Red Team vs Blue Team: Which Does Your Organisation Need?
Most organisations asking for a red team need a penetration test, and some need neither yet. Matching the exercise to your actual detection maturity.
GuardsArm Team
Security Experts
"We want a red team engagement" is usually said by an organisation that needs a penetration test. The two get conflated in procurement, they cost very different amounts, and they answer different questions — and a red team against an organisation with no detection capability produces an expensive report stating that you did not notice.
What each actually is
| Penetration test | Red team | Purple team | |
|---|---|---|---|
| Question | What can be exploited? | Would we detect and respond? | How do we get better at detecting? |
| Scope | Defined systems | Objective-based (reach the EHR, exfiltrate records) | Specific techniques |
| Defenders informed? | Usually yes | No — that is the point | Yes, working alongside |
| Duration | Days to weeks | Weeks to months | Days |
| Output | Findings with severity | Narrative of the attack path and what was missed | Detection improvements, immediately |
| Cost | Lower | Highest | Moderate |
| Prerequisite | None | A functioning detection capability | Some detection capability |
Choose by maturity, honestly
The honest test: if you commissioned a red team tomorrow, would anyone see them? If the answer is clearly no, spend the money on detection first. You will learn more from a purple team exercise at a fraction of the cost.
For healthcare specifically
Red teaming a hospital carries constraints that do not apply elsewhere:
- No action may risk patient care. Clinical systems and medical devices are normally out of scope for active exploitation, or handled only in a test environment.
- Physical intrusion is plausible in an open building, and needs explicit written authorisation plus a named contact reachable at all hours.
- Social engineering against clinical staff must be designed so it cannot cause a clinical error — nothing that could alter treatment.
- An abort procedure is mandatory, known to both sides, and tested before the engagement starts.
These are not obstacles so much as the reason to use a provider who has worked in clinical environments before.
What a good engagement requires from you
Whichever you commission, these determine whether it produces value:
- A written objective. "Test our security" produces a generic result. "Determine whether an attacker starting from a phished clinical workstation can reach and exfiltrate records from the EHR" produces an answer.
- Rules of engagement signed before anything starts, covering scope, timing, prohibited actions and the abort procedure.
- A named point of contact reachable throughout, on both sides.
- Agreement on what happens if they find a real intrusion — it happens, and deciding mid-engagement wastes hours.
- Remediation capacity afterwards. A report nobody has time to act on is the most common waste in security testing.
That last point is worth planning for explicitly. Book the remediation time when you book the test.
Where to start
Answer the maturity question first. If you have no SOC coverage overnight — see build, buy or hybrid — then a red team is premature. A penetration test plus a purple team week will tell you more and cost less.
For scoping a test properly, the penetration testing RFP template covers the requirements that make bids comparable.
GuardsArm runs penetration tests, purple team exercises and red team engagements in clinical environments. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on “Red Team vs Blue Team: Which Does Your Organisation Need?”
Talk to the GuardsArm team about how these services apply to your environment.


