BAS vs Red Team: how attack simulation is a game-changer.
Let there be no misunderstanding: this is not an argument against Red Teams – quite the contrary. We have several partners who are excellent Red Teamers and with whom we work particularly well. Red Team exercises remain the gold standard for confronting organisations with the reality of cyber risk. However, new methods for continuously strengthening SecOps through solutions such as Breach and Attack Simulation, are increasingly challenging traditional Red Team methods. But why?

BAS highlight the vulnerabilities that Red Teams exploit.
The two approaches have different aims.
The Red Team will adopt a «least effort» approach: spending as little time as possible on the targeted infrastructure, leaving as few traces as possible, getting straight to the point via the shortest route, limiting their movements, and so on.
By achieving its objective, it will highlight very specific and localised weaknesses, which will then be rectified. The BAS solution follows all possible paths, generating noise at various intensities with one main aim: to verify that what needs to be detected is indeed detected and is effectively handled by the cyber teams.
Along the way, the simulations produced by the BAS highlight numerous shortcomings – sometimes isolated, often overlooked and generally relatively simple to rectify. Here are a few very specific examples:
Regarding detection:
Regarding the reaction:
BAS are throwing a spanner in the works for the Red Teams.
One of the benefits of Breach and Attack Simulation solutions is the training of defence teams (Blue Team). The more they are confronted with increasingly complex simulations, the more detection mechanisms will be optimised, the more effective the defenders’ processes and reflexes will become, and the faster and more accurate investigations will be.
In short, BAS will not replace Red Teams, but will push them to improve.
BAS = panoramic photo and Red Team = photo taken with 24x zoom.
A well-run Red Team is one that goes undetected. And this is the conclusion that is drawn: «If a very skilled, highly organised attacker who takes their time sets their sights on you, they will eventually get the better of you.».
A strong message, but one that is becoming less and less heard by senior management and auditors. Repeated for years, this message has been heard and taken on board. The proof: cyber budgets are growing every year and the technological building blocks are piling up.
The question now is what the actual, overall effectiveness of these measures and investments is. As the Red Team focuses on a specific, well-defined path, it cannot provide this overall picture. The BAS, with its more «comprehensive» approach, offers an answer to this new question.
To measure, you need an accurate ruler.
The concepts of measurement and ranking are playing an increasingly important role in assessing cyber performance within organisations.
To measure progress in cyber maturity, a baseline framework is required to serve as a benchmark. In IT, such comparisons are based on precise technical criteria and actions that can be replicated exactly. One must compare like with like.
Let’s consider a real-life example:
During a simulated attack, the SOC fails to detect the three persistence tactics executed automatically by the BAS. Upon analysis, it becomes clear that the detection scenario is not configured correctly. These things happen; the MSSP rectifies the issue. In a second test a few weeks later, the BAS re-enacts exactly the same technical event (traffic flow, source, target, time, sequence, etc.). This time, the scenario triggers. Bingo! The scenario is then automatically retested on a regular basis. This is done to verify that there is no regression, for the purposes of ongoing monitoring and to ensure continued compliance.
To measure, you need an accurate ruler.
If there’s one piece of advice to take away: if you need to deploy a Red Team, do so in environments where your BAS solutions tell you that you’re secure.
It is in precisely these contexts and environments that the human touch of a Red Team will deliver the most valuable results.
And in that sense, BAS and Red Team are definitely complementary and will remain so for a long time to come.