What is your ‘real’ security posture?

Issue 6 2025 Editor's Choice, Information Security, Infrastructure, AI & Data Analytics

Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by the real deal – cybercriminals. Operating a tick-box system of thinking, believing that ticking compliance frameworks, passing penetration tests, and completing security awareness training annually, does not mean you are safe.


Christo Coetzer

On the contrary, it can also mean you have become the CEO/COO/or CTO, etc., of Never-Never land, nurturing a comforting fantasy. The last thing you want to happen is that, when the bad guys strike – and today they are increasingly sophisticated - you discover catastrophically that your defences are little more than a misconception.

Red teaming

The Only Way to Know If You are Truly Defensible. The disconnect between perceived and actual security posture is precisely why red teaming has emerged as an indispensable component of mature cybersecurity programmes. Unlike traditional security assessments that validate the existence of controls; red teaming reveals whether those controls actually work when facing determined, adaptive adversaries.

Red teaming goes beyond penetration testing. In a nutshell, penetration testing identifies technical vulnerabilities within a defined scope and timeframe, whereas red teaming simulates real-world adversarial campaigns. A red team operates like genuine threat actors, employing social engineering, physical infiltration, supply chain compromise, and advanced persistent threat techniques to achieve specific objectives, whether that is exfiltrating sensitive data, compromising critical systems, or demonstrating the ability to cause operational disruption.

The fundamental difference between the two lies in the approach. Penetration testers announce their presence through scope agreements and rules of engagement, which in turn constrain activities. Red teams, conversely, operate under the radar, testing not only technical controls, but also detection capabilities, incident response procedures, and the human element that so often represents the weakest link in security chains.

Facing the truth about your defences

Most organisations invest heavily in preventive controls, such as firewalls, endpoint protection, identity management systems, and data loss prevention tools. These controls create a sense of security, reinforced by quarterly vulnerability scans showing declining numbers of high-severity findings.

However, prevention-focused security operates on a fundamentally flawed assumption; that you can eliminate all attack vectors. Red teaming exposes this approach as fallacious. Time and again, red team engagements demonstrate that determined adversaries will find ways through even robust preventative controls. They might phish credentials from an employee working remotely on an unsecured home network. They might exploit a zero-day vulnerability in a third-party application that your scanners cannot detect. They may even brazenly walk into your building carrying a USB device and a convincing story.

What red teaming truly tests is not whether you can prevent every attack (which is not possible), but whether you can detect and respond to attacks in progress before they achieve critical objectives. This shift from prevention to detection and response represents the maturation of cybersecurity thinking, acknowledging that breaches are inevitable, while focusing on minimising their impact.

Testing your detection and response capabilities

Your security operations centre claims 24/7 monitoring. Your incident response plan outlines clear escalation procedures. Your threat intelligence feeds provide indicators of compromise, but do these capabilities actually function when faced with sophisticated adversaries using tactics specifically designed to evade detection?

Red teaming answers this question definitively. A skilled red team will employ living-off-the-land techniques, using legitimate system tools and processes to avoid triggering alerts. They will move laterally through your network at a pace that mimics normal user behaviour. They will exfiltrate data in volumes and patterns designed to blend with legitimate business traffic.

When your security operations team fail to detect these activities – which they often do – the resulting report provides invaluable insights. Perhaps your detection rules focus too heavily on known attack patterns, while missing novel techniques. Perhaps your analysts are overwhelmed by alert volumes and miss critical signals. Perhaps gaps in lateral movement detection exist because internal network traffic receives less scrutiny than perimeter activity.

These failures should not be viewed as embarrassing, but rather as an opportunity for improvement. Better to discover these gaps through controlled red team exercises than through incident responses to actual breaches where the consequences are measured in regulatory fines, reputational damage, and operational disruption.

Be sure to check out the second article in this two-part series, where Christo Coetzer will explore the human element of cybersecurity weaknesses in your business. The article is at www.securitysa.com/26131r


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Detect procurement fraud before losses escalate
Security Services & Risk Management News & Events Financial (Industry) Editor's Choice
Organisations need to move procurement fraud prevention closer to the point where suspicious activity occurs, rather than relying primarily on investigations after money has already been lost, according to SAS and FACTS Consulting.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Integrating the industry
News & Events Infrastructure
With private security, neighbourhood watches, CCTV, drones, control rooms and community safety networks expanding across the country, the next frontier may not be more technology, but connecting what already exists.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
BlueVision launches Fusion Cloud
BlueVision Information Security Products & Solutions
Most businesses have moved to the cloud, including Microsoft 365, Azure, AWS and more, and in doing so assume they're protected because they're using a reputable platform; however, the reality is somewhat different.

Read more...
Protect More with SecuVue
Secutel Technologies Surveillance AI & Data Analytics
Whether you are responsible for electronic key management, securing safes and containers, transport operations or high-value equipment, every asset represents an investment that deserves intelligent protection.

Read more...
Amplifying the value of CCTV systems with AI
IoT & Automation Surveillance Entertainment and Hospitality (Industry) Retail (Industry) AI & Data Analytics
Smart AI platforms enable retail and hospitality organisations to turn their existing CCTV investments into proactive security systems and smart retail ecosystems that boost customer service and ROI.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.