TL;DR: Offensive security only creates value when it is aligned to business risk, crown jewels, and realistic attacker objectives, according to Bishop Fox, with mature programs using tiered testing, multiple scenarios, and continuous coverage for high-value environments. The practical shift is from checklist penetration tests to measurable adversary emulation that exposes exploitable weakness, detection gaps, and strategic control failures.
NHIMG editorial — based on content published by Bishop Fox: Red Teaming: Is Your Security Program Ready for the Ultimate Test?
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, with 46% confirmed and 26% suspected.
Questions worth separating out
Q: What makes a red team exercise useful to security leaders?
A: A useful red team exercise shows how an attacker could reach high-value assets, where defenders would detect the activity, and which architectural weaknesses make the path possible.
Q: How should security teams decide which systems red teams should target?
A: They should start with crown jewels, likely threat actors, and the attack paths most likely to produce material loss.
Q: What do organisations get wrong about offensive security coverage?
A: They often confuse compliance cadence with meaningful coverage.
Practitioner guidance
- Define crown jewels before scheduling tests Identify the 20 systems or identities that would create the most loss if compromised, then build red team scenarios around those assets instead of around generic tool coverage.
- Translate identity weaknesses into testable scenarios Add standing privilege, credential reuse, offboarding gaps, and secrets exposure to offensive scenarios so the exercise reflects realistic attacker movement rather than isolated vulnerabilities.
- Use tiered cadence instead of annual theatre Move high-risk environments to semiannual or continuous offensive coverage, while lower-risk areas stay on a slower cadence.
What's in the full article
Bishop Fox's full webcast covers the operational detail this post intentionally leaves for the source:
- The 5-5-20x planning model for tying red team scope to threats, threat actors, crown jewels, and business lines.
- Cadence examples for external, internal, web, cloud, purple team, and assumed-breach exercises across maturity tiers.
- The full good, bad, and ugly outcome matrix that shows how reporting quality changes the value of an engagement.
- Companion guidance on what makes a red team result strategically actionable for executive decision-making.
👉 Read Bishop Fox's webcast analysis of red team readiness and offensive security coverage →
Red team coverage: what practitioners need to act on?
Explore further
Risk-aligned offensive security is the dividing line between noise and value. A red team that is not tied to business risk, threat intelligence, and crown-jewel assets becomes an expensive exercise in reporting. Bishop Fox’s framing reinforces a basic governance truth: security testing must answer what an attacker can reach, not just what the scanner found. For identity programmes, that means privileged paths, secrets, and access reuse must be in scope. The practitioner takeaway is to align offensive testing to the assets that actually change loss exposure.
A question worth separating out:
Q: How do you know if red team and blue team exercises are actually improving resilience?
A: You know they are working when findings consistently reduce the time needed to detect, investigate, and contain realistic attack paths. If the same exposure patterns keep reappearing, or if the response team cannot act before the chain progresses, the exercise is producing evidence but not resilience.
👉 Read our full editorial: Red team coverage that changes risk decisions, not just compliance