Skip to content
StrikeCyberStrikeCyber
Research

How to Run a Successful Red Team Engagement - Lessons from the Front Lines

11 January 2025·5 min readRed Teaming

A red team engagement is not a bigger penetration test. It is a goal-oriented, threat-led exercise that emulates a real adversary across technical, physical and human attack surfaces to answer one question: if a capable attacker targeted us, would we detect them, and could we stop them before they reached what matters. Done well, red teaming gives Australian boards and security leaders an honest picture of their resilience. Done poorly, it produces an expensive report that gathers dust.

The 2026 threat landscape makes this exercise more valuable than ever. Adversaries now use AI to accelerate reconnaissance and craft convincing social engineering, ransomware-as-a-service crews industrialise intrusion, and identity-based attacks let criminals log in rather than break in. This guide walks through how to run a red team engagement that delivers measurable improvement, drawing on hard lessons from the front lines.

Start With Clear Objectives, Not Just Scope

The single biggest predictor of a valuable red team engagement is a well-defined objective. Coverage-based thinking belongs to penetration testing. Red teaming is about specific, business-relevant goals that map to what would genuinely hurt your organisation.

Strong objectives are concrete and measurable, for example:

  • Reach and demonstrate access to a defined crown-jewel dataset or application
  • Achieve domain admin or equivalent control over a critical environment
  • Exfiltrate a marked, harmless test file without triggering data loss prevention
  • Test whether the security operations team detects and responds within its own stated timeframes

Frame objectives around risk owners and business impact rather than technical trophies. When the goal is "prove we can reach the customer payments platform", every finding along the way has clear meaning for the people who carry that risk.

Define Threat-Led Scenarios

Generic testing produces generic results. A threat-led scenario grounds the engagement in the adversaries who realistically target your sector, whether that is financially motivated ransomware operators, opportunistic criminals or, for critical infrastructure, more capable state-aligned actors.

Build scenarios from real threat intelligence and recognised frameworks so the tactics, techniques and procedures reflect genuine adversary behaviour rather than a tester's habits. A useful scenario states:

  • Who the emulated adversary is and what motivates them
  • How they would plausibly gain initial access, such as phishing, exposed services or a compromised supplier
  • What they are trying to achieve, tied to your objectives
  • Which behaviours are in and out of scope, such as destructive actions or ransomware detonation

This approach keeps the exercise realistic and defensible, and it produces findings your team can act on because they mirror attacks you will actually face.

Set Rules of Engagement That Protect the Business

Rules of engagement (ROE) are the contract that lets a red team operate aggressively without harming the organisation. Getting them right is what separates a controlled, professional exercise from an incident.

Good ROE documents cover:

  • Scope boundaries, including systems, networks and locations that are strictly off-limits
  • Permitted techniques, such as phishing or physical entry, and any that are prohibited
  • Data handling rules, so real sensitive data is never removed or exposed
  • Timing windows, escalation triggers and emergency stop procedures
  • Named points of contact on both sides who can pause the exercise at any time
  • Legal authorisation and get-out-of-jail documentation for physical and social engineering work

Agree ROE in writing before anything begins, and make sure the people authorising the work understand what they are approving. Clear ROE is what allows testers to be realistic while the business stays safe.

Scope for Realism, Then Manage Communication

Scoping decides how faithful the engagement will be. Decide early whether the security operations team knows the exercise is running. A "black box" run where defenders are unaware gives the most honest read on detection, while a more open run trades some realism for faster learning.

Whatever you choose, run a tight communication line throughout. A small trusted control group on the client side should have visibility of progress so that any genuine security event can be told apart from red team activity, and so the exercise can be paused if it risks real disruption. Regular checkpoints prevent surprises and keep leadership informed without tipping off the broader defensive team.

If your organisation is early in its testing maturity, it often makes sense to build up through penetration testing first, then progress to full red team engagements and broader adversary simulation once foundational controls are in place.

Execute Like a Real Adversary

Execution should follow the arc of a genuine intrusion rather than a checklist. A typical engagement moves through reconnaissance, initial access, establishing a foothold, privilege escalation, lateral movement, persistence and finally action on objectives.

Two principles matter most during execution. First, stealth is part of the test: the value is in learning what your monitoring and endpoint detection actually catch, so testers should work quietly and record every action with timestamps for later comparison. Second, discipline over opportunism: it is tempting to chase every weakness found along the way, but a focused team keeps driving towards the agreed objectives, which is what makes the results meaningful to risk owners.

Turn It Into Purple Teaming

The engagement is only half the value. The other half is the collaboration afterwards, and increasingly during, the exercise. Purple teaming brings the offensive (red) and defensive (blue) sides together to compare the attacker timeline against the defender timeline, action by action.

This is where organisations improve fastest:

  • Replay each attacker action and confirm whether it generated a log, an alert or a response
  • Identify blind spots where activity was invisible, and tune detection rules to close them
  • Rehearse the response so playbooks are validated under realistic conditions, not just written down
  • Re-test specific techniques immediately to confirm the new detections work

Purple teaming converts a point-in-time result into lasting capability, and it builds a working relationship between attack and defence that pays off in a real incident.

Measure the Value

A red team engagement should produce evidence, not just anecdotes. Report against outcomes leadership can understand and track over time:

  • Time to detect and time to respond for key attacker actions
  • How far the team progressed towards each objective before being contained, if at all
  • Specific detection and response gaps, each with a prioritised, owned remediation action
  • A clear read on maturity against the ASD Essential Eight, with attention to application control, privileged access and monitoring

For entities regulated under APRA CPS 234 or captured by the SOCI Act, this evidence also supports assurance obligations and board reporting. Follow the same rhythm the ACSC recommends more broadly: test, remediate and re-test on a regular cadence, because environments and adversaries never stand still.

Running a successful red team engagement takes clear objectives, honest scoping, disciplined execution and genuine collaboration afterwards. When those come together, the exercise stops being a compliance line item and becomes one of the sharpest tools you have for building real resilience. If you want a threat-led red team engagement scoped around the way your organisation is genuinely attacked, StrikeCyber runs them for businesses across Australia from our Brisbane base. Call 1300 654 898 or get in touch to start the conversation.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation