Not all red team engagements are created equal. A threat-intelligence-led (TI-led) red team goes further than a standard adversary simulation by grounding the engagement in real, current threat intelligence specific to the target organisation and its sector. The red team does not simply test generic attack techniques — it replicates the tactics, techniques, and procedures (TTPs) of the threat actors most likely to target the organisation in the real world.
What makes a red team engagement threat-intelligence-led
A standard red team engagement is objective-based: reach a specific target, exfiltrate data, demonstrate domain compromise. The red team chooses whichever techniques are most effective based on their own experience and the target environment.
A TI-led engagement adds a layer of realism. Before the red team begins, a threat intelligence provider produces a detailed assessment of the threats facing the organisation. This assessment identifies:
- Which threat actors are most relevant — nation-state groups, organised crime, hacktivists, or insiders — based on the organisation’s sector, geography, and assets.
- What TTPs those actors use. Real-world campaigns attributed to those groups provide a playbook of specific techniques: initial access methods, malware families, lateral movement patterns, and exfiltration techniques.
- What the likely objectives would be. What would a real attacker target? Customer data, intellectual property, financial systems, operational technology?
The red team then builds its engagement plan around this intelligence. Instead of testing with arbitrary tools and techniques, they replicate the specific tradecraft of the identified threat actors. The result is an engagement that answers a much more specific question: “If APT group X targeted us tomorrow using the techniques they used against our sector last quarter, would we detect and stop them?”
Frameworks: TIBER, CBEST, and STAR
Several regulatory frameworks formalise the TI-led red teaming process. These are most common in the financial services sector, where regulators have recognised that traditional penetration testing alone is insufficient to test resilience against sophisticated adversaries.
TIBER-EU
The Threat Intelligence-Based Ethical Red Teaming framework was developed by the European Central Bank and adopted by central banks across the EU. It defines a structured process for conducting TI-led red team tests on entities within the financial sector.
Key features:
- A dedicated threat intelligence phase, conducted by an independent TI provider, produces a Targeted Threat Intelligence Report.
- The red team designs and executes the engagement based on the intelligence report.
- A white team (a small group within the target organisation who are aware of the test) manages the process while the broader organisation remains unaware.
- The engagement is followed by a purple team phase to address identified gaps.
- Results are shared with the relevant national authority (central bank or financial regulator).
CBEST
CBEST is the UK’s implementation of intelligence-led penetration testing, developed by the Bank of England for the financial services sector. It predates TIBER-EU and follows a similar structure:
- A threat intelligence phase identifies the most relevant threats to the institution.
- A red team simulates those threats against the institution’s critical functions.
- The engagement tests people, processes, and technology — not just technical controls.
- Results inform the institution’s remediation plan, which is reviewed by the regulator.
CBEST is typically required for systemically important financial institutions in the UK.
STAR
Simulated Targeted Attack and Response (STAR) is another variant used in some jurisdictions, following the same core principle: threat intelligence drives the red team’s approach, and results are assessed against the organisation’s critical functions and detection capabilities.
The three-phase structure
Regardless of the specific framework, TI-led red teaming follows a broadly consistent three-phase structure:
Phase 1: Threat intelligence. An independent TI provider assesses the threat landscape for the target organisation. The output is a report detailing the most relevant threat actors, their TTPs, and recommended attack scenarios for the red team to simulate.
Phase 2: Red team execution. The red team plans and executes the engagement based on the TI report. This is a full-scope adversary simulation: the red team uses the identified TTPs to attempt to compromise the organisation’s critical functions. The engagement window is typically measured in months.
Phase 3: Assessment and remediation. After the engagement, the results are reviewed with the organisation and (where applicable) the regulator. This phase often includes a purple team element, where the red and blue teams work together to address the detection and response gaps identified during the test.
Who needs TI-led red teaming
TI-led red teaming was developed for, and remains most common in, sectors with mature regulatory frameworks and high-value targets:
- Financial services. Banks, insurers, payment processors, and market infrastructure providers are the primary users, often mandated by regulators.
- Critical national infrastructure (CNI). Energy, telecommunications, transport, and water utilities are increasingly adopting TI-led approaches.
- Government and defence. Departments and agencies with nation-state threat exposure use TI-led testing to validate their resilience.
However, any organisation with a sophisticated threat landscape and mature security function can benefit. The key prerequisites are:
- A clear understanding of which threat actors are most relevant.
- Existing detection and response capabilities that are worth testing.
- The budget and appetite for a multi-month engagement.
- Willingness to act on the findings.
The value of realism
The fundamental value of TI-led red teaming is realism. A standard penetration test identifies vulnerabilities. A standard red team tests whether an organisation can be compromised. A TI-led red team tests whether an organisation can withstand the specific threats it actually faces.
This distinction matters when reporting to boards, regulators, and insurers. The ability to say “we tested our resilience against the specific threat actors targeting our sector, using their documented techniques, and here is what we found” carries significantly more weight than “we ran a penetration test and found some issues.”
For organisations subject to TIBER, CBEST, or equivalent frameworks, TI-led red teaming is not optional — it is a regulatory expectation. For others, it represents the gold standard for understanding and improving resilience against targeted attacks.