What is your ‘real’ security posture?

Issue 6 2025 Editor's Choice, Information Security, Infrastructure, AI & Data Analytics

Many businesses operate under the illusion that their security controls, policies, and incident response plans will hold firm when tested by the real deal – cybercriminals. Operating a tick-box system of thinking, believing that ticking compliance frameworks, passing penetration tests, and completing security awareness training annually, does not mean you are safe.


Christo Coetzer

On the contrary, it can also mean you have become the CEO/COO/or CTO, etc., of Never-Never land, nurturing a comforting fantasy. The last thing you want to happen is that, when the bad guys strike – and today they are increasingly sophisticated - you discover catastrophically that your defences are little more than a misconception.

Red teaming

The Only Way to Know If You are Truly Defensible. The disconnect between perceived and actual security posture is precisely why red teaming has emerged as an indispensable component of mature cybersecurity programmes. Unlike traditional security assessments that validate the existence of controls; red teaming reveals whether those controls actually work when facing determined, adaptive adversaries.

Red teaming goes beyond penetration testing. In a nutshell, penetration testing identifies technical vulnerabilities within a defined scope and timeframe, whereas red teaming simulates real-world adversarial campaigns. A red team operates like genuine threat actors, employing social engineering, physical infiltration, supply chain compromise, and advanced persistent threat techniques to achieve specific objectives, whether that is exfiltrating sensitive data, compromising critical systems, or demonstrating the ability to cause operational disruption.

The fundamental difference between the two lies in the approach. Penetration testers announce their presence through scope agreements and rules of engagement, which in turn constrain activities. Red teams, conversely, operate under the radar, testing not only technical controls, but also detection capabilities, incident response procedures, and the human element that so often represents the weakest link in security chains.

Facing the truth about your defences

Most organisations invest heavily in preventive controls, such as firewalls, endpoint protection, identity management systems, and data loss prevention tools. These controls create a sense of security, reinforced by quarterly vulnerability scans showing declining numbers of high-severity findings.

However, prevention-focused security operates on a fundamentally flawed assumption; that you can eliminate all attack vectors. Red teaming exposes this approach as fallacious. Time and again, red team engagements demonstrate that determined adversaries will find ways through even robust preventative controls. They might phish credentials from an employee working remotely on an unsecured home network. They might exploit a zero-day vulnerability in a third-party application that your scanners cannot detect. They may even brazenly walk into your building carrying a USB device and a convincing story.

What red teaming truly tests is not whether you can prevent every attack (which is not possible), but whether you can detect and respond to attacks in progress before they achieve critical objectives. This shift from prevention to detection and response represents the maturation of cybersecurity thinking, acknowledging that breaches are inevitable, while focusing on minimising their impact.

Testing your detection and response capabilities

Your security operations centre claims 24/7 monitoring. Your incident response plan outlines clear escalation procedures. Your threat intelligence feeds provide indicators of compromise, but do these capabilities actually function when faced with sophisticated adversaries using tactics specifically designed to evade detection?

Red teaming answers this question definitively. A skilled red team will employ living-off-the-land techniques, using legitimate system tools and processes to avoid triggering alerts. They will move laterally through your network at a pace that mimics normal user behaviour. They will exfiltrate data in volumes and patterns designed to blend with legitimate business traffic.

When your security operations team fail to detect these activities – which they often do – the resulting report provides invaluable insights. Perhaps your detection rules focus too heavily on known attack patterns, while missing novel techniques. Perhaps your analysts are overwhelmed by alert volumes and miss critical signals. Perhaps gaps in lateral movement detection exist because internal network traffic receives less scrutiny than perimeter activity.

These failures should not be viewed as embarrassing, but rather as an opportunity for improvement. Better to discover these gaps through controlled red team exercises than through incident responses to actual breaches where the consequences are measured in regulatory fines, reputational damage, and operational disruption.

Be sure to check out the second article in this two-part series, where Christo Coetzer will explore the human element of cybersecurity weaknesses in your business. The article is at www.securitysa.com/26131r


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Balancing secure access control and fire safety
Editor's Choice Access Control & Identity Management Fire & Safety
In modern building management, few topics create as much tension as the intersection between security access control and fire evacuation safety. Nichola Allen of G2 Fire sheds light on this delicate balance.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...
Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
From drone market growth to application-level commercialisation
IoT & Automation Infrastructure
After years of pilot projects and technology validation, the question for the market is shifting from whether drones can fly safely and collect data, to where they can deliver repeatable operational value at scale.

Read more...
AI-enabled NVR for Milestone XProtect
Surveillance Infrastructure Products & Solutions
As surveillance environments continue to grow in scale and complexity, organisations need infrastructure that is easy to deploy, simple to manage, and ready for AI-driven workloads.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.