September 29, 2025 numan

Red Teaming: How to Challenge Plans Before Reality Does

How Thinking Like an Adversary Can Expose Blind Spots, Strengthen Decisions, and Prevent Avoidable Failure

Introduction

Most organisations do not fail because nobody was intelligent.

They fail because intelligent people worked from incomplete assumptions, agreed too quickly, ignored uncomfortable evidence, or became too emotionally invested in a preferred plan.

A strategy can look convincing inside the room where it was created.

The problem appears when customers, competitors, criminals, regulators, technological failures, or unexpected events refuse to behave according to that plan.

Red teaming creates a structured way to discover those weaknesses before reality does.

In Red Team: How to Succeed by Thinking Like the Enemy, Micah Zenko examines how military units, intelligence agencies, governments, security organisations, and private companies use independent challengers to test their own thinking.

The official publisher describes red teaming as the practice of entering the perspective of competitors or adversaries to gain a strategic advantage. The method can involve alternative analysis, simulations, vulnerability testing, and deliberate attempts to expose weaknesses in plans and systems.

However, creating a group called a red team is not enough.

The organisation must genuinely want to hear what the team discovers.

That is often the hardest part.

What Is Red Teaming?

A red team is an authorised group assigned to examine an organisation, strategy, operation, or system from an opposing perspective.

Its members may think like:

  • A competitor
  • A dissatisfied customer
  • A criminal
  • A cyberattacker
  • A regulator
  • A political opponent
  • A hostile government
  • A careless employee
  • A sceptical investor
  • An operational failure

The purpose is not criticism for its own sake.

It is to improve the organisation’s chances of succeeding.

In cybersecurity, the National Institute of Standards and Technology defines a red team as an authorised group that emulates an adversary’s attack or exploitation capabilities to reveal the effects of successful attacks and test the defenders’ performance.

Strategic red teaming is broader.

It may test whether a business plan depends on unrealistic customer behaviour, whether a military operation underestimates an opponent, or whether a company’s security procedures survive a determined attempt to bypass them.

The central question is:

How could this plan fail if the world does not behave as we expect?

Why Organisations Struggle to See Their Own Weaknesses

People are usually better at identifying flaws in someone else’s plan than in their own.

Once we help create an idea, we become attached to it.

We remember the evidence supporting it, defend the effort already invested, and interpret disagreement as resistance rather than useful information.

Organisations develop similar blind spots.

Familiarity creates false confidence

When a process has worked repeatedly, people begin assuming it will continue working.

They stop asking whether conditions have changed.

Hierarchy discourages disagreement

Employees may recognise a serious problem but hesitate to challenge senior leaders.

The risk of speaking can feel greater than the risk of remaining silent.

Success hides fragility

A company may be succeeding because market conditions are favourable, not because its strategy is strong.

Until the environment changes, the weakness remains hidden.

Plans become identities

When leaders strongly associate themselves with a strategy, criticism of the plan may feel like criticism of their competence.

Groups seek harmony

Teams often reward people who support the emerging consensus.

Someone who repeatedly identifies risks may be viewed as negative, difficult, or disloyal.

Red teaming exists because ordinary planning processes do not reliably correct these tendencies.

Red Teaming Is More Than Playing Devil’s Advocate

A person occasionally saying, “Let me play devil’s advocate,” may help a discussion.

However, that is not the same as a serious red-team process.

An informal challenger may lack:

  • Time
  • Independence
  • Access to information
  • Relevant expertise
  • A clear mandate
  • Protection from retaliation
  • Methods for testing the plan
  • A way to ensure findings are addressed

A real red team is deliberately authorised to challenge assumptions.

Its members gather evidence, model alternative behaviours, test weaknesses, and communicate findings to people with the authority to respond.

The process should create disciplined opposition, not spontaneous negativity.

The First Requirement Is a Leader Willing to Be Challenged

Red teams cannot help leaders who want only reassurance.

A leader may approve a review while quietly expecting the team to confirm the existing plan.

When the findings become uncomfortable, the leader may:

  • Question the team’s loyalty
  • Restrict access to information
  • Reject the methodology
  • Attack individual members
  • Delay the report
  • Remove difficult conclusions
  • Accept minor recommendations while ignoring the central warning

Under these conditions, red teaming becomes theatre.

Zenko’s central argument is that red teams are only as effective as leaders permit them to be. The organisation must support the work, provide resources, protect independent thinking, and respond seriously to the findings.

Before commissioning a red team, leaders should ask:

  • Am I prepared to discover that my preferred plan is weak?
  • Will people be safe when they challenge me?
  • What evidence would cause us to change direction?
  • Who will review the recommendations?
  • What happens if the findings are politically inconvenient?
  • Have we allocated time to respond before execution?

If the answer to these questions is unclear, the exercise may create frustration without improving the decision.

Red Teams Should Inform, Not Decide

A red team’s responsibility is to test, challenge, and inform.

It should not automatically take ownership of the final decision.

The decision-maker must consider:

  • The red team’s findings
  • Operational priorities
  • Costs
  • Legal obligations
  • Ethical concerns
  • Available resources
  • Timing
  • Other risks and opportunities

This distinction matters because a red team is intentionally focused on weaknesses.

Its task is to identify what may go wrong. Therefore, it may not give equal attention to the benefits of proceeding.

The red team improves the decision process, but it does not replace accountable leadership.

A useful relationship is:

The decision-maker owns the choice. The red team improves the quality of that choice.

Independence Must Be Protected

A red team needs enough independence to challenge the organisation honestly.

If team members report directly to the people whose strategy they are testing, they may consciously or unconsciously soften the findings.

However, complete separation can also create problems.

An entirely external team may misunderstand the operational environment, underestimate constraints, or suggest changes that are impossible to implement.

The strongest arrangement often combines:

  • Independence from the plan’s original authors
  • Access to senior decision-makers
  • Relevant operational knowledge
  • Permission to question assumptions
  • Protection from retaliation
  • Awareness of organisational constraints

The red team should be close enough to understand the system but independent enough to challenge it.

Choose the Right Red Team Members

Not everyone is suited to red teaming.

A strong red team requires more than intelligence.

Members need curiosity, disciplined scepticism, imagination, judgment, and the ability to communicate uncomfortable findings constructively.

Useful qualities include:

Intellectual independence

They do not assume something is correct merely because it is established or supported by senior people.

Empathy for the adversary

They can temporarily set aside their own preferences and understand how another actor may think.

Attention to detail

They notice weak signals, inconsistencies, and small vulnerabilities that others overlook.

Systems thinking

They examine how people, technology, incentives, communication, and processes interact.

Creativity

They imagine non-obvious paths to failure.

Evidence-based judgment

They distinguish a plausible threat from an imaginative but unsupported possibility.

Communication skill

They can present difficult findings without turning the process into a personal attack.

A useful red team is not a group of permanent pessimists.

It is a group of disciplined challengers.

Learn to Think Like the Adversary

Thinking like the enemy requires more than asking, “What would I do if I were them?”

That question can still produce your own assumptions in a different costume.

Instead, the red team should examine the adversary’s:

  • Objectives
  • Incentives
  • Resources
  • Constraints
  • Culture
  • Risk tolerance
  • Past behaviour
  • Knowledge of the situation
  • Likely perception of your weaknesses

A competitor may not want to defeat your company directly.

It may want to weaken one profitable segment, recruit critical employees, influence distributors, or change customer expectations.

A cyberattacker may not use the technically most advanced route.

They may target an employee, supplier, forgotten account, or badly designed recovery process.

A dissatisfied customer may not complain through the official channel.

They may quietly leave, discourage others, or share the experience publicly.

The purpose is to enter another perspective deeply enough to identify actions that your original plan did not anticipate.

Different Forms of Red Teaming

Red teaming can take several forms depending on the decision being tested.

Alternative Analysis

The team develops explanations or forecasts that differ from the dominant view.

For example:

  • What if demand falls instead of rising?
  • What if the competitor does not react as expected?
  • What if our strongest assumption is wrong?
  • What evidence supports an alternative explanation?

Vulnerability Probing

The team actively looks for weaknesses in a physical, technological, or organisational system.

This may include:

  • Cybersecurity testing
  • Facility access testing
  • Supply-chain disruption
  • Fraud scenarios
  • Data leakage
  • Emergency-response weaknesses

Simulations and War Games

Participants represent different stakeholders and respond dynamically to one another.

This helps expose second- and third-order effects that are difficult to see in a static plan.

Premortem Analysis

The team assumes the plan has failed and works backward to explain what caused the failure.

This makes it easier to discuss risks without first convincing everyone that failure is likely.

Competitive Challenge

The red team adopts the role of a competitor and looks for ways to weaken the organisation’s position.

Customer Challenge

The team tests the product, process, or strategy from the customer’s perspective.

The method should match the problem.

A cybersecurity penetration test will not answer every strategic question, while a discussion-based premortem will not prove whether a building can be physically accessed.

Red Teaming in Business Strategy

Businesses can use red teams before:

  • Entering a new market
  • Launching a product
  • Acquiring another company
  • Making a large investment
  • Changing a pricing model
  • Selecting a technology platform
  • Restructuring the organisation
  • Depending on a new supplier
  • Expanding internationally
  • Making a major public commitment

Consider a company preparing to launch a product.

The original team may focus on features, marketing, and expected demand.

A red team may ask:

  • Why might customers refuse to change?
  • Which competitor could copy the offer quickly?
  • What happens if the price is challenged?
  • Where could the supply chain fail?
  • Which claim could create regulatory trouble?
  • How could the product be misused?
  • What support problem may damage trust?
  • Which internal capability is being overestimated?

The goal is not to stop the launch.

It is to make the launch stronger.

Red Teaming Security and Operations

Red teaming is especially valuable where failure can cause serious physical, financial, operational, or reputational harm.

Security plans often fail because they assume people will follow expected routes.

A real adversary searches for the neglected route.

That may involve:

  • A poorly protected vendor
  • An unused entrance
  • An employee vulnerable to manipulation
  • Weak password recovery
  • Unmonitored equipment
  • An outdated emergency contact
  • Conflicting responsibilities during a crisis
  • A backup process that has never been tested

The question should not be:

“Do we have a security policy?”

It should be:

“Can a determined person defeat the actual system?”

Red Teaming Artificial Intelligence

AI systems have created another major application for red teaming.

An AI red team deliberately searches for harmful outputs, unsafe behaviour, security vulnerabilities, misleading responses, bias, privacy failures, and ways users may manipulate the system.

The principle remains the same:

Do not evaluate a system only under the conditions its designers expect.

Test how it behaves when people use it incorrectly, creatively, maliciously, or in situations the original team did not anticipate.

AI red teaming should examine:

  • Harmful or discriminatory outputs
  • Fabricated information
  • Sensitive-data disclosure
  • Prompt manipulation
  • Unsafe recommendations
  • Excessive confidence
  • Failure under unusual inputs
  • Human overreliance
  • Weak escalation controls
  • Misuse by insiders or external actors

The method has evolved, but the underlying discipline remains adversarial testing before widespread failure.

Common Reasons Red Teams Fail

The Leader Wants Validation

The exercise is designed to make the existing plan appear stronger rather than genuinely test it.

The Scope Is Too Broad

The red team is told to “find everything wrong” without a clear decision, system, or timeframe.

The Team Lacks Access

Members cannot examine the necessary data, people, plans, or systems.

Findings Become Personal

The original team treats criticism of the plan as criticism of its intelligence or commitment.

The Red Team Becomes an Internal Police Force

Employees feel constantly watched, judged, or trapped.

This creates fear instead of learning.

The Findings Are Too Vague

A report that says “communication should improve” gives nobody a clear action.

Every Possible Threat Is Treated Equally

An imaginative scenario is presented with the same urgency as a highly probable and damaging risk.

Nobody Owns the Response

The report is delivered, discussed, and forgotten.

Red teaming creates value only when findings influence decisions and actions.

Red Team Without Creating a Culture of Fear

Constant testing can exhaust employees.

If red teams appear unexpectedly, operate without boundaries, or publicly expose individual mistakes, people may experience the process as surveillance or punishment.

A healthier approach is to:

  • Explain the purpose
  • Define the scope
  • Protect individuals where appropriate
  • Focus on systems and decisions
  • Time-box the exercise
  • Separate learning from humiliation
  • Share the improvements created
  • Avoid testing every activity continuously

The purpose is organisational resilience, not permanent suspicion.

Red teams should be used where the potential consequences justify the pressure and expense.

A Practical Red Teaming Framework

1. Define the Decision or System

State exactly what is being tested.

For example:

“Can this launch achieve its first-year target under realistic competitive conditions?”

2. Identify the Assumptions

List what must be true for the plan to succeed.

3. Appoint a Sponsor

Choose a leader who will protect the process, provide access, and respond to the findings.

4. Create the Red Team

Select people with relevant expertise, independent thinking, and no need to defend the original plan.

5. Define the Adversary or Perspective

Clarify whose interests, incentives, and behaviour the team will model.

6. Select the Methods

Use interviews, data analysis, simulations, penetration tests, premortems, or scenario exercises as appropriate.

7. Rank the Findings

Evaluate each weakness according to:

  • Likelihood
  • Potential impact
  • Speed of occurrence
  • Detectability
  • Ability to recover

8. Recommend Actions

Connect every major finding with a practical response.

9. Assign Owners and Deadlines

Clarify who will decide, implement, or accept each risk.

10. Retest

Confirm that the response actually reduced the vulnerability.

A red-team report is not the final product.

The final product is a stronger decision or system.

Questions Every Red Team Should Ask

  • What must be true for this plan to work?
  • Which assumption has the weakest evidence?
  • What are we not discussing?
  • Who benefits if we fail?
  • How would a competitor exploit this plan?
  • What would a hostile actor notice first?
  • Which small failure could trigger a larger one?
  • Where are we depending on one person or supplier?
  • What warning sign might we ignore?
  • What happens if the opposite of our forecast occurs?
  • Which risk cannot be recovered from?
  • What would make us stop or change direction?

These questions help turn confidence into testable reasoning.

A One-Day Red Team Workshop

Session 1: Define Success

Clarify the objective, boundaries, and expected result.

Session 2: Expose Assumptions

List the beliefs supporting the plan.

Session 3: Adopt the Adversary’s View

Examine incentives, capabilities, and likely actions.

Session 4: Attack the Plan

Use scenarios, premortems, and vulnerability analysis.

Session 5: Prioritise

Separate serious risks from interesting but unlikely possibilities.

Session 6: Strengthen

Design preventive actions, contingency plans, and warning indicators.

Session 7: Decide

Confirm what will change, who owns it, and what risk is consciously accepted.

Even a short exercise can improve a major decision when leaders genuinely welcome challenge.

Who Should Read Red Team?

The book is particularly useful for:

  • Executives making high-stakes strategic decisions
  • Board members responsible for risk and oversight
  • Security leaders protecting physical and digital systems
  • Military and government professionals
  • Strategy teams examining markets and competitors
  • Technology leaders deploying AI or critical systems
  • Operations managers responsible for business continuity
  • Entrepreneurs testing assumptions before investing heavily
  • Anyone concerned about groupthink or organisational blind spots

Its main value lies in turning scepticism into a disciplined organisational capability.

About Micah Zenko

Micah Zenko is a Partner at McChrystal Group, where he advises organisations on complexity, risk, strategic planning, scenarios, and red teaming.

His official biography describes more than two decades of experience in national security, foreign policy, and organisational strategy. Before joining McChrystal Group, he led red-team work at the Council on Foreign Relations and held research roles connected with Chatham House and Harvard Kennedy School.

In addition to Red Team, he has written books on military strategy, national security, risk, and threat perception. His current work focuses on helping leadership teams challenge assumptions, stress-test strategy, and improve organisational resilience.

Frequently Asked Questions

What is red teaming?

Red teaming is the structured use of independent challengers to examine a plan, organisation, or system from the perspective of an adversary, competitor, or sceptical outsider.

What is the purpose of a red team?

Its purpose is to expose assumptions, identify weaknesses, anticipate threats, and improve decisions before failure occurs.

Is red teaming the same as cybersecurity testing?

Cybersecurity red teaming is one application. Red teaming can also be used for strategy, military planning, physical security, mergers, product launches, operations, and organisational decisions.

What is the difference between a red team and a devil’s advocate?

A devil’s advocate may raise occasional objections. A red team has a formal mandate, suitable methods, access to information, and responsibility for systematically testing the plan.

Should a red team make the final decision?

Usually not. The red team should inform and challenge the decision-maker, who remains accountable for balancing the findings with other priorities.

Who should serve on a red team?

Members should combine independent thinking, relevant expertise, imagination, evidence-based judgment, attention to detail, and the ability to communicate difficult findings constructively.

Why do organisations resist red teams?

Leaders may fear embarrassment, delay, criticism, loss of control, or evidence that challenges a preferred decision.

How can a company start red teaming?

Begin with one important decision, define the scope, list assumptions, appoint an independent team, test the plan from an adversarial perspective, rank the risks, and assign owners to the response.

Conclusion

Red teaming is not about expecting every plan to fail.

It is about recognising that confidence is not proof.

Organisations naturally become attached to their own strategies. Hierarchy discourages disagreement, success hides weaknesses, and familiar processes begin to feel safer than they really are.

A red team interrupts that comfort.

It asks what competitors, adversaries, customers, criminals, unexpected events, or simple human error may do to the plan.

However, red teaming succeeds only when leaders are prepared to hear the answer.

The team needs independence, access, expertise, protection, and a clear purpose. Its findings must also lead to decisions, ownership, and follow-through.

The best time to discover a weakness is not after the attack, failed launch, lost investment, or public crisis.

It is while the weakness can still be corrected.

Call to Action

Choose one major plan your organisation currently believes will succeed.

Then write:

  • The outcome we expect
  • The assumptions supporting it
  • The assumption with the weakest evidence
  • The competitor or adversary’s likely goal
  • The easiest way to disrupt the plan
  • The failure we are least prepared to discuss
  • The warning signs we should monitor
  • The risk we cannot afford
  • The person who can challenge the plan independently
  • The action we will take if the red team is correct

Before approving the plan, ask one final question:

“How would someone determined to defeat this exploit what we have overlooked?”

Subscribe To Our Newsletter

Join our newsletter to receive updates, news from our blog.

, , , , , , , , ,