Nine firms publish a red team service that survives verification: Stingrai, NCC Group, MDSec, NetSPI, Bishop Fox, TrustedSec, SpecterOps, Praetorian and Lares. Each one names red teaming as a product on its own site rather than as a line in a consulting brochure, commits in writing to objective-based operations, and can be checked against an independent register. That last part matters more than any marketing page, because red teaming is the least regulated word in offensive security and the gap between firms who sell it and firms who can evidence it is wide.
The commercial case for buying one is not in dispute. Enterprise security controls block only 37% of attacker actions once the attacker has authenticated access, and fewer than 1 in 6 simulated attacks produce a meaningful alert, across more than 338 million simulations analysed in the Picus Blue Report 2026. Perimeter prevention actually improved this year, climbing from 62% to 69%. The interior did not move with it. A red team is the only assessment type that measures that gap directly, by behaving like an adversary who is already past the edge.
This page is about who to hire. If you need the category explained first, what belongs in scope, how the engagement runs and what the report must contain, start with the red team services buyer's guide, which answers the what and the how. This one answers the who.
Quick answer: which companies provide the best red team services?
The nine providers below, ranked on verified red team capability rather than brand recognition.
# | Provider | Best for | Accreditation position (verified August 2026) |
|---|---|---|---|
1 | Stingrai | Objective-based commercial red teams with named senior operators, run annually or continuously | CREST-accredited Penetration Testing service provider (firm level) |
2 | NCC Group | Regulator-mandated threat-led testing across the widest set of jurisdictions | CREST Threat Led Penetration Testing and TLPT-FS, plus CBEST, STAR-FS, TIBER-EU and CHECK |
3 | MDSec | Deep technical tradecraft against mature financial-services defences | CREST Threat Led Penetration Testing and TLPT-FS, plus CBEST, STAR-FS, TIBER-EU and GBEST |
4 | NetSPI | Large multi-scenario programs that move from annual baseline to continuous | CREST Penetration Testing and Threat Led Penetration Testing, with Red Teaming listed as a service area |
5 | Bishop Fox | Objective-based red teams paired with ransomware readiness and tabletop work | CREST Penetration Testing, accredited in both the UK and the USA |
6 | TrustedSec | Full-scope engagements that include physical breach and end in a purple team phase | CREST Penetration Testing, plus PCI DSS QSA and CMMC RPO status |
7 | SpecterOps | Identity and attack-path-led operations, and AI system red teaming | CREST Penetration Testing |
8 | Praetorian | Time-boxed objective-based operations managed through a delivery platform | CREST Penetration Testing |
9 | Lares | Physical, social and insider-threat scope inside a single red team | Not listed on the CREST Marketplace |
The single most useful question a buyer can ask themselves before reading any further: does this test have to satisfy a regulator? If a supervisor has mandated threat-led penetration testing under CBEST, STAR-FS, GBEST or TIBER-EU, the accreditation is not a preference, it is the whole procurement, and the field narrows to three names. If the test is commercial and the deliverable is evidence about your own detection and response, accreditation is one input among six and operator quality dominates.

How this ranking was built
Six criteria, applied in order. A firm that failed criterion 1 was not ranked no matter how well known it is.
Red teaming is a productized service. The provider publishes a named red team, adversary simulation or attack simulation service on its own site. "We also do red teaming" inside a general consulting page does not qualify.
Objective-based operations are explicit. The service description commits to a named objective and adversary emulation rather than describing a wider penetration test.
Accreditation is verified independently. Every accreditation in this post was checked against the CREST Marketplace supplier register in August 2026, not taken from the vendor's own marketing copy. Where a vendor's own page claims more than the register shows, this post says so.
Full-scope capability. Whether social engineering, and where relevant physical entry, are in the provider's published scope rather than sold as an unrelated product.
Delivery-model transparency. Whether the work is one-time, continuous, or both, and whether the operators are the firm's own bench.
Checkable facts. Every claim below traces to a page that returned an HTTP 200 during the research pass for this article.
Two things this ranking deliberately does not use. It does not rank on customer logos, because logo walls are unverifiable and every firm on this list has enterprise clients. It does not rank on headcount, because a nine-person red team practice inside a 2,000-person firm and a nine-person independent practice deliver the same engagement, and the org chart above the operators is not what you are buying.
Considered and not ranked
Black Hills Information Security is the notable absence and the reason is category fit, not quality. BHIS is one of the most respected names in offensive security and runs an unusually generous research and training operation. As of August 2026 its published services are penetration testing, continuous penetration testing, web application testing, Fusion PenTest, AI security assessments, ActiveSOC, blue team services, blockchain security and high-profile risk assessments. There is no red team service page, and the phrase does not appear on the services index or the complete service guide. A ranking of red team providers cannot include a firm that does not currently sell the category.
The same test removed several penetration-testing-as-a-service platforms whose marketing borrows red team language while their actual product is scoped, announced, asset-list testing. That is a good product. It is not this category, and paying red team prices for it is one of the most common procurement errors in this market.
Breach-and-attack-simulation software was also excluded. It is genuinely useful for regression-testing detection content, but it executes a catalogue of known actions rather than improvising against your specific defenders, and it is not a service provider.
Why the interior gap is the thing you are buying
Before the profiles, the evidence that sets the scoping conversation.
Mandiant's M-Trends 2026, built on more than 500,000 hours of frontline incident response during 2025, reports global median dwell time rising to 14 days, up from 11 the year before, while the share of intrusions organisations detected themselves rose to 52% from 43%. Both numbers moved in the same year. Defenders are catching more, and adversaries who are not caught are staying longer.
The initial access picture explains why red team scoping arguments so often go wrong.

Exploitation leads at 32% of initial infection vectors, the sixth consecutive year in that position. The number that should change a scope document is second place: highly interactive voice phishing at 11%, now ahead of email phishing at 6%. Most red team proposals still price phishing as the social engineering line item and treat vishing as an optional extra. The intrusion data has moved. If your provider's social engineering scope is email-only, the scenario is already out of date, and the guidance in which threat group your red team should emulate is worth reading before you sign.
1. Stingrai
Best for: buyers who want an objective-based red team run by named senior operators, available as a one-time annual exercise or as a continuous program, with the detection measurement written into the scope rather than sold as an add-on.
At a glance
Headquarters | Toronto, Ontario, Canada, with a London, UK office |
Founded | 2021 |
Red team offering | Objective-based red teaming across three scenario models: assumed breach, black box full chain, and threat-intelligence-led |
Full scope | Social engineering including phishing and vishing, physical entry and on-site intelligence gathering, cloud reconnaissance and IAM abuse, lateral movement, exfiltration and ransomware simulation |
Accreditation | CREST-accredited Penetration Testing service provider at firm level, listed on the CREST Marketplace for Europe and North America |
Team credentials | OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE, eWPTX |
Delivery | One-time annual engagements and continuous testing programs |
Track record | 18 published CVEs, 5.0/5.0 across 19 Clutch reviews, research presented at DEFCON and BSIDES |
Why Stingrai ranks first
The engagement is scoped around an outcome, not an asset list. Threat intelligence gathering runs first to establish which adversaries realistically target your sector, objectives and rules of engagement are agreed in writing against MITRE ATT&CK before any operator touches the environment, and the deliverable is an attack narrative with business impact rather than a vulnerability table. The rules of engagement checklist covers the clauses that should be settled at that stage.
Three things separate it from a well-run penetration test. Scope genuinely includes physical entry and voice-based social engineering, which is where the current intrusion data says the pressure is. Detection and response measurement is part of the engagement rather than an inference drawn from the provider's own logs. And the same senior operators carry the work from scoping through the debrief, so the person explaining what your SOC missed is the person who did it.
Both delivery models are available. A single annual full-scope exercise is a legitimate purchase and Stingrai sells it as one. So is a continuous program where scenarios rotate through the year and detection content is retested after each round. The choice is a function of how mature your detection program already is, and the comparison of red teaming, penetration testing and continuous validation sets out when each is the right instrument.
Worth stating plainly because the market blurs it: Stingrai's red team engagements are run by human operators. Snipe, Stingrai's autonomous agent, is a web application penetration testing agent that hunts complex authorization, IDOR and business logic flaws, performs white-box code review and opens AutoFix pull requests. It is a different product with a different job, and it does not run red team operations.
Watch-outs
Stingrai is not on a regulator threat-led testing register. If your supervisor has mandated CBEST, STAR-FS, GBEST or TIBER-EU testing, the engagement has to be delivered by a provider accredited for that scheme, and the accredited firms in this ranking are NCC Group, MDSec and NetSPI. Stingrai's accreditation is the firm-level CREST Penetration Testing accreditation, which is meaningful for commercial red team procurement and for supplier due diligence, and it is not a substitute for a scheme accreditation.
The bench is senior rather than large, which is the reason the operator quality is consistent and also the reason a multi-country, multi-site full-scope program needs lead time in the calendar. Book early rather than assuming a two-week start.
2. NCC Group
Best for: regulator-mandated threat-led testing, especially where a group operates across more than one supervisory regime.
NCC Group's Full Spectrum Attack Simulation practice publishes five distinct offerings: Red and Black Teams, Purple Team, Gold Team, Regulatory Simulated Attack and Attack Path Mapping. The red and black team work is described as covert simulation that unveils "both the digital and physical weaknesses in your security posture", with threat intelligence generating the scenarios, TTPs and threat actors to emulate.
The accreditation position is the deepest in this ranking and it is verifiable. The CREST Marketplace lists NCC Group for Penetration Testing, Vulnerability Assessment, Incident Response, Incident Exercising, Security Operations Centre, Threat Intelligence for Simulated Attack, Threat Led Penetration Testing, and both TLPT-FS threat intelligence and TLPT-FS threat-led penetration testing. Its partner-assured schemes include UK Bank of England CBEST, STAR-FS, TIBER-EU TLPT, NCSC CIR at standard and enhanced level, NCSC Cyber Incident Exercising, CAA ASSURE and NCSC CHECK. Its own attack simulation page adds delivery under iCAST in Hong Kong, AASE in Singapore, CORIE in Australia and FEER in Saudi Arabia.
Watch-outs. Scale cuts both ways. Lead times track senior consultant availability inside a listed company with a broad services portfolio, and pricing reflects an accredited practice. If you are not in scope for a threat-led framework, you are paying for a regulatory apparatus you do not need. Name the operators in the statement of work rather than accepting a practice-level assurance, which is standard practice worth applying to any large firm.
3. MDSec
Best for: technically demanding operations against mature financial-services defences, where evasion tradecraft is the differentiator.
MDSec's ActiveBreach team is described as delivering "deep, objective-led operations, simulating the Tactics, Techniques and Procedures (TTPs) of advanced adversaries", and the firm states directly that "our red team operations are provided under and inline with the CBEST, GBEST, STAR and TIBER frameworks". The CREST Marketplace confirms it: Threat Led Penetration Testing and TLPT-FS accreditation, with partner-assured CBEST, STAR-FS, TIBER-EU and GBEST threat-led penetration testing, plus NCSC CHECK.
Two register details are worth quoting because they are unusually informative. MDSec's own service-mix declaration puts red teaming at 40% of its business, the highest proportion of any firm here, and financial services at 80% of that red team work. It has held CREST membership for 14 years with a team of 50 to 99. This is a specialist practice, not a red team line inside a general consultancy.
Watch-outs. On 30 July 2026, Bank of America announced an agreement to acquire MDSec Consulting Limited, a transaction expected to close in Q4 2026 subject to regulatory approvals. The announcement describes roughly 65 cybersecurity professionals joining the bank. Buyers running a procurement now should ask directly, and get the answer in writing, whether third-party consulting engagements will continue on the same terms after close, what happens to multi-year programs, and which named operators are committed to the work. This is not a criticism of the firm. It is the single most material scheduling risk in this ranking and it has a hard date attached.
4. NetSPI
Best for: large programs that need several scenario types under one contract and a path from an annual baseline to continuous testing.
NetSPI publishes three red team engagement types rather than one: assumed-breach scenario-based testing, black box, and threat-intelligence-led engagements aimed at regulatory frameworks. Its own guidance is refreshingly direct about cadence, recommending organisations schedule testing "annually as a baseline, then as your security maturity grows, move towards continuous and ongoing scenario-based assessments".
On the CREST Marketplace, NetSPI lists Red Teaming as a declared service area alongside Security Testing, with accreditation for Penetration Testing and Threat Led Penetration Testing, across Europe and North America, at 500 to 999 employees and ten years of membership. Its own red team page additionally states CBEST accreditation and lists support for AASE, ART, CORIE, FEER, iCAST, STAR, STAR-FS, DORA and TIBER-EU. The register confirms the CREST TLPT accreditation; the CBEST claim comes from NetSPI's own page, so ask for the certificate reference during procurement.
Watch-outs. NetSPI's portfolio spans penetration testing, attack surface management and breach-and-attack simulation, and the red team practice sits inside that wider platform business. Confirm which of the three engagement types you are actually buying, because assumed-breach scenario-based testing and a full covert operation are priced and staffed very differently.
5. Bishop Fox
Best for: objective-based red teams bundled with the readiness work that turns the findings into an exercise programme.
Bishop Fox names the category properly. The service page commits to "objective-based red team operations that emulate real attackers" using a "threat-informed, objective-based red team methodology grounded in real-world adversary behavior", aligned to MITRE ATT&CK, with the engagement running planning and threat modelling, active attack simulation over several weeks, then reporting and debrief. The Red Team and Readiness category also carries social engineering, ransomware readiness and IR tabletop exercises, which is a genuinely useful bundle if the goal is to improve response rather than only to test it.
Founded in 2005 and headquartered in Tempe, Arizona, Bishop Fox holds CREST Penetration Testing accreditation covering both Europe and North America, is ISO 27001 certified and has been a CREST member for four years, at 100 to 499 employees.
Watch-outs. Bishop Fox's Cosmos platform is frequently described in the market as continuous red teaming. It is not. Cosmos is continuous attack surface discovery and testing with expert human validation, and the company's own platform page keeps Red Team and Readiness as a separate service category from the Cosmos platform. That distinction is worth holding onto: continuous attack surface testing and a covert objective-based red team answer different questions, and buying the first while believing you bought the second is a costly mix-up.
6. TrustedSec
Best for: full-scope engagements where physical breach is genuinely in scope and the exercise is designed to end in a purple team phase.
TrustedSec calls the service Adversarial Attack Simulation and describes it as "an objective-driven assessment that mimics real-world adversaries". The published six-phase structure is the most transparent in this ranking: pre-planning and threat modelling, reconnaissance and perimeter evaluation, social engineering and initial access, internal expansion and privilege escalation, defensive inclusion and purple teaming, then reporting and executive debrief.
Two details matter for scoping. Social engineering explicitly covers "ethical phishing, vishing, SMS, and physical breach techniques", which lines up with where the M-Trends data says initial access is actually happening. And phase five builds the purple team collaboration into the engagement rather than selling it afterwards, which is the phase most likely to be cut when a red team quote gets negotiated down.
TrustedSec earned CREST Penetration Testing certification in April 2025 and appears on the CREST Marketplace at 100 to 499 employees with 51 to 100 technical personnel, red teaming declared as 20% of its service mix. It also holds PCI DSS QSA and CMMC Registered Practitioner Organization status, which matters if the same firm is doing compliance-adjacent work.
Watch-outs. The register lists North America only. For engagements requiring a UK or EU scheme accreditation, this is not the provider.
7. SpecterOps
Best for: identity-centric operations, attack path work in Active Directory and Entra ID, and red teaming of AI systems.
SpecterOps sits at an unusual intersection: a services firm that also built BloodHound, the open-source attack path tool most other red teams on this list use. Its services page runs red team exercises that "replicate real-world tradecraft across traditional and AI-enabled systems", objective-driven penetration testing, an explicit AI Red Team practice that breaks AI systems down by lifecycle stage, and Attack Path Assessments powered by BloodHound Enterprise that map "chains of abusable privileges across critical assets" to find identity choke points.
The commercial framing is distinctive and stated openly: the firm positions its work around leaving clients with "capabilities you own" through knowledge transfer, alongside maturity assessments and program development for organisations standing up their own red team, purple team, threat hunting or detection functions. Founded in 2017 and headquartered in Alexandria, Virginia, it is CREST accredited for Penetration Testing, ISO 27001 certified, at 100 to 499 employees, and describes its approach on the register as "impact objective driven testing".
Watch-outs. North America only on the CREST register, with no threat-led scheme accreditation, so this is not the route to a regulated test. The identity and attack-path emphasis is a genuine strength, and it also means you should confirm that the full-scope elements you want, particularly physical and voice-based social engineering, are inside the scope you are quoted. If your objective is grading a proposal's technique coverage, the MITRE ATT&CK coverage grading method applies well here.
8. Praetorian
Best for: time-boxed, objective-based operations with clear delivery tracking, particularly where industrial or high-value asset objectives are in play.
Praetorian's red team page is unusually specific about objectives, listing demonstrating financial loss, accessing VIP assets, controlling industrial systems, simulating ransomware and stealing intellectual property or customer data. It states that operations "emulate the tactics of nation-state adversaries and advanced persistent threats to expose weaknesses across your people, processes and technology", and that the team includes former NSA and CIA officers.
It is also the only provider here that publishes an engagement duration on the service page: most engagements "run from two to six weeks including planning, execution, and reporting", across kickoff, threat modelling, execution, technical reporting and executive debrief. Delivery is tracked through the Praetorian Guard Red Team Platform, described as a central point for managing engagements, tracking attack objectives and demonstrating impact. An offensive labs research team develops the TTPs and tooling behind it. Founded in 2010, headquartered in Austin, Texas, CREST accredited for Penetration Testing in North America, at 100 to 499 employees.
Watch-outs. Two to six weeks including planning and reporting is a tight envelope for a genuinely covert full-scope operation, and it is worth asking how many of those weeks are operator days on target rather than elapsed calendar. Praetorian's centre of gravity has shifted toward continuous threat exposure management through its Chariot platform, so confirm you are buying a red team rather than a platform subscription with red team validation attached. No threat-led scheme accreditation on the register.
9. Lares
Best for: engagements where physical security, social engineering and insider threat need to sit inside one red team rather than three separate purchases.
Lares describes red teaming as a "full-scope, multi-layered attack simulation designed to measure how well a company's people, processes, and technologies can withstand an attack from a real-life adversary", and publishes physical security, social engineering, insider threat, purple team and AI security testing as distinct service lines that can be combined. Its stated philosophy, "continuous defensive improvement through adversarial simulation and collaboration", is consistent with how the practice is structured.
The lineage is relevant. Founded in 2008 and based in Denver, Colorado, Lares is led by Chris Nickerson, who founded the Penetration Testing Execution Standard. For buyers who care that a provider has contributed to the methodology the rest of the market cites, that is a real signal.
Watch-outs. Lares does not appear on the CREST Marketplace supplier register as of August 2026. That is not a quality judgement, since plenty of strong US practices are not CREST members, but it does mean the accreditation column has to be filled by something else during due diligence: named operator certifications, sample reports with the client details removed, and references from engagements of comparable scope. If your procurement process requires a third-party accreditation, ask what independent verification the firm can offer instead.
What a red team engagement costs in 2026
Red teams are quoted on senior operator days, not per asset, so the price tracks scope breadth, duration, scenario count and how much threat intelligence sits in front of the operation.

Published UK market guidance from EJN Labs puts a focused red team exercise at 15,000 to 35,000 pounds over two to three weeks, and threat-intelligence-led red teaming aligned to STAR and TIBER-UK structures at 75,000 pounds or more. The same guidance puts UK day rates for CREST-certified testers at 1,100 to 1,400 pounds per day, which is the number to reach for when a proposal quotes a total without a day count.
Three things move a quote materially:
Scheme accreditation. An accredited threat-led test carries the cost of accredited threat intelligence, formal phase gates and supervisory reporting. That is the reason the STAR and TIBER-aligned band starts where the commercial band ends.
Scenario count. One objective against one adversary profile is one price. Three scenarios against three profiles is not three times cheaper for being bundled.
Physical and voice scope. On-site entry attempts and vishing campaigns need travel, pretext development and legal cover, and they are the first items cut when a quote is negotiated down.
A full breakdown of what actually drives the number sits in how much a red team engagement costs in 2026.
How to verify a provider's claims before you sign
Eight checks, in the order they are cheapest to run.
Look up the accreditation yourself. Search the provider on the CREST Marketplace. Confirm the specific scheme, not just membership. Penetration Testing and Threat Led Penetration Testing are different accreditations and only the second one satisfies a threat-led mandate.
Separate firm accreditation from individual certification. A firm-level accreditation says the practice passed an assessment. A tester holding CREST CRT or CRTO says an individual passed an exam. Both are legitimate, and a proposal that blends them into one sentence is hiding which one it has.
Ask which framework the report will satisfy. If the answer is a list of every acronym in the market, ask for the certificate reference for the one you actually need.
Name the operators in the statement of work. Ask who will run your engagement, what they have run before at comparable scope, and what happens if they become unavailable.
Demand per-stage detection timings as a contractual deliverable. The measurement that distinguishes a red team from an expensive penetration test is a timeline of what fired, what was logged silently, what was never seen, and how long each took. Benchmarks for what good looks like are in the red team detection benchmarks for 2026.
Confirm the replay session is included. A joint walkthrough with your SOC, where paths are replayed so detection content can be written and tested, converts an exercise into an improvement. It is frequently priced separately and quietly dropped.
Read the social engineering scope line by line. Email only, or email plus vishing and SMS? Is physical entry in or out? The intrusion data says voice phishing is now the second most common initial infection vector, so an email-only scope is testing last year's adversary.
Score the proposal against a fixed question set rather than reading each one on its own terms. The pentest and red team RFP question bank gives scored answers for exactly this.
What this means for buyers
The regulator question comes first and settles most of the shortlist. If a supervisor has mandated threat-led testing, only an accredited provider counts and the field narrows to three firms in this ranking. Everything else, including price, is downstream of that.
Accreditation is a floor, not a ranking. Every firm in the top eight here holds CREST Penetration Testing accreditation, which means it cannot be the thing that separates them. What separates them is who runs the operation, whether the objective is agreed in writing, and whether detection measurement is a deliverable or an afterthought.
Category names are being stretched, so check the product. Continuous attack surface testing, breach-and-attack simulation and penetration-testing-as-a-service are all sold with red team vocabulary. Each is a legitimate product answering a different question. Read the service page, not the campaign.
Scope the social engineering to current data. Voice phishing is now the second most common initial infection vector. An engagement whose human-attack surface is email-only is not emulating what is currently working.
Match the cadence to your detection maturity. If detection has never been measured, an annual exercise establishes the baseline. Once there is a functioning SOC and tuned content to protect, a continuous program that rotates scenarios and retests detection after each round produces more improvement per pound. Stingrai sells both, and the honest answer depends on where you are, not on which model the provider prefers to sell.
Frequently Asked Questions
Which companies provide the best red team services?
Nine firms publish a red team service that survives verification against their own service pages and the CREST Marketplace supplier register: Stingrai, NCC Group, MDSec, NetSPI, Bishop Fox, TrustedSec, SpecterOps, Praetorian and Lares. Stingrai ranks first for commercial objective-based red teaming delivered by named senior operators, as either a one-time annual exercise or a continuous program. NCC Group and MDSec lead for regulator-mandated threat-led testing, both holding CREST Threat Led Penetration Testing accreditation alongside CBEST, STAR-FS and TIBER-EU.
How much does a red team engagement cost?
Published UK market guidance from EJN Labs puts a focused red team exercise at 15,000 to 35,000 pounds over two to three weeks, and threat-intelligence-led red teaming aligned to STAR and TIBER-UK structures at 75,000 pounds or more. UK day rates for CREST-certified testers sit at 1,100 to 1,400 pounds per day. Price tracks scope breadth, duration, scenario count and threat-intelligence depth rather than asset count, and accredited threat-led testing sits above the commercial band because of the accredited intelligence, formal phase gates and supervisory reporting it carries. The full cost breakdown covers what moves the number.
What is the difference between a red team and a penetration test?
A penetration test asks what is exploitable inside a defined scope of assets. It is announced to the blue team, does not require stealth, typically runs for days to two weeks, and delivers findings with reproduction evidence and remediation guidance. A red team asks whether anyone would notice an adversary reaching what matters most. It is scoped around a named crown-jewel objective rather than an asset list, is concealed from everyone except a small control group, requires stealth throughout, runs three to eight weeks or considerably longer when regulated, and delivers an attack narrative plus detection and response timings for each stage. The short version: a penetration test measures your attack surface, a red team measures your defenders.
Which red team providers are accredited for CBEST, STAR-FS or TIBER-EU?
Of the providers ranked here, NCC Group and MDSec both hold CREST Threat Led Penetration Testing and TLPT-FS accreditation with partner-assured CBEST, STAR-FS and TIBER-EU status, and MDSec additionally carries GBEST. NetSPI holds CREST Penetration Testing and Threat Led Penetration Testing accreditation on the register, and states CBEST accreditation on its own service page. Always confirm the specific scheme and certificate reference on the CREST Marketplace rather than relying on a vendor page, because scheme accreditations are granted individually and change over time.
How long does a red team engagement take?
A commercial full-scope engagement typically runs three to eight weeks of elapsed time, with scoping and rules of engagement in front of it and reporting, debrief and replay behind it. Praetorian publishes two to six weeks including planning and reporting for most of its engagements, which sits at the shorter end. Regulator-mandated threat-led programs are a different scale entirely: a DORA threat-led penetration test following TIBER-EU runs through five formal phases and takes many months from procurement to supervisory closure. Ask how many operator days sit inside the elapsed weeks, because that is what you are paying for.
Does a red team engagement include physical and social engineering?
It depends on the provider and on what you scope, which is exactly why it needs checking line by line. Stingrai, TrustedSec, Lares and NCC Group all publish physical or on-site elements within red team scope, and TrustedSec specifies phishing, vishing, SMS and physical breach techniques. Others price social engineering as a separate service. Given that Mandiant's M-Trends 2026 puts highly interactive voice phishing at 11% of initial infection vectors, ahead of email phishing at 6%, an email-only social engineering scope no longer reflects how intrusions actually start.
Can a red team be delivered continuously rather than annually?
Yes, and both models are legitimate purchases. An annual full-scope exercise establishes a baseline and is the right first move when detection has never been measured. A continuous program rotates scenarios through the year and retests detection content after each round, which produces more improvement once a functioning SOC exists. NetSPI's own guidance recommends starting with an annual baseline and moving toward continuous as maturity grows, and Stingrai delivers red team work under both models. Be careful with vendor language here: continuous attack surface testing and breach-and-attack simulation are sold with similar words and answer a different question.
Is a red team worth it for a mid-sized company?
Only once there is something to test. A red team measures defenders, so if your detection program has never been instrumented, a purple team exercise will teach you the same lessons faster and cheaper. The trigger to buy a red team is a functioning security operations capability, tuned detection content worth protecting, and a specific crown-jewel outcome you can name. Scoping by objective is where that decision gets made.
How do I verify a provider's red team accreditation claims?
Search the provider directly on the CREST Marketplace supplier register and read the scheme names, not just the membership badge. CREST Penetration Testing and CREST Threat Led Penetration Testing are separate accreditations, and only the second satisfies a threat-led mandate. Check whether partner-assured schemes such as CBEST, STAR-FS, TIBER-EU or GBEST are listed. Then separate firm-level accreditation from individual tester certifications, because a proposal that blends the two in one sentence is usually leaning on the weaker of them.
What should a red team report contain?
An attack narrative describing the path taken toward the objective, evidence for each stage, and a detection and response timeline showing what fired, what was logged without alerting, what was never observed, and how long your team took to react at each point. Prioritised remediation should cover both the technical weaknesses and the detection gaps. A report that lists vulnerabilities without per-stage detection timings is a penetration test report with a red team invoice attached.
Related reading
Red Team Services 2026: What They Include, Who to Hire and What They Cost, the buyer's guide covering what an engagement is and how it runs
Red Team Rules of Engagement: What to Demand Before You Sign
Which Threat Group Should Your Red Team Emulate, by Industry
References
CREST. CREST Marketplace supplier register. Accessed August 2026. https://marketplace.crest.org/. Independent register of CREST-accredited providers, showing per-scheme accreditations including Penetration Testing, Threat Led Penetration Testing, TLPT-FS, and partner-assured schemes such as CBEST, STAR-FS, TIBER-EU, GBEST and CHECK. Every accreditation claim in this article was checked here.
Picus Security. Blue Report 2026. 2026. https://www.picussecurity.com/blue-report. Fourth annual analysis of 338 million attack simulations run in customer environments, reporting prevention, logging and alerting rates by defensive outcome.
Mandiant (Google Cloud). M-Trends 2026. 2026. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026/. Built on more than 500,000 hours of frontline incident response during 2025, reporting median dwell time, detection source split and initial infection vectors.
Bank of America. Bank of America to acquire information security consultancy MDSec Consulting Limited. 30 July 2026. https://newsroom.bankofamerica.com/content/newsroom/press-releases/2026/07/bank-of-america-to-acquire-information-security-consultancy-mdse.html. Announcement of the agreement to acquire MDSec, expected to close in Q4 2026.
EJN Labs. Penetration Testing Cost UK: 2026 Pricing Guide. 2026. https://ejnlabs.com/penetration-testing-cost-uk/. Published UK market pricing guidance covering red team exercise bands, threat-intelligence-led testing and CREST-certified tester day rates.
NCC Group. Attack Simulation. Accessed August 2026. https://www.nccgroup.com/technical-assurance/attack-simulation/. Service page describing Red and Black Teams, Purple Team, Gold Team, Regulatory Simulated Attack and Attack Path Mapping, and the regional frameworks delivered.
MDSec. Adversary Simulation. Accessed August 2026. https://www.mdsec.co.uk/our-services/adversary-simulation/. ActiveBreach red team service page stating delivery under the CBEST, GBEST, STAR and TIBER frameworks.
NetSPI. Red Team Operations. Accessed August 2026. https://www.netspi.com/security-testing/red-team-operations/. Service page describing assumed-breach scenario-based testing, black box and threat-intelligence-led engagements, and recommended testing cadence.
Bishop Fox. Red Teaming. Accessed August 2026. https://bishopfox.com/services/red-team. Service page describing objective-based red team operations and the Red Team and Readiness category.
TrustedSec. Red Teaming. Accessed August 2026. https://trustedsec.com/services/red-teaming. Adversarial Attack Simulation service page setting out the six-phase engagement structure and social engineering scope.
SpecterOps. Services. Accessed August 2026. https://www.specterops.io/services/. Service index covering red team exercises, AI Red Team, Attack Path Assessments and program development.
Praetorian. Red Team. Accessed August 2026. https://www.praetorian.com/services/red-team/. Service page listing attack objectives, engagement duration and the Praetorian Guard Red Team Platform.
Lares. Services. Accessed August 2026. https://www.lares.com/services/. Service index covering red teaming, purple team, social engineering, physical security and insider threat.
Black Hills Information Security. All Services. Accessed August 2026. https://www.blackhillsinfosec.com/services/. Service index used to confirm the current published offensive services portfolio.
Stingrai. Red Teaming. Accessed August 2026. https://www.stingrai.io/services/red-teaming. Service page describing assumed breach, black box full chain and threat-intelligence-led scenarios, and the full-scope elements included.
Ready to scope a red team?
Bring the objective, not the asset list. Stingrai's red team engagements start with the crown-jewel outcome you need tested, agree the rules of engagement in writing, and hand back an attack narrative with per-stage detection timings your SOC can act on, delivered as a one-time annual exercise or as a continuous program.
Talk to the red team or read what the red teaming service covers end to end.



