phase had the red team work with the defenders to improve detection and hunting. A penetration test could have found the unpatched server; the red team also showed that alerts were going unread.
Which comes first: a penetration test or a red team?
The penetration test. A red team run against an environment with known, unfixed weaknesses and no one watching alerts is likely to succeed, and it will teach you what a scan and a scoped test would have shown for far less money. A sensible order is:
- Scan and patch continuously so known vulnerabilities do not pile up.
- Penetration test what you expose, starting from the internet, and fix what it finds.
- Put monitoring and response in place, in-house or through managed detection and response, with an incident response plan people have rehearsed.
- Then red team, to test whether the people and tools in step three catch a determined attacker.
Which fits a small team?
Almost always a penetration test, scoped to what you actually expose. For a typical small business that means an external test first, then a web application test if customers use software you built, and an internal assessment if a phished laptop could reach your file server and backups. Phishing simulations answer the social engineering question without a full red team.
A red team starts to make sense when you have a monitoring and response function, your test findings are closed, and a board, customer or regulator wants to know how you would fare against a real adversary. Until then, a tabletop exercise is a cheaper way to test response decisions: leadership walks through a realistic scenario, such as ransomware or a hijacked mailbox, and finds the gaps on paper.
What drives the cost and effort of each?
We publish no rate card. The same factors move both kinds of quote:
- Scope. The number of addresses, applications, sites and user groups in play.
- Test type and depth. External, internal, web application or social engineering, and whether testers get credentials or roles inside the application.
- Duration and team. A red team's longer campaign and experienced operators make it the larger engagement.
- Rules of engagement. Physical access attempts, phone pretexting and production testing all add planning and safeguards.
- Reporting and retesting. Whether fixes are retested, and how detailed the report must be for a customer or auditor.
- Your own time. Coordinating the test, then fixing what it finds.
Our guide to penetration testing cost breaks down what drives a quote and how to compare two of them.
How does NetSys help with penetration testing?
Our testing work is built around penetration tests in two tiers. Tier 1 is a free remote external penetration test, limited to the information available to us and the external scope we agree with you in writing. Tier 2 tests an application and its source code in an isolated NetSys sandbox, with findings, reproduction steps, fixes and a retest, quoted per codebase. Internal and on-site work is scoped separately as an internal security assessment, and phishing is measured through simulated campaigns in our security awareness training.
Testing is AI-driven, and an engineer verifies every finding before it reaches the report. Findings are ranked by real-world risk, each with what we found, what an attacker could do with it and the step that closes it, and the report is yours whether or not you hire us for the fixes.
Book a call with a NetSys engineer to agree the scope of a first external test and decide which kind of testing should follow it.
Frequently asked questions
What is the difference between red teaming and penetration testing?
A penetration test finds and proves exploitable weaknesses in a defined scope, usually with IT aware of the test. A red team simulates a real adversary pursuing an objective, often without warning the defenders, to test detection and response. NIST treats red team exercises as an extension of penetration testing, in control CA-8(2).
Is a red team better than a penetration test?
Neither is better; they answer different questions. A red team is only useful once the basics are in place, because an environment with known holes and unread alerts will fail it for reasons a cheaper test would already have shown.
Which fits a small team?
A penetration test, starting with your external exposure, plus phishing simulations for staff. Consider a red team after you have monitoring and response in place and have fixed earlier test findings.
What affects the cost, implementation and support?
Scope, test type and depth, duration, the rules of engagement and retesting. Support after the test is the work of fixing findings and confirming the fixes, which is where most of the value is realized.
Does a red team use social engineering?
Often. NIST's description of red team exercises includes social engineering by email, telephone, shoulder surfing and personal conversation, alongside technical attacks. Any such activity should be written into the rules of engagement before the exercise starts.
How often should a small business run a penetration test?
After anything that changes your attack surface, such as a new office, a network rebuild, a migration or a major application release, and on a regular cadence after that; many businesses under customer or insurer scrutiny test their external systems once a year. Some rules set a minimum: CMMC Level 3, under 32 CFR Part 170, requires penetration testing at least annually.
Related reading
CybersecurityPenetration Testing vs. Vulnerability Scanning for SMBs
Read Article
Cost GuidesHow Much Does Penetration Testing Cost?
Read Article
CybersecurityCyber Attack Response Plan for Small Business: 6 Steps
Read ArticleAlso on this topic: Penetration Testing Tools: The Main Types, and How AI Changes a Test
Discuss penetration testing for your business.
Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.
