Red Team vs Penetration Testing: Which Does Your Malaysian Organisation Need?

Red teaming and penetration testing are both offensive security disciplines — but they answer fundamentally different questions. Penetration testing asks can an attacker exploit this specific vulnerability? Red teaming asks can an attacker achieve a real-world objective against our organisation, right now, without us knowing? For Malaysian organisations navigating compliance mandates from NACSA, Bank Negara Malaysia RMiT, and the PDPA, choosing the right engagement type is a strategic decision — not just a procurement one.
What is penetration testing?
A penetration test — commonly called a pentest — is a structured, scoped security assessment where certified testers attempt to identify and exploit vulnerabilities within an agreed boundary. Before the engagement begins, both parties sign rules of engagement defining exactly what systems can be tested, which techniques are permitted, and what the success criteria look like.
The scope is fixed. A web application pentest covers your web application. A network pentest covers defined IP ranges. An API security assessment covers documented endpoints. This structure makes penetration testing highly efficient for proving compliance, validating a specific control, or assessing a new system before go-live.
Common penetration testing types include:
- Web application penetration testing — testing for OWASP Top 10 vulnerabilities, authentication weaknesses, and business logic flaws in web apps and APIs
- Network penetration testing — assessing internal and external network perimeters, firewall rules, and lateral movement paths
- Mobile application penetration testing — reviewing Android and iOS apps for insecure data storage, weak cryptography, and API exposure
- Social engineering assessment — simulated phishing, vishing, and pretexting campaigns against employees
Simply Data conducts penetration testing across all these domains using ISCB-certified testers, following methodologies aligned with OWASP, PTES, and NIST SP 800-115. A structured report with exploited findings, risk ratings, and remediation recommendations is delivered at engagement close.
What is red teaming?
A red team engagement is an objective-based adversary simulation with no predefined scope or rules limiting attack technique. The red team — typically a small, multi-discipline group of offensive security specialists — is given a goal that mirrors a real threat actor’s objective: exfiltrate the customer database, compromise the CFO’s credentials, or gain persistent access to the OT network. Everything else is up to them.
Red teams operate exactly as sophisticated adversaries do. They conduct open-source intelligence (OSINT) gathering, craft targeted spear-phishing lures, attempt physical intrusion into offices, develop custom malware to evade endpoint detection, and exploit human trust alongside technical weaknesses. The engagement runs for weeks or months. The blue team — your internal SOC or security operations staff — is deliberately kept unaware. The measure of success is not a list of vulnerabilities found, but whether the objective was achieved and whether the blue team detected and responded effectively.
Red team operations are mapped to threat actor techniques catalogued in the MITRE ATT&CK framework, giving organisations a structured way to understand exactly which tactics, techniques, and procedures (TTPs) their defences can and cannot detect.
What is purple teaming?
Purple teaming bridges the gap between offensive simulation and defensive improvement. In a purple team exercise, the red team and blue team work collaboratively and transparently — the red team executes each attack technique while the blue team observes, attempts to detect it in real time, and tunes detection rules immediately when gaps are found.
Purple teaming is not a replacement for red teaming. It is a knowledge-transfer mechanism. Where a red team engagement reveals whether your defences work, a purple team exercise reveals why they fail and gives your team the hands-on training to fix it. Organisations with a mature SOC capability typically cycle between red team engagements (to test real-world stealth) and purple team exercises (to systematically improve coverage across the MITRE ATT&CK matrix).
Choosing the right engagement by organisational maturity
The most common mistake Malaysian organisations make is commissioning a red team engagement when they have not yet established foundational security hygiene. A red team against an organisation with unpatched systems, no EDR deployment, and no SOC will produce a report so long it becomes unactionable. The right engagement type matches your current security maturity.
Early maturity — start with penetration testing
If your organisation is deploying security controls for the first time, seeking ISO/IEC 27001 certification, or responding to a compliance requirement, a scoped penetration test is the correct starting point. It produces a prioritised list of technical vulnerabilities with clear remediation steps. It satisfies audit requirements. It gives your team a baseline to work from.
For organisations in the banking and financial services sector, BNM RMiT explicitly requires annual penetration testing of critical systems and internet-facing applications. A scoped pentest — conducted by a qualified, independent provider — is the primary mechanism for meeting this obligation.
Developing maturity — add specialised assessments
Once you have remediated findings from multiple pentest cycles and deployed core controls (patching programme, EDR, network segmentation, MFA), broaden your testing to cover specific risk areas. This is where specialised assessments add value: a dedicated web application penetration test for customer-facing portals, API security reviews for integration-heavy environments, or cloud configuration assessments for Azure and AWS workloads.
At this stage, social engineering assessments also become relevant. The 2023 CyberSecurity Malaysia annual report noted that phishing remained the top attack vector for Malaysian organisations — testing your employees’ resilience to targeted phishing campaigns is no longer optional for organisations handling personal data under PDPA or financial data under CMDF guidelines.
Advanced maturity — red team and purple team exercises
Red team engagements are appropriate when your organisation has:
- A functioning SOC or security operations capability with active monitoring
- Endpoint detection and response (EDR) deployed across the estate
- Completed at least two full pentest cycles with remediation verified
- An incident response plan that has been tabletop-tested
- Executive appetite to understand worst-case breach scenarios
Critical national information infrastructure (CNII) operators — defined under Malaysia’s National Cyber Security Policy and overseen by NACSA — are expected to demonstrate this level of security maturity. For Tier 1 banks, major utilities, telecommunications providers, and government-linked entities, red team exercises are increasingly a board-level expectation rather than an optional enhancement.
Malaysian compliance context
Malaysian organisations face overlapping compliance obligations that directly drive penetration testing requirements:
BNM Risk Management in Technology (RMiT)
Financial institutions licensed by Bank Negara Malaysia must conduct penetration testing on critical systems at least annually. Internet-facing systems require more frequent assessment. RMiT Paragraph 10.56 also requires institutions to perform vulnerability assessments after significant system changes. Red team exercises are not mandated but are referenced in the BNM supervisory expectations for advanced cyber resilience — Tier 1 banks are expected to demonstrate threat-led penetration testing (TLPT) capability consistent with international standards.
NACSA National Cybersecurity Policy
NACSA’s framework for CNII sectors (government, banking, energy, telecommunications, water, transport, healthcare, defence, and food) requires operators to conduct regular security assessments including vulnerability testing and penetration testing. NACSA’s Cybersecurity Malaysia Framework aligns with the NIST Cybersecurity Framework and expects CNII operators to progress toward advanced testing disciplines as part of continuous improvement.
Personal Data Protection Act (PDPA)
The PDPA’s Security Principle requires data processors to take practical steps to protect personal data from loss, misuse, modification, and unauthorised disclosure. While the Act does not prescribe penetration testing explicitly, the Personal Data Protection Department’s guidance treats regular security testing as an expected component of a reasonable security programme. Organisations that have suffered a data breach without evidence of regular security testing face greater regulatory exposure during PDPC investigations.
ISO/IEC 27001
Annex A Control 8.8 (Management of Technical Vulnerabilities) and Control 5.37 (Documented Operating Procedures) under ISO/IEC 27001:2022 effectively require organisations to conduct regular vulnerability assessments. Many ISO 27001 certification bodies in Malaysia expect penetration test evidence as part of the Statement of Applicability review. Simply Data holds ISCB certification for penetration testing, giving clients confidence that assessments meet the technical rigour expected by certification auditors.
Red team, pentest, or purple team — the decision framework
Use this guidance to match your situation to the right engagement:
| Situation | Recommended engagement |
|---|---|
| Compliance requirement (RMiT, ISO 27001, PDPA audit) | Scoped penetration test |
| New application or system pre-launch | Application penetration test |
| Testing specific control effectiveness | Targeted penetration test |
| Mature SOC — testing detection capability | Red team engagement |
| SOC with detection gaps — training needed | Purple team exercise |
| Board-level breach simulation | Red team engagement |
| CNII operator — advanced assurance | Red team with MITRE ATT&CK mapping |
The right answer often involves sequencing. Most Simply Data clients begin with a foundational penetration test, use findings to drive a remediation programme, and return annually to test progress — progressively expanding scope and sophistication as their security posture matures.
Protect your organisation with Simply Data
Simply Data is a Malaysian cybersecurity company providing ISCB-certified penetration testing, red team assessments, and security posture evaluations to organisations across banking, government, healthcare, and enterprise sectors. Our offensive security team works to the same methodologies used by NACSA-recognised assessors — delivering findings that satisfy regulatory requirements and give your leadership team a clear, honest picture of your actual security posture.
Whether you need a scoped penetration test to meet your next RMiT audit, a web application assessment before a product launch, or a full red team engagement to stress-test your SOC, Simply Data has the certified expertise to deliver it. Contact our team to discuss which engagement is right for your organisation — no obligation, no jargon.
Frequently Asked Questions
What is the difference between red team and penetration testing?
Penetration testing is a scoped, time-boxed engagement where security professionals test specific systems or applications against agreed rules of engagement. Red teaming is a broader, objective-based simulation with no predefined scope — the red team attempts to achieve a real-world adversary goal (such as accessing sensitive data or disrupting operations) using any means available. Penetration testing finds known vulnerability classes; red teaming exposes gaps in detection, response, and people.
Which is more expensive — red team or penetration testing?
Red team engagements are significantly more expensive than standard penetration tests, typically ranging from RM 80,000 to RM 200,000 or more for a full engagement, compared to RM 8,000 to RM 40,000 for a scoped web application or network pentest. The cost difference reflects the longer duration (weeks to months), the multi-discipline team required (OSINT, social engineering, physical intrusion, malware development), and the bespoke attack scenarios involved.
Does BNM RMiT require penetration testing?
Yes. Bank Negara Malaysia Risk Management in Technology (RMiT) policy document explicitly requires financial institutions to conduct penetration testing on critical systems at least annually, and after significant changes. For internet-facing systems, vulnerability assessments and penetration tests must be performed more frequently. Red team exercises are encouraged but not mandated under RMiT — however, they are increasingly expected of Tier 1 banks and insurers as part of advanced cyber resilience programmes.
What is purple teaming and when should we use it?
Purple teaming is a collaborative exercise where offensive (red) and defensive (blue) security teams work together in real time to test and improve detection and response capabilities. Unlike a traditional red team engagement where the blue team is kept unaware, purple teaming prioritises knowledge transfer — the red team reveals each tactic as it is executed, allowing the blue team to tune detections immediately. It is most effective for organisations that already have a functioning SOC or blue team and want to measurably improve detection coverage against specific threat actor techniques.
Is penetration testing required for PDPA compliance in Malaysia?
Malaysia’s Personal Data Protection Act (PDPA) requires organisations to implement appropriate security safeguards to protect personal data, but does not prescribe penetration testing by name. However, the Personal Data Protection Commissioner’s guidance and industry best practice treat regular vulnerability assessments and penetration testing as part of a reasonable security programme. For organisations in regulated sectors (banking under RMiT, critical infrastructure under NACSA guidelines), penetration testing requirements are more explicit.
How often should Malaysian organisations conduct penetration testing?
For most Malaysian organisations, penetration testing should be conducted at least once per year, plus after any significant change to infrastructure, applications, or network architecture. Financial institutions regulated by BNM RMiT are required to test critical systems annually at minimum. Organisations pursuing ISO/IEC 27001 certification typically conduct penetration tests as part of their annual internal audit cycle. High-risk sectors such as healthcare, utilities, and e-commerce should consider quarterly vulnerability assessments supplemented by annual penetration tests.


