Red team assessment: detection and response under realistic load
A red team assessment is a goal-based, multi-week attack simulation against the entire detection and response chain, not against a narrow scope. The output is not a vulnerability list but an evidence-backed statement about what SOC, EDR, identity and cloud controls stop together. ANOMAL runs red team engagements using MITRE ATT&CK with a methodology based on TIBER-EU. For systemically important institutions, FINMA considers red-teaming exercises a required part of cyber exercises (supervisory notice 03/2024) and names frameworks such as TIBER-EU and CBEST.
What a red team is and is not
A red team attacks specific objectives. It asks whether an attacker can reach objective Y within X weeks without the SOC stopping them. Objectives include payment initiation, crown-jewel data and domain admin access. The team chooses the scope and attack paths, mirroring a real attacker. This distinguishes the exercise from a pentest, which checks whether systems within a defined scope are exploitable.
Unlike a pentest, a red team also evaluates analysts' responses, playbooks, escalation paths and communication with executive leadership. Endpoint or cloud findings form part of this wider assessment. For a comparison, see [Penetration testing Switzerland](/en/services/penetration-testing-switzerland).
Engagement types
| Type | Objective | When it fits |
|---|---|---|
| Full red team | No blue-team foreknowledge, realistic attacker, goal-based. | When the claim 'our SOC catches attacks' needs hard evidence. |
| Assumed breach | Attack starts from a compromised endpoint or account. | When lateral movement and detection matter more than initial access. |
| Purple team | Red and blue collaborate openly and tune detection rules live. | After a full red team, to convert findings into rules. |
| TIBER-EU-oriented exercise | Threat-intelligence-led, regulator-ready report, methodology based on TIBER-EU. | Regulated financial institutions with FINMA / DORA expectations. For systemically important institutions, FINMA considers red-teaming exercises a required part of cyber exercises (supervisory notice 03/2024) and names frameworks such as TIBER-EU and CBEST. |
How an ANOMAL red team engagement runs
- Objective workshop with executive leadership: which assets constitute 'winning', what rules apply (time windows, blackout, communication).
- Threat-intelligence build-up: which attacker profiles are realistic for the sector, which TTPs (MITRE ATT&CK) will be used.
- Operational phase over several weeks: initial access, persistence, lateral movement, objective achievement, continuous OpSec.
- Controlled white-cell channel: a small named group knows about the exercise and stops it if real risks arise; everyone else treats events as real.
- Reporting: executive summary with objective outcome, attack timeline, detection gaps, concrete rule and process recommendations.
- Optional purple team phase: convert observed paths into detection rules and anchor them in the SOC.
If the team discovers a real compromise during the exercise, it follows the same process as for a real incident. See Incident Response 72h. The team pauses or aborts the exercise in that case.
How this compares to pentest, bug bounty and tabletop
| Activity | Question | What it does not cover |
|---|---|---|
| Pentest | Is scope X exploitable? | Statement on SOC reaction and playbook effectiveness. |
| Bug bounty | What do external researchers find on publicly exposed assets? | Systematic attack chains, targeted objective achievement, detection evaluation. |
| Red team | How far does a realistic attacker get before we stop them? | Broad compliance evidence (use audit or certification for this). |
| Tabletop | How does the organisation react to a planned scenario? | Technical reality of the attack chain, real detection latencies. |
A red team replaces neither pentest nor SOC. It is the maturity exercise once both are in place. Without an established SOC with detection content the yield is low because almost everything gets flagged. Detection latencies across the SOC chain (see MTTD and MTTR in a SOC) are the actual yardstick. For the broader framework, see SOC as a Service Switzerland.
Frequently asked questions
When does a red team make sense?
A red team makes sense once a SOC has run for at least six to twelve months. The organisation should have established detection content and a standard pentest cycle. Before that, the exercise yields little because basic gaps limit the findings' value.
How long does a red team engagement take?
An engagement typically involves four to eight weeks of operations, plus two weeks of preparation and two weeks of reporting. Shorter formats are possible but lose realism because OpSec and persistence take time.
Who in our organisation may know about it?
A small white cell knows about the exercise, typically two to four people including the CISO and sponsor. Everyone else, SOC analysts included, treats events as real. Only that makes the reaction meaningful.
Does a red team satisfy cyber-insurance requirements?
A red team cannot replace baseline controls. Insurers recognise a red team report as strong evidence of maturity, and it often reduces premiums, especially for regulated institutions. For an overview of requirements, see [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland).
What happens to evidence and access after the engagement?
The team removes or disables all persistence mechanisms, access and accounts it created, following a documented chain of custody. It hands over or deletes artefacts according to customer instructions. This is a standard part of the playbook.
Related terms
- Red Team A Red Team simulates a realistic attack to test an organisation's detection and response capabilities under real-world conditions.
- Purple Team A Purple Team combines a Red Team and a Blue Team, allowing insights from attacks to directly improve detection rules.
- Blue Team The Blue Team defends an organisation's IT, detects attacks and responds to security incidents.
- MITRE ATT&CK MITRE ATT&CK is a publicly accessible knowledge base of adversarial tactics and techniques based on real-world observations.
- TTP Tactics, Techniques and Procedures (TTPs) describe how an attacker operates, from their goals to the concrete implementation.