Penetration testing finds and proves as many vulnerabilities as possible inside an agreed scope. Red teaming pursues one objective, such as reaching a trading system or reading the CEO’s mailbox, by any route that works, while your security team tries to catch it. The first measures your exposure. The second measures your detection and response. Most organizations need both eventually, in that order.
This guide sets out the differences that matter when you are deciding what to buy, including what each engagement costs, how long it runs, and the signs that you are ready for one and not the other.
The one-sentence difference
A penetration test is broad and cooperative: the testers know the scope, your team knows the dates, and the goal is coverage. A red team exercise is narrow and adversarial: the operators have an objective, your defenders usually do not know it is happening, and the goal is realism.
Both are performed by skilled people using real attack techniques. The difference is the question being answered.
What a penetration test is for
A penetration test answers: what is wrong with this system, and how bad is it?
- Scope is explicit. A web application, an API, an external perimeter, an internal network, a cloud account. The boundaries are written down before testing starts.
- Coverage is the goal. Testers work through the scope methodically, following the OWASP testing guides for applications and PTES or NIST SP 800-115 for networks, and go beyond them where judgment says to.
- Everything found is reported. A finding is a finding whether or not it leads anywhere. The report is a prioritized list with evidence and remediation guidance.
- Your team knows. Rules of engagement, testing windows, and contacts are agreed. Detection is not being measured, so there is no reason to hide.
- Compliance recognizes it. PCI DSS Requirement 11.4, NYDFS 500.5, SOC 2 auditors, and cyber insurers ask for penetration tests by name.
Typical duration is one to three weeks of testing. At Invadel, fixed prices start at $4,000 for an API test, $4,200 for an external network test, $5,200 for a web application, and $6,000 for an internal network, each with a free retest. The full list is on the pricing page.
What red teaming is for
A red team exercise answers: could a real attacker reach our most important assets, and would we notice?
- Scope is an objective, not a system. “Obtain domain administrator rights.” “Access the customer database.” “Move funds through the payment system.” The route is the operators’ choice.
- Realism is the goal. Operators use phishing, external attack paths, physical pretexts where agreed, and lateral movement the way a motivated adversary would, at the pace an adversary would.
- Only what advances the objective is pursued. A red team will walk past a dozen medium-severity vulnerabilities if one path already works. The report is a narrative of the attack, not an inventory.
- Defenders usually do not know. A small trusted group is aware. The security team is measured on what it detects and how it responds.
- Techniques are mapped to MITRE ATT&CK so the debrief can say which tactics were detected, which were missed, and where the gaps are.
Typical duration is three to six weeks, including planning and a debrief. Invadel’s red team assessments start at $12,500 for a focused operation with one objective and rise with the number of objectives, access vectors, and environments; the red team cost guide explains the tiers.
Side by side
| Penetration test | Red team exercise | |
|---|---|---|
| Question answered | What is exploitable in this scope? | Can an attacker reach the objective undetected? |
| Scope | Defined systems | Defined objective, open route |
| Breadth vs depth | Broad coverage of the scope | Deep pursuit of one path |
| Defenders informed | Yes | Usually a small trusted group only |
| What is measured | Vulnerabilities and their impact | Detection, response, and the attack path |
| Output | Prioritized findings with evidence | Attack narrative, detection timeline, ATT&CK mapping |
| Duration | One to three weeks | Three to six weeks |
| Starting price at Invadel | From $4,000 | From $12,500 |
| Compliance driver | PCI DSS, NYDFS 500, SOC 2, HIPAA, insurers | Board assurance, mature security programs, regulator expectations for large institutions |
How to tell which one you need
You need a penetration test if:
- You have never had one, or the last one is more than a year old.
- A customer, auditor, regulator, or insurer has asked for “a penetration test.” They mean this one.
- You just shipped a new product, migrated to the cloud, or inherited a network through an acquisition.
- Your vulnerability scanner says clean and you want to know whether a person would agree.
- You do not yet have a security team or a detection capability to measure.
You are ready for a red team exercise if:
- Your systems have been penetration tested and the serious findings are fixed.
- You have a security operations function, in-house or outsourced, with logging and alerting worth testing.
- Leadership wants to know whether the investment in detection actually works.
- You want to rehearse incident response against a live adversary rather than a tabletop scenario.
- A regulator or a board has asked for assurance beyond a vulnerability list.
Running a red team exercise before the basics are in place wastes money. The operators will reach the objective in the first week through a known-vulnerable system, and the report will tell you what a penetration test would have told you for a third of the price.
The common middle ground
Two engagements sit between the pure forms and are often the right answer.
Assumed-breach internal testing. An internal network penetration test starts from the position an attacker holds after a successful phishing email, a foothold on one workstation, and works toward Domain Admin. It is broad like a penetration test but follows the attacker’s logic, and it is the engagement most organizations get the most from once the perimeter is tested.
Purple teaming. A red team exercise run with the defenders in the room, pausing at each technique to check whether it was detected and tuning the alert on the spot. Less realistic, far more educational, and a good first step for a young security operations team.
Choosing at Invadel
Both engagements are run by the same senior in-house team, which matters because the red team can build on what the penetration test found rather than rediscovering it. Most clients start with a penetration test, fix what it finds, and move to a red team assessment once detection is in place. If you are unsure which applies to you, the short scoping questionnaire gives us enough to say, and the answer is sometimes “not yet.”
Written by
Invadel Team
Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →