Red team services: published prices and what to buy first
By The PenTest Index · Prices and terms checked October 10, 2026
Red team services are goal-based attack exercises: a hired team tries to reach something you care about, such as customer data, while your defenders try to catch them. Buy one only if someone is watching for attacks and you have had a recent penetration test. Two UK firms publish prices from £15,000. The US firms we checked require a scoped quote for the exercise total; Mandiant also publishes a UK public-sector hourly list rate.
Most people who are told to "get a red team" need one of five different things. The table below sorts that out first. After it you will find every published price we could confirm, two places where a seller's own page disagrees with itself, and a brief you can copy and send.
Which red team services fit the question you need answered?
Pick the exercise by the question you want answered, not by the label on the proposal. Sellers use these names loosely, so match on what the work does.
| The question you need answered | Ask for | Are defenders told? | What you get | What it will not tell you |
|---|---|---|---|---|
| Where are the weak spots in this app, API or network? | A penetration test (pentest): a scoped hunt for weaknesses in named systems | Usually yes | A list of findings and fixes | Whether your team would notice a real attack |
| Could an outside attacker reach our prize without being caught? | A red team exercise that starts from outside | No, apart from a few people in charge | The attack story, and what defenders caught and missed | Every weakness you have. The team follows attack paths toward the goal |
| If one laptop or login is stolen, how far can they get? | An assumed-breach exercise: a red team that starts with access you hand over | Often no | The path from that foothold to the prize, and the response to it | Whether an attacker could have got that foothold alone |
| Do our alerts work, and can you help us fix them? | A purple team exercise: attackers and defenders working side by side | Yes | Tested and tuned detections | How your team performs without coaching |
| Our regulator told us to run a threat-led test | A threat-led penetration test under the regulator's own scheme | No | Evidence in the regulator's format | Anything outside that scheme's scope |
Here is the plain version. A pentest checks every door and window for a weak lock. A red team picks one prize inside the building and tries to carry it out without the guards noticing. Both are useful. They answer different questions.
One more branch: "AI red teaming" means testing how an AI model or chatbot behaves under pressure. It is a separate service. Bishop Fox and Precursor Security both say so on their own pages, and it is not what this page covers.
For the full comparison, see red teaming vs pentesting. If the first row is your question, go straight to choosing the type of penetration test.
Outside start or assumed breach?
An outside start pays the team to get in. An assumed-breach start skips that step and spends the whole budget on what happens next.
Neither is more "real." Getting in can take weeks, and a good phishing email works on almost any company sooner or later. If your biggest worry is what an attacker does once inside, handing over one ordinary login is a fair trade. If your worry is the front door, pay for the outside start. Just make sure every firm quotes the same starting point, or their prices cannot be compared.
Should your defenders know?
Keep it quiet if you want to measure how your team responds on a normal day. Tell them if you want to improve specific alerts. Those are two different tests, so ask for them as two separate phases.
A quiet exercise still needs a small "control group": a few people on your side who know the test is running and can stop it.
A recent public case shows why the split matters. In an advisory released August 25, 2026, the US cybersecurity agency CISA described two red team assessments it ran at the same time. At one organization the team went undetected. At the other, defenders "quickly detected the initial compromise and quarantined the affected systems," so the team "moved to an assume breach model" and was given access to carry on (CISA advisory AA26-237A, read October 10, 2026). Our reading: the second organization got two results, a win at the front door and a separate result for what happened after. Your report should keep them apart the same way.
Are you ready for a red team?
You are ready when there is something to measure. That means four things: someone watches for attacks, you have had a recent pentest and fixed the serious findings, you can name the prize, and leadership and legal will sign off.
| Check | If the answer is no |
|---|---|
| Someone monitors alerts, in-house or through an outside service (often called MDR, managed detection and response) | A red team mostly proves what you already know. Set up monitoring and buy a pentest first |
| You had a penetration test in the last 18 months and fixed the serious findings | The team will walk in through known holes. Buy the pentest first |
| You can name one thing an attacker must not reach | Not yet. Ask: what data would end a customer contract if stolen? What system stops revenue if it goes down? |
| Leadership and legal will approve a simulated attack | Not yet. Get that approval before you ask for quotes |
| A regulator requires a threat-led test | Different route. See the regulator section below before you call a seller |
This is our rule of thumb, and the sellers say much the same. Precursor Security lists regular penetration testing, security monitoring and an incident response plan as prerequisites, and tells buyers without them to "start with penetration testing." Bishop Fox says red teaming is "best suited for organizations with mature security programs." TrustedSec's readiness list includes "at least one penetration test completed in the past 18 months."
Company size is not on the list. A 60-person firm with monitoring and a clear prize can get real value. A 2,000-person firm with no one watching the alerts cannot.
If a customer asked you for a "red team" and you are not sure they meant it, send them one question: "Do you need a penetration test report on our product, or an exercise that tests our detection and response?" Many mean the first.
If you answered no to monitoring or a recent pentest, start there. Tell our tool what needs testing and it gives you a scope checklist to send to the providers you choose. It is free, needs no email or sign-up, and sends nothing to providers.
How much do red team services cost?
Two UK firms publish a starting price of £15,000 for a red team exercise. The four US firms we checked show no price on their red team pages, and one advertised $5,999 figure needs a question before you rely on it.
All figures below are the firms' own published numbers, in the currency they publish, checked October 10, 2026. They are indicative prices, not quotes for your scope and not a market average.
| Firm | Published price | Stated scope and length | What the number leaves open |
|---|---|---|---|
| EJN Labs (UK) | Focused: £15,000–£35,000. Full adversary simulation: £35,000–£75,000. Threat-intelligence-led: £75,000+ | Focused: 1–2 attack vectors, 2–3 weeks. Full: multi-vector, 3–5 weeks. Threat-intelligence-led: 5–6 weeks | Labeled "indicative ranges." The fixed price comes after a scoping call. The page lists phishing with physical pretext as a separate "Red-Team Adjunct" from £15,000, so ask what the red team price includes |
| Precursor Security (UK) | "From £15,000." A standard exercise for a 500–2,000 person organisation "averages £25,000." Extended, 4–6 weeks: £35,000–£50,000+. Work aligned to the UK's CBEST scheme: £40,000–£60,000 | See the conflict below | The page gives two different lengths for a standard exercise and two different top ends for the typical range |
| Astra | "Red Team assessment services for just $5,999" | Not stated | Team size, length and the methods included at this price are not stated. See the note below |
| Bishop Fox, NetSPI, TrustedSec (US) | None on the red team page we read | — | Quote required |
| Mandiant (Google Cloud) | None on its red team service page. Google's UK G-Cloud 15 list gives $650 or £480.88 per hour for Red Team Assessment | No engagement length in the price document | UK public-sector framework list rate, not an exercise total. Confirm applicable terms, hours and scope |
| CovertSwarm (UK) | Monthly subscription: custom price. Separate one-off engagement: from £1,725/$2,395 per day on its pricing page | Subscription: ongoing. One-off: scoped engagement | Monthly price, hours and minimum term. The one-off total depends on agreed days and scope |
Precursor's page disagrees with itself in two places. Its cost answer prices a "standard 2-4 week red team exercise" at an average of £25,000. Its duration answer says exercises "typically last 4-6 weeks minimum," and another line says "standard red team exercises run 4-6 weeks." Its comparison table gives a typical cost of £15,000–£60,000+, while its cost answer says £15,000 to £50,000+. None of this is sinister. It does mean you should ask: "Which length does the £25,000 figure cover?"
Astra's $5,999 matches the price of a different product. Astra's pricing page lists its Pentest Expert plan at $5,999 per year for one target. Its red team page uses the same figure but does not say what you get for it, and its own FAQ on that page says custom enterprise engagements "are quoted after scoping." We cannot tell from the published pages whether $5,999 buys a red team exercise or a pentest plan. Ask Astra in writing before you budget on that number.
What a price means in days
A price tells you little until you turn it into people and days. EJN Labs is the one firm that gives enough to try.
EJN says its consultants are priced at £1,100 to £1,400 per day, though it bills fixed prices and not day rates. Our arithmetic from those figures:
- £15,000 ÷ £1,400 is about 11 price-equivalent consultant-days. £15,000 ÷ £1,100 is about 14.
- £35,000 ÷ £1,400 is 25 price-equivalent consultant-days. £35,000 ÷ £1,100 is about 32.
On a five-day working week, a "2–3 week" exercise is 10 to 15 working days. Those divisions give price-equivalent consultant-days, not confirmed staffing: EJN's fixed price also includes reporting and retests. The useful part is the question it gives you for any firm: how many people, for how many days each?
What sellers say the market charges
TrustedSec, which sells these services, says red team assessments for companies of 100 to 1,000 employees "typically cost $40,000–$80,000," and describes that as market data as of Q1 2025 (TrustedSec's cost page). That is a seller's view of the market, not TrustedSec's price list and not our measurement. It does suggest US quotes may start well above the UK published prices. Get a written quote before you assume either.
What moves the price
Six things, in rough order: how many goals, how many weeks, how many people, whether the team must get in from outside, whether phishing or physical entry is included, and how much debrief and follow-up you want. Research on which attackers target your industry adds cost too. EJN says its red team work includes "a 1–2 week threat-intelligence phase before active operations."
For ordinary pentest budgets, see our published penetration testing prices. Do not carry those numbers over to a red team.
Which red team firms should you look at?
Start with the firm whose published page already matches your starting point and your need for a price, then ask each one the same questions. No public page we read settles the whole purchase.
These seven are listed A to Z. This is not a ranking and not the whole market. We chose firms whose pages state something you can check. Everything in the table is what the firm says about itself on the page linked or in the sources below, read October 10, 2026. We have not bought or tested any of these services.
| Firm and offer | What its page says | Price published? | Ask before you sign |
|---|---|---|---|
| Bishop Fox — Red Teaming | Covert attacks to measure your defenders. You choose which tactics are in or out. Scenarios include ransomware and "trusted insider." Report includes an attack timeline with "defensive performance." Social engineering "can be incorporated" | No | Does "trusted insider" mean we hand over a login? How many people and days? |
| CovertSwarm — subscription red teaming | Ongoing attacks by "simple monthly subscription," using "digital, physical and social methods" | Subscription: custom price. Separate one-off: from £1,725/$2,395 per day | Monthly price, hours per month, minimum term, how to leave |
| EJN Labs — Red Teaming | "End-to-end adversary simulation: phishing, initial access, lateral movement, exfiltration." Says every engagement includes free retests of fixed findings with "no time limit"; third-party retests of vendor-controlled systems are excluded | Yes, from £15,000 | What does the focused tier include? Is the threat-intelligence phase inside the 2–3 weeks? |
| Mandiant (Google Cloud) — Red Team Assessment | Goals set around your risks, for example reaching payment or personal data. Separate technical and executive reports. Starts "with information about the environment or without" | UK G-Cloud 15 list: $650 or £480.88 per hour; no total on the service page | Can we start from supplied access? Is a debrief with our defenders included? |
| NetSPI — Red Team Operations | Three named routes: Assumed Breach, Black Box, and Threat Intelligence-Led. Calls its scenario-based testing a hybrid of pentesting and purple-team-style work | No | In the assumed-breach route, are defenders told? When does joint work begin? |
| Precursor Security — Red Team Operations | "Concealed from SOC" (your security operations team). Says a full purple team debrief is included in every operation. Lists a "re-test consultation" | Yes, from £15,000 | Which length does our price cover? What does the re-test consultation check, and when? |
| TrustedSec — Adversarial Attack Simulation | Uses "phishing, vishing, SMS, and physical breach techniques." Lists joint work with your defenders and an executive debrief as part of each engagement | No | Which human and physical methods are in our price? Which phase is quiet? |
Several of these firms say they hold CREST accreditation, an industry body's approval scheme. We report that as their statement. Check CREST's own list for the exact company and service before you rely on it.
Where to look first
- You want a published starting price and can use a UK firm: EJN Labs and Precursor Security. Confirm what is in and out.
- You want to start from handed-over access: NetSPI names an Assumed Breach route, Bishop Fox's methodology describes supplied access, and TrustedSec publishes supplied-credentials scenarios. Confirm the account, device and scope.
- You want phishing, phone and physical entry in the same exercise: TrustedSec and Precursor both list them. Confirm they are in your price.
- You want separate reports for engineers and executives: Mandiant lists both.
- You want pressure all year, not one project: CovertSwarm. Get the monthly price and minimum term in writing.
- Astra: treat as unresolved until it confirms what $5,999 covers.
Provider links on this page use ordinary URLs without referral codes. Money never decides who we list or in what order. See how we make money.
A worked check for one buyer
For this example buyer, the public pages point to NetSPI and Precursor Security as the first two quote requests. Neither is cleared yet. Here is how we got there.
Say you run security for a 150-person company. You use Microsoft 365, a finance app and an outside monitoring service. You had a pentest in the spring. Your question: if one ordinary employee login is stolen, can an attacker reach finance records, and will the monitoring service catch it? You set five must-haves. They are your choices for this purchase, not rules from any standard.
This is how we run a Purchase Check on this site: take the buyer's must-haves, hold each one against what a specific offer actually publishes, and mark what is supported, what is missing and what to ask.
| Your must-have | What the published pages establish | Question to send |
|---|---|---|
| Start from a login we supply | Supported starting-access options: NetSPI lists an Assumed Breach route; Bishop Fox's methodology expressly includes a supplied user account; TrustedSec's SSO scenario requires valid user credentials. Unresolved: the other four, and the exact low-privilege account, device and scope for this buyer | "Will you start from one low-privilege account we provide, with no paid work on getting in?" |
| Defenders are not told during the first phase | Supported: Bishop Fox ("covertly"), Precursor ("concealed from SOC"). Unresolved: the rest | "Who on our side will know, and at what point are defenders told?" |
| A debrief with our monitoring team is included | Supported: Precursor says it is in every operation. TrustedSec lists it as part of each engagement. Bishop Fox's methodology lists a Blue Team deep dive and behavior replay. Unresolved: the rest | "Is a session replaying the attack with our defenders in the price?" |
| A published price to budget from | Supported: EJN Labs and Precursor, both from £15,000, indicative. Published rates only: CovertSwarm's separate one-off engagement, from £1,725/$2,395 per day; Mandiant's UK G-Cloud 15 list, $650 or £480.88 per hour. Unresolved: their exercise totals and the rest | "What is the complete fixed price for this scope?" |
| A check of our fixes about 45 days after the report | Supported in general terms: EJN says free retests of fixed findings have no time limit; third-party retests of vendor-controlled systems are excluded. Unresolved: inclusion and availability of this buyer's check around day 45, Precursor's "re-test consultation," and the rest | "What exactly is rechecked after we fix things, by when must we ask, and does it cost extra?" |
No firm is supported on all five from public pages alone. NetSPI supports the starting point, which is the heart of this purchase; Bishop Fox and TrustedSec also publish supplied-access options. Precursor supports three of the five and publishes a price, but its starting point is unresolved. So those two go first, each with the questions for its gaps. If either answers "no" to a must-have, that offer is out for this buyer, however good the price.
Supported here means one condition is backed by one published sentence. It is not a judgment of the firm's quality.
View Precursor's red team page and prices
View EJN Labs' published red team prices
View Bishop Fox's red team service
View Mandiant's Red Team Assessment
View TrustedSec's red team service
View CovertSwarm's subscription red teaming
Already have a provider? Run its contract through the same five rows. If it already covers the exercise and the evidence you need, you may not need a new supplier at all.
What should your red team brief say?
Write down the question, the starting point, who is told, and the evidence you want. Then ask every firm to price that same job. A brief gives suppliers the same question, so their answers line up.
Here is a filled example for the 150-person company above. It is made up.
| Field | Example answer |
|---|---|
| The question | Can activity from one ordinary employee login reach finance records, and how does our monitoring service detect, escalate and contain it? |
| Starting point | One standard user account and one company laptop, handed over through a secure process we agree separately |
| Who is told | A control group of three people. Defenders are not told in phase one. Phase two is a joint replay with the monitoring service |
| In scope | Our Microsoft 365 tenant, the test laptop and the finance app. Exact targets listed before sign-off |
| Not allowed | No phishing, no physical entry, nothing destructive, no export of real customer data. Any change to a security control needs approval and gets recorded |
| Evidence we want | Attack timeline, whether the goal was reached, what defenders saw and did, and what help the testers were given |
| Dates | Final report by a date we name. The firm proposes start, testing window and debrief dates |
| Follow-up | A check of our fixes, requested about 45 days after the report. Price and deadline stated |
| Price | One complete figure: prep, testing, report, debrief, follow-up, travel and tax |
Now the blank version. Copy it, fill it in, and send the same text to every firm.
Red team quote brief
- The question and the goal. What we want to learn, and what counts as the goal being reached.
- Systems and owners. What is in scope, roughly how big, who owns it, and which third parties are involved.
- Starting point. Outside start, or the exact account, device and access level we will supply.
- If entry fails or is caught. Who can approve handing over access, and how the report will keep the two phases apart.
- Who is told. Who knows from day one, which phase is quiet, and when joint work with defenders begins.
- Methods allowed and banned. Phishing, phone calls, physical entry, changes to security controls, and anything off limits.
- Evidence and reader. What the report must show and who will read it.
- People and effort. How many people, their roles, and days of active work each.
- Dates. Preparation, testing window, report date and debrief.
- Follow-up. What is rechecked after fixes, by when we must ask, and the cost.
- Total price. Currency, what is included, required products or subscriptions, travel, tax, term and renewal.
- Open questions. Anything that would stop us buying.
This brief is a buying aid. It does not give anyone permission to test. Do not put passwords, keys or other secrets in it.
Prepared with The PenTest Index: https://thepentestindex.com/red-team-services/
When the proposals come back, line them up against the brief row by row. A lower price for a different starting point is not a saving. Our Quote Check covers the general money and contract questions; the red team rows are the ones in the brief above.
Run a Quote Check on a proposal
What should the report show?
Ask for a report that says what the testers tried, what they reached, and how your defenders reacted, with any help the testers were given written down.
A pentest report lists holes. A red team report should tell a story with times on it. Use this to check a sample before you sign.
| Ask to see | The question it answers | The catch to look for |
|---|---|---|
| Goal result and attack path | Did they reach the prize, and how? | Proof of access versus "could have" |
| Timeline of actions | What was tried, and when? | Stages that were skipped or handed over |
| What defenders did | What was detected, escalated and contained? | Missing logs, or activity defenders were warned about |
| Help given to the testers | Under what conditions did this result happen? | Accounts supplied, controls switched off, tools allowed through |
| Fixes, in order | What should we do first? | Advice versus fixes that were checked afterward |
Ask each firm: "Can you share a redacted sample report and show where these five things appear?" Mandiant lists separate technical and executive reports. Bishop Fox lists an attack timeline with defensive performance. Precursor lists an attack narrative and a chart of which techniques were detected. For the basics of any test report, see what to check in a penetration testing report.
How long does a red team engagement take?
Published lengths run from two weeks to about six weeks for a standard exercise, and far longer for regulator-led work. Treat any published length as a description, not a booking.
| Firm | Stated length | Note |
|---|---|---|
| EJN Labs | Focused 2–3 weeks. Full 3–5 weeks. Threat-intelligence-led 5–6 weeks | Also says red team work has a 1–2 week threat-intelligence phase before active operations |
| Precursor Security | "Standard red team exercises run 4-6 weeks" | Its cost answer prices a "standard 2-4 week" exercise. For work aligned to CBEST or TIBER-EU it gives 6–12 months end to end |
| Bishop Fox | "Active attack simulation over several weeks" | Plus planning, reporting and debrief |
| Others | Not stated on the page we read | Ask |
Three different things hide inside "how long." Get each in writing:
- Active effort. How many people work on it, and for how many days.
- Calendar window. The first and last day testing can happen.
- Report date. When the final report lands, and when the debrief is.
A six-week window with one person working part of it is a smaller purchase than a three-week window with two people working all of it.
Does a red team count for SOC 2, PCI DSS or a regulator?
Usually it is not what the request asks for. Read the exact words of the request, then check whether the exercise covers those systems and produces that evidence.
Customer and audit requests. Say a customer asks for a test of your product and its API, and you send a report from an exercise on your office network and logins. The report can be excellent and still miss the request, because the product was never tested. For what auditors and card-industry assessors ask for, see our pages on SOC 2 penetration testing and PCI penetration testing. Your auditor, assessor or customer decides what they accept. Ask before you buy.
EU financial firms. This is the one place we can point to a rule that requires something close to a red team. The EU's Digital Operational Resilience Act, Article 26, says financial entities identified by their authority "shall carry out at least every 3 years advanced testing by means of TLPT," short for threat-led penetration testing. The authority may change this frequency based on risk and operational circumstances. Each test must be "performed on live production systems" supporting critical or important functions. The authority identifies which entities must do this, and testers must be contracted in line with Article 27 (Regulation (EU) 2022/2554, original text read October 10, 2026). If that is you, your first call is to your authority, not to a seller.
Several sellers say they can deliver under these schemes. NetSPI says it supports threat-led testing "fully aligned with TIBER-EU standards." EJN Labs prices a "regulator-structured" tier at £75,000+. Precursor prices work aligned to the UK's CBEST scheme at £40,000–£60,000. Bishop Fox is careful on this point: it says red teaming "is not a compliance exercise." These are the firms' own statements. Whether a given firm may test under your scheme is for the scheme's authority to confirm.
Is a red team exercise safe and legal?
Get written permission from the people authorized to approve testing; it is safe only if the limits are agreed before anything starts.
Before testing begins, you and the firm should sign a document, often called rules of engagement. It names the exact targets, the methods allowed, what is off limits, who can stop the test, and how to reach them at 2 a.m. The brief on this page is not that document.
Three points that are specific to red teams:
- Third parties. Your cloud host, your monitoring service and your office landlord may each need to agree before their systems or premises are touched.
- People. Phishing and phone pretexts involve your staff. Decide with HR and legal how many people can be targeted and how they are told afterward. Precursor says it targets "10-20 individuals necessary for objective achievement, not the entire organisation."
- The quiet part. If defenders are not told, the control group must be able to tell a real attack from the test within minutes.
Ask every firm what its stop procedure is and how it records each action. See our page on penetration testing rules of engagement for what that document should contain.
Questions before you book
What if our defenders catch the testers early?
That is a good result. Write it down as one. A separately agreed phase with handed-over access can then answer a different question: what happens if the next attacker is not caught? That is what happened in the CISA case above. The report should show both results and never let the second erase the first.
Can a small company use red team services?
Yes, if it passes the readiness checks. Size alone does not decide it. A small firm will usually get more from a focused or assumed-breach exercise than from a long outside-start campaign, because the budget goes on the part it cares about.
What is red team as a service?
It is red teaming sold as an ongoing subscription instead of a single project. CovertSwarm sells it this way and describes monthly cycles. Before you sign, get the monthly price, the hours of human work each month, the minimum term and the exit terms in writing. A subscription is a way of paying. It does not tell you how much testing you get.
Is breach and attack simulation software the same thing?
No. That is software used to replay known attack steps against your controls on a schedule. It is useful for checking that an alert still fires. NetSPI draws a similar line on its own page between continuous checks of detection controls and red teaming, which it says tests "people and processes." Software does not adapt the way a human team with a goal does.
How we checked this page
We read each firm's own red team or pricing page on October 10, 2026 and recorded what it says. Every price is the firm's published figure. We sell no testing, we did not buy these services, and we did not rate anyone. Where a page was silent we wrote "not stated" and gave you the question to ask. Our method explains how we compare offers.
Seen a price or term that has changed? Send us the source and we will update the entry and its check date.
Sources
All checked October 10, 2026 unless noted.
- Astra, red team assessment services: https://www.getastra.com/services/red-team-assessment-services
- Astra, plans and pricing (Pentest Expert plan; checked October 7, 2026): https://www.getastra.com/pricing
- Bishop Fox, Red Teaming: https://bishopfox.com/services/red-teaming
- CISA, advisory AA26-237A, "A Tale of Two SOCs: Insights From Two Red Team Assessments," released August 25, 2026: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
- CovertSwarm, Red Teaming: https://www.covertswarm.com/services/red-teaming
- EJN Labs, UK penetration testing prices: https://ejnlabs.com/pricing/
- European Union, Regulation (EU) 2022/2554, Article 26: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022R2554
- Mandiant (Google Cloud), Red Team Assessment: https://cloud.google.com/security/consulting/mandiant-red-team
- NetSPI, Red Team Operations: https://www.netspi.com/netspi-ptaas/red-team-operations/
- Precursor Security, Red Team Operations: https://www.precursorsecurity.com/services/offensive-security/red-team-operations
- TrustedSec, Red Teaming: https://trustedsec.com/services/red-teaming
- TrustedSec, red team assessment cost: https://trustedsec.com/resources/business-resources/red-team-assessment-cost
- AttackIQ, Ready (expert-managed service): https://www.attackiq.com/products/ready/
- AttackIQ, original BAS-as-a-service announcement, March 30, 2023: https://www.attackiq.com/resources/press-release/attackiq-launches-breach-and-attack-simulation-as-a-service/
- Bishop Fox, Red Team Methodology, pages 3 and 10: https://assets.bishopfox.com/prod-1437/Documents/Methodologies/Bishop-Fox-Red-Team-Methodology.pdf
- CovertSwarm, pricing (subscription and separate one-off rate): https://www.covertswarm.com/pricing/
- Google Cloud, G-Cloud 15 security products pricing (UK public-sector framework hourly list rate): https://assets.applytosupply.digitalmarketplace.service.gov.uk/g-cloud-15/documents/720213/759625889116401-pricing-document-2026-01-29-2237.pdf
- NetSPI, realistic red team scenarios, July 15, 2025: https://www.netspi.com/blog/executive-blog/red-teaming/part-2-crafting-realistic-scenarios-for-red-teaming/
- TrustedSec, Assumed Breach scenarios, May 23, 2024: https://trustedsec.com/blog/assumed-breach-the-evolution-of-offensive-security-testing
- Crown Prosecution Service, Computer Misuse Act authorization guidance: https://www.cps.gov.uk/prosecution-guidance/computer-misuse-act
- NIST SP 800-115, sections 6.5–6.6 (documented authorization and legal review): https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf