Back to Blog
Security Testing
8 min read

Red Team vs Blue Team: Which Does Your Organisation Need?

Most organisations asking for a red team need a penetration test, and some need neither yet. Matching the exercise to your actual detection maturity.

GuardsArm Team

Security Experts

February 26, 2025

Red team and blue team

"We want a red team engagement" is usually said by an organisation that needs a penetration test. The two get conflated in procurement, they cost very different amounts, and they answer different questions — and a red team against an organisation with no detection capability produces an expensive report stating that you did not notice.

Different questions
Pen test: what is vulnerable. Red team: would we notice
Maturity-gated
Red teaming is wasted without something to detect it
Purple is often the answer
Collaborative, cheaper, and builds capability directly

What each actually is

Penetration testRed teamPurple team
QuestionWhat can be exploited?Would we detect and respond?How do we get better at detecting?
ScopeDefined systemsObjective-based (reach the EHR, exfiltrate records)Specific techniques
Defenders informed?Usually yesNo — that is the pointYes, working alongside
DurationDays to weeksWeeks to monthsDays
OutputFindings with severityNarrative of the attack path and what was missedDetection improvements, immediately
CostLowerHighestModerate
PrerequisiteNoneA functioning detection capabilitySome detection capability

Choose by maturity, honestly

Matching the exercise to detection maturityMatching the exercise to detection maturity1No detection capabilityStart hereVulnerability management and a penetration test. Nothing else will pay back.2Basic monitoring, few detectionsNextPenetration testing plus purple teaming to build detections on real technique.3Functioning SOC, tuned detectionsNow it is worth itRed teaming answers a question you cannot otherwise answer.4Mature, regularly red-teamedSustainContinuous or adversary-emulation programmes against specific threat actors.
Commissioning a red team from the first row buys a report you already knew the conclusion to.

The honest test: if you commissioned a red team tomorrow, would anyone see them? If the answer is clearly no, spend the money on detection first. You will learn more from a purple team exercise at a fraction of the cost.

Purple teaming is underrated
Running a known technique with the defenders watching, checking whether the alert fires, and fixing it if it does not — repeated across a dozen techniques in a week — improves detection faster than any other exercise, and it leaves capability behind rather than a report.

For healthcare specifically

Red teaming a hospital carries constraints that do not apply elsewhere:

  • No action may risk patient care. Clinical systems and medical devices are normally out of scope for active exploitation, or handled only in a test environment.
  • Physical intrusion is plausible in an open building, and needs explicit written authorisation plus a named contact reachable at all hours.
  • Social engineering against clinical staff must be designed so it cannot cause a clinical error — nothing that could alter treatment.
  • An abort procedure is mandatory, known to both sides, and tested before the engagement starts.

These are not obstacles so much as the reason to use a provider who has worked in clinical environments before.


What a good engagement requires from you

Whichever you commission, these determine whether it produces value:

  • A written objective. "Test our security" produces a generic result. "Determine whether an attacker starting from a phished clinical workstation can reach and exfiltrate records from the EHR" produces an answer.
  • Rules of engagement signed before anything starts, covering scope, timing, prohibited actions and the abort procedure.
  • A named point of contact reachable throughout, on both sides.
  • Agreement on what happens if they find a real intrusion — it happens, and deciding mid-engagement wastes hours.
  • Remediation capacity afterwards. A report nobody has time to act on is the most common waste in security testing.

That last point is worth planning for explicitly. Book the remediation time when you book the test.


Where to start

Answer the maturity question first. If you have no SOC coverage overnight — see build, buy or hybrid — then a red team is premature. A penetration test plus a purple team week will tell you more and cost less.

For scoping a test properly, the penetration testing RFP template covers the requirements that make bids comparable.

GuardsArm runs penetration tests, purple team exercises and red team engagements in clinical environments. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on “Red Team vs Blue Team: Which Does Your Organisation Need?”

Talk to the GuardsArm team about how these services apply to your environment.