That’s Not Red Teaming!

Over a decade ago, I attended my first conference with the title Red Teamer. I was waiting in line with a coworker who was a bit newer to Red Teaming but still brought valuable experience to the team. Momentarily, I was distracted by another friend when my coworker started getting interrogated by another conference attendee simply because he had said, “I work on a Red Team.” The fellow attendee insisted that the way he described his job was not, in fact, Red Teaming. I stepped in to defend my coworker, who was clearly uncomfortable. I remember that moment distinctly and can’t help but wonder why it was even necessary.

Over the years, I’ve seen this online and in person, and I’ve even experienced it myself after publishing briefs. There is never any direct feedback from the person, just a smug sense of accomplishment for pointing out that it didn’t fit their definition of Red Teaming. I am fully aware that some internal Red Teams blur the line in their ability to be completely unbiased. In the pursuit of being a Red Teamer and employee of the company, they end up delivering on metrics that don’t make sense and do, in fact, diminish the outcome. I discuss this in my brief, The 10x ROI of Red Teams. I will unpack these contradictory roles and their impact on internal Red Teams in a future brief.

“There is no ‘right way’ to red team” — p. 215

Bryce G. Hoffman (2017)

Red Teaming: How Your Business Can Conquer the Competition by Challenging Everything

Now I’m going to surprise and baffle some people with this statement: Red Teaming is not just a specific cybersecurity exercise. It’s a philosophy and way of thinking where you challenge assumptions about any topic. Although Red Team thinking can be used in cybersecurity, it’s not exclusive to our field. I’ve read every word I can find on Red Teaming, including its history, books, and articles, and none of it supports the idea that its execution has a specific definition; in fact, the opposite is true. To further support this, some of the best books about Red Teaming aren’t even about the cybersecurity aspects:

I could rant about this all day, but I won’t because none of it would be better evidence than the 3 books I referenced. Bryce G. Hoffman even states in his book, “There is no ‘right way’ to red team” (p. 215). My point, however, is that we should stop the senseless arguments about the right and wrong way to do Red Teaming. Ironically, to achieve this, we also need to recognize our own biases in how we think about this topic. Let’s instead focus on the quality of the exercises we perform. If we waste time bickering over the definition, we may drive away some amazing Red Team thinkers and diminish our overall ability to deliver value.

Discover more from Red Team Brief

Subscribe now to keep reading and get access to the full archive.

Continue reading