Penetration test
“What weaknesses exist here?”
A defined area, known to operations, chasing coverage. Delivers a prioritised list of findings. Physical variant: perimeter, locks, access control and visitor process.
Breadth before depth
Terminology · Offensive security
The three words get used interchangeably — including by the people selling them. But they answer three different questions. Buy the wrong one and you get a correct answer to a question you never asked.
Christian Tang Mathiasen · · 6 min read
We regularly get a call from somebody who says: “We’d like a red team exercise.” Ten minutes into the conversation it often turns out that what they need is something else — and sometimes cheaper.
That is not the buyer’s fault. The industry uses the same words for wildly different services. So here is the difference as we use it, with no marketing on top.
A penetration test has a defined scope: these systems, this network, this building, in this period. The purpose is coverage — to find and document as many exploitable weaknesses as possible within the agreed area.
The test is rarely secret. Operations usually know it is running, and that is the intention: you want access to everything inside the scope, not to sneak up on it. The outcome is a list of findings, severity and recommended remediation. It is a good product. It is often also the right place to start, because it is the cheapest way to clear out what is already known.
The same principle exists physically. A physical penetration test puts specific, agreed barriers to the test: perimeter, doors, locks, access control, visitor process. Its limitation lies in the very thing that makes it strong — the scope. An attacker does not read your scope.
A red team exercise does not measure coverage. It measures whether an objective can be reached. The goal is rarely “find vulnerabilities”, but “reach this account, this system, this dataset — without being detected”.
The other half matters just as much: the exercise tests the defence. Did anyone notice? When? What did they do, and did it work? That is why a red team exercise is known to only a handful of people in the organisation while it runs. You get fewer findings than from a penetration test, but a deeper answer — and an answer about the organisation, not only about the technology.
In practice, red teams work mainly in the cyber domain. The way in is typically an email, an exposed service or a stolen credential. Run the two teams together with open communication throughout and it is usually called a purple team exercise. That is more training than test, and it is underrated.
This is our category, and the difference is not cosmetic. Where red teams take on the role of possible adversaries mainly in order to find weaknesses in the cyber domain, black teams take a more intense and realistic approach and work primarily in the physical and human domain.
The team is independent of the organisation it tests, and has no access to internal knowledge of the systems. It works under the same shortage of information as a real attacker — and uses the methods an attacker would use: social engineering, physical infiltration, silent breaching and deception.
Where the red team’s way in is an email, ours is a door. Or a contractor’s uniform, a visitor registration nobody checked, a key in a drawer five metres from the room it opens. Silent breaching — opening something in such a way that afterwards it cannot be seen to have been open — is a physical craft. Deception is not a technology but a story that fits what the employee was expecting to see that day anyway.
Side by side
They do not exclude one another. Most organisations need them in sequence — and get the most out of them in exactly that order.
“What weaknesses exist here?”
A defined area, known to operations, chasing coverage. Delivers a prioritised list of findings. Physical variant: perimeter, locks, access control and visitor process.
Breadth before depth
“Can anyone reach the objective unseen?”
Objective-driven, covert, known to only a few. Tests the defence just as much as the attack surface. In practice works mainly in the cyber domain.
Depth before breadth
“What can a human being do on site?”
An independent team with no internal knowledge. The physical and human domain: reconnaissance, pretext, entry, internal movement, detection and response.
The whole attack chain
Scope is not bureaucracy. It is the single factor that decides most about what you learn. A narrow scope gives a precise answer to a narrow question. That is fine, if that was the question you had.
The attacker has no scope. He has an objective and the time to choose for himself which door it goes through. So the most useful way to commission a test is not to describe the method, but to describe the objective: what must not be reachable? Then we find the routes there — including the ones nobody had thought of.
Freedom in method is not the same as an absence of limits. Scope, techniques, sensitive areas, escalation procedures and safety limitations are always agreed in advance in a Rules of Engagement agreement that you approve. The purpose is never to disrupt operations or embarrass employees.
Choose a penetration test if you want to know how many known weaknesses exist in a particular system or a particular building, and would like a list you can work through systematically.
Choose a red team exercise if you have already closed what is known, have a monitoring or response function, and want to know whether it spots a real attacker in time.
Choose a black team engagement if your risk does not live only in the network: if somebody could do damage by standing physically in front of the equipment, talking to the right employee, or walking in as a contractor on a Friday afternoon.
And choose none of them yet if you know the findings will not be fixed. A test that ends in a drawer is an expensive way to acquire a bad conscience. Start instead with a baseline: a Security Assessment gives you an overall picture of the security level and a prioritised order for the money — from DKK 47,500 excl. VAT.
Because the category decides what actually gets tested. When an organisation buys “red team”, what it buys in practice is a cyber exercise. The physical and human domain becomes a section in a policy that nobody has put to the test — and that is usually the section a real attack chain starts in.
We could call it “physical red teaming”. It would sell more easily. But it would also imply that it is a variant of the cyber exercise, and it is not. It is a different discipline with a different professional core: observation, reconnaissance, elicitation, behaviour, routines, equipment — and a patience that cannot be automated.
If you are in doubt about what you need, have a conversation first. It takes twenty minutes to work out, and we have a clear interest in you not buying the wrong thing. We would rather sell the right engagement in a year than the wrong one today.
Next step
A short conversation is enough to work out whether a Security Assessment or a full penetration test is the better fit. It costs nothing and commits you to nothing.