Red Teamers are some of the most intelligent, technical, and frankly scary people I have worked with in my entire career. I’ve been amazed at their motivation, ingenuity, and drive to meet their objectives. Regardless of this fact, one thing that has remained consistent across all my experiences is that many Security Leaders don’t know how to properly leverage Red Teams. It always leaves Red Teams struggling to justify their existence and forces them to rely on obtuse metrics. In this brief, I’m going to explain the 10x ROI you gain from Red Teams (mostly relevant to internal Red Teams) and their outcomes so you can understand how to handle them as a valuable people asset.
the value of Red Teams
Red Teams have an uncanny ability to provide an unbiased perspective on how well your security program is performing. From my experience, they can do this across many verticals, but let me talk about a few to outline their value and support the pure math to show you the ROI. Many of the values cannot be measured, but I will mention them anyway so you can understand my point about gaining far greater than 10x returns.
attack path discovery
Red Teams, during their exercises, discover attack paths, which are a series of steps that, when combined, can lead to the compromise of your organization’s most valuable assets. I call this “demonstrated risk” because after the report is delivered, the risk remains exposed until action is taken to break the specific attack chain (chains can be reconstructed with different steps, but that’s a topic for a different brief). From my perspective, remediating attack chains alone provides huge value to an organization. From a risk-prioritization perspective, the demonstrated risk is much greater than the “theoretical risk,” which I discuss in my brief, A Red Team view of attack surfaces.
Measurement of real world response
In a sea of security vendor messaging, security community opinions, and expensive tools, there exists a reality for your organization. Can you defend against real-world attacks that target your most valuable assets? When questions like this arise, it’s plain to me that you should test this long before you truly need the answer. But for some reason, organizations get lost in the security echo chamber and forget to answer this question. If you want to score goals (you will now be unwillingly exposed to my hockey references), you practice scoring goals, not theorizing about how you might do such a thing. If you want to know how well you will defend against an advanced attack, simulate one and measure the response.
Systemic issue identification
If you have the luxury of having an in-house Red Team after a few years, they will have carried out multiple Red and Purple Team operations. During this pursuit, they will start to learn your environment and organization very well (in many cases, better than you do). A good internal Red Team will be able to identify not just 1-off problems but, at a systemic level, what is going wrong. For example, they may notice that developers repeatedly deploy a system in a certain configuration (or lack thereof) from their CI/CD pipeline, leaving their entire fleet of servers vulnerable. This type of pattern recognition becomes common for Red Teamers after performing exercises for a company for longer than 1-2 years, and especially if you stay in the same industry (I’ve Red Teamed software companies my entire career). Remediating these patterns is beyond the scope of Red Teaming, but if done, it is invaluable.
the cost of Red Teams
The cost of Red Teams can vary, of course, but I’m going to use round numbers to keep things simple. The average Red Team consists of 2-4 people (although I’ve been on teams of 8-12). Let’s just say each of them costs $220,000 to keep it simple. The cost ranges greatly, but I think this number is a good middle ground for our calculation.
4 Red Teamers x $220,000 each = $880,000
To account for hardware, infrastructure, and software, let’s go nuts and say they spend $100,000/year as well, which is high, but I don’t want to undermine my later math. I’ll group this under a category called capabilities. Capabilities are the tools, services, and infrastructure required for a Red Team to exist and be an effective team.
4 Red Teamers $880,000 + Capabilities $100,000 = $980,000
It may seem like a hefty investment (and you can start with 2 Red Teamers), but come on, many companies spend far more on security software that does almost nothing…
what to avoid with red teams
Now let’s talk about how to undermine your investment before we get into the full ROI picture. Red Teamers require time and focus to build capabilities. Contrary to what hacker movies suggest, you can’t just bang on a keyboard and hack anything based on some innate computer skills. It takes time to build tools (what works today can trigger alerts tomorrow), to build a team with varied skill sets, and to develop a deep understanding of the target environment. For me, this is the most misunderstood part of Red Teaming. It can be tempting for security leadership to treat us as another security engineering team or to have us join so many meetings that we implicitly develop a bias detrimental to our outcomes.
The second big mistake I’ve seen is forcing the Red Team to fit into the organization’s goals and metrics. Red Teams are meant to provide an unbiased opinion of a security program, not to be measured by the security program itself. That defeats the entire purpose of having a Red Team. I’ve seen Red Teams forced into metrics such as vulnerability counts and number of operations, which diminishes the value of having a Red Team. Leverage the Red Team for their unique ability to measure the investment you have made in security and its effectiveness in stopping real-world attacks. Do this correctly, and the ROI will pay for the Red Team multiple times.
maximizing your investment
Now let’s get into the math I promised. In 2026, the cost of a data breach in the US rose to $10.22 million, as I stated in my previous brief, A Red Team view of attack surfaces: Public. In reality, that’s just the average, and larger breaches have ranged from $50-$100 million (based on the final reported costs of large data breaches). With the Red Team discovering attack paths if they were to remediate just one of them and avoid such a breach (Multiple are discovered in one year), the cost savings would immediately 10x the ROI. That’s before even taking into consideration the defensive improvement that may not only help responders minimize impact in such an incident but also improve detection organization-wide. Add the fact that Red Teams will find systemic issues, giving you time to remediate them and saving you immeasurable future response time.
Average cost of a single breach in the US $10,220,000 % $980,000 = 10.42 ROI
That’s only for the potential risk reduction in avoiding a single breach with money to spare. Keep in mind that Red Teams also provide an invaluable measure of an organization’s ability to defend against real-world attacks, help you shift money away from ineffective tools, and can reduce risk 10x larger than the size of the average data breach in a single exercise. From a pure-numbers perspective, if leveraged correctly, Red Teams can 10x (and in some cases 100x) your Return on Investment.