GetPentest

Red team assessment in Canada

A red team exercise answers a different question from a penetration test. It is not a bigger pentest, it is not better value, and for most Canadian companies buying one is a way of paying six figures to learn something a $15,000 test would have told you.

Last reviewed 2026-08-31Written by Jacob Masse, TrazTech Inc.

A red team assessment in Canada costs between $50,000 and $150,000 CAD and runs four to twelve weeks. It buys the answer to one question: if a capable attacker went after this company for a month, would anybody notice and would anybody stop them. A penetration test answers a different question, which is what is wrong with this system, and it costs a fifth as much because finding flaws is faster than emulating an adversary.

$50,000 to $150,000 Canadian red team engagement, CAD

4 to 12 weeks Typical duration, excluding scenario design

$10,000 to $30,000 What the same money buys as an application test

The difference, stated once and plainly

A penetration test measures the systems. A red team assessment measures the people and the tooling that are supposed to catch someone attacking those systems. Everything else follows from that.

Penetration test
Scoped by asset. Your team knows it is happening. Coverage is the goal, so the tester tells you every weakness found in the agreed scope, and the report is a list you can work through.
Red team assessment
Scoped by objective. Almost nobody internally knows. Stealth is the goal, so the team takes one route to the objective and deliberately leaves other weaknesses untouched. The report is a narrative and a timeline, not a list.
Purple team exercise
Same techniques, run openly and in the room with your defenders, one technique at a time, checking whether each one alerts. Cheaper than a red team, faster, and better at improving detection because the feedback loop is minutes rather than weeks.
Assumed breach test
Starts the tester inside with a standard user account or a foothold on a laptop. It is a penetration test, not a red team, but it answers the question most companies actually have about lateral movement.
Red team against penetration test, Canadian market, 2026
DimensionPenetration testRed team assessment
Question answeredWhat is wrong with this systemWould we detect and stop an attacker
ScopeNamed assets and URLsA named objective, most routes permitted
Who knowsEngineering, support, sometimes support deskTwo or three named people
FindingsAll of them, rankedThe path taken, plus what defence missed
Typical duration5 to 20 tester days4 to 12 weeks
Social engineeringExcluded unless bought separatelyUsually central to it
Physical intrusionNoSometimes, if the objective needs it
Accepted as audit evidenceYes, routinelyYes, but it is not what the auditor asked for
Cost, CAD$6,000 to $40,000$50,000 to $150,000

You need something for it to measure

Red teaming is over-sold in Canada, on a prerequisite vendors rarely raise. A red team measures detection and response. If nobody is watching alerts outside business hours, the exercise will succeed on day two, the report will say so, and you will have spent $70,000 CAD to learn something your own security lead could have told you for free.

  1. Somebody is paid to watch alerts, either your own staff or a managed detection provider under contract with a response time in it.
  2. Endpoint detection is deployed across the fleet, not on the servers only.
  3. You have an incident response plan that has been used at least once, in a real event or a tabletop.
  4. You have already had penetration tests, and the findings from them are closed rather than filed.
  5. Someone senior has agreed in advance what happens if the team reaches the objective. That is a bad moment to invent a policy.

Miss the first four and the correct purchase is an internal network test on an assumed breach basis, which costs $12,000 to $35,000 CAD and finds the same lateral movement paths with none of the theatre. Miss only the third and a purple team exercise gets you further per dollar.

What to ask before you buy one

Red team engagements are the most interesting work in this industry and the firms that do them are keen to sell them. That enthusiasm biases them toward telling a buyer they are ready when they are not. Ask the firm what they expect the exercise to conclude. A firm that says "we will probably get in inside a week and the finding will be that you have no detection coverage" is worth hiring, and is also telling you to buy something else first.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

What the engagement actually contains

Scenario design comes first, and it is a week or two of work before anything technical happens. A credible engagement starts from threat intelligence about who realistically targets your sector, then writes an objective in business terms: reach the payment approval system, exfiltrate a copy of the customer database, obtain the ability to push code to production. Vague objectives such as "get domain admin" produce vague reports.

Then comes reconnaissance, initial access, and the slow part. Initial access in a Canadian engagement is usually phishing or a password spray against an exposed service, occasionally a physical visit to a reception desk. After that the team moves toward the objective while trying not to trip anything. That is what makes it slow, and therefore expensive. Every step is logged with a timestamp so it can be laid against your own alerting afterwards.

The deliverable is the part that differs most from a penetration test. You should receive a narrative timeline, a list of every action taken with the time it happened, a comparison against what your detection tooling recorded, and a set of detection gaps written as engineering work rather than as findings. If a firm proposes to deliver a red team report in the same template as a penetration test report, they are selling a long penetration test.

Whether it satisfies an auditor

It usually does, and it is usually the wrong way to spend the budget. A SOC 2 or ISO 27001 auditor asking for evidence of technical testing will accept a red team report, but they will then ask for coverage of the systems in your scope statement, and a red team deliberately does not provide that. The standard outcome is that you buy a red team and a penetration test in the same year. What each framework actually asks for is on SOC 2 penetration testing and ISO 27001 penetration testing, and PCI DSS is prescriptive enough that a red team never substitutes for the required tests.

Regulated financial institutions are the exception. Where a supervisor or a large banking customer expects intelligence-led testing against a published scheme, the scheme names the shape of the exercise and you follow it rather than designing your own. That requirement arrives in writing and is not ambiguous.

What moves the price

Red team cost drivers, CAD
DriverEffect on priceWhy
Scenario design from threat intelligenceAdd $8,000 to $20,000A week or two of research before any testing
Physical intrusion componentAdd $10,000 to $25,000Travel, two operators, and legal preparation
Custom tooling to evade your specific stackAdd $10,000 to $30,000Development time, and it is thrown away afterwards
Purple team replay after the exerciseAdd $8,000 to $15,000Worth every dollar. This is where detection improves
Longer window for stealthRoughly linearSlower is quieter, and you are buying operator weeks
Scenario-led engagement with physical and purple replay$90,000 to $150,000Upper end of the Canadian market

Those are the same day rates under every quote in this market, and the arithmetic is on penetration testing cost in Canada. A red team is expensive because it is many operator weeks, not because the rate is different.

Rules of engagement, which matter more here

Because almost nobody internally knows the exercise is running, the paperwork does more work than in a normal test. Three things need to exist before anything starts. An authorisation letter, signed by an officer of the company, that an operator can produce if a security guard or a police officer detains them. A named escalation contact who is awake and reachable at any hour and can call the exercise off. And a written rule about what happens if the team finds a real intruder already inside, which happens often enough that it should not be improvised.

Where the exercise touches personal information, the same accountability rules apply as in any test: under PIPEDA, and under Law 25 in Quebec or PIPA in British Columbia and Alberta, the information stays your responsibility after it reaches the testing firm. Say in the contract what may be copied, where it is held and when it is destroyed. PIPEDA compliance covers the transfer rules in more detail.

Work out whether you are ready for one

Tell us what detection you have in place and what you are trying to prove, and the scope goes to Canadian firms that run these properly.

Get matched

Common questions

Is a red team assessment just a bigger penetration test?

No. A penetration test aims for coverage and tells you everything it finds in scope. A red team aims for one objective and stays quiet, which means it deliberately walks past weaknesses without reporting them. Buying a red team when you wanted coverage produces a thin list of findings and a frustrated engineering team.

How much does a red team cost in Canada?

Between $50,000 and $150,000 CAD for a scenario-led engagement of four to twelve weeks. Below about $50,000 the engagement is short enough that stealth is not really being attempted, and what you are buying is an assumed breach penetration test with a more exciting name on the invoice.

Should we tell our security team it is happening?

No, and that is the point. Two or three named people know: usually the executive who authorised it, the head of security, and one technical contact who can stop the exercise. Everyone else responds as they would to a real event, which is the measurement you are paying for. Tell them afterwards, quickly, and frame the debrief as a test of the tooling rather than of the individuals.

What is a purple team exercise and is it cheaper?

Yes, usually $15,000 to $40,000 CAD. Your defenders and the offensive team sit together and work through techniques one at a time, checking whether each one produces an alert and tuning the rule when it does not. It improves detection faster than a red team because the feedback arrives in minutes. A red team measures where you are, a purple team moves you.

Will our auditor accept a red team report instead of a pentest?

Usually yes as evidence that testing happens, but they will still ask about coverage of the systems in your scope statement, and a red team report cannot answer that. Plan on both in the same year, or buy the penetration test first and the red team when detection is worth measuring. What happens afterwards matters more either way, which is why remediation verification is the evidence auditors chase hardest.