- How is a continuous red team different from an annual penetration test?An annual penetration test is a point-in-time snapshot — it tells you what was vulnerable on the day of the test. A continuous red team operates as an ongoing program: quarterly assessments, real-time findings, named operators who learn your environment over time, and rolling coverage of new infrastructure as it ships. The result is a permanent state of validated security posture, not an annual surprise.
- What's included in the Continuous Red Team retainer?Recurring penetration testing across your environment (web, API, cloud, network, mobile), digital and assumed-breach red teaming, purple teaming and detection engineering collaboration, threat-actor-aligned adversary simulation, and continuous compromise assessment. All findings flow through the Bluefire platform in real time, with quarterly executive reviews and an annual posture report.
- How does purple teaming work in the program?Purple teaming combines our offensive operators with your detection and response engineers in collaborative sessions. We execute specific TTPs against your environment in a controlled, observed manner; your Blue Team validates which detections fire, which don't, and what tuning is required. The output is a measurable improvement in detection coverage against the techniques most relevant to your threat model, plus newly developed detection rules tested under live conditions.
- Can we choose which assessments happen each quarter?Yes. The program is structured with a baseline quarterly cadence — but the specific scope of each quarter is jointly planned with your security team during quarterly business reviews. Common patterns include rotating coverage of the application portfolio, prioritizing new deployments, deep purple-team weeks, or assumed-breach campaigns against specific segments of the environment. We work to your roadmap.
- What does 'real-time findings' actually mean?Every finding is posted to the Bluefire platform within hours of validation — not weeks later in a final PDF. Your team can triage, ask questions, retest, and remediate while our operators are still mid-engagement. Critical and high-severity findings trigger immediate notification to your security team. Integrations with Jira, ServiceNow, GitHub Issues, and Slack push findings into your existing workflows, with no manual transcription.
- Who delivers the engagement on Bluefire's side?Every engagement is delivered by named senior operators with hands-on offensive backgrounds — not junior analysts running tools. The same core operators remain assigned to your account across quarterly cycles, building deep knowledge of your environment, your applications, and your threat model. You will know their names, backgrounds, and certifications before the engagement begins.
- How does the program scale with our environment?Investment scales with scope. A mid-market technology company with a focused application portfolio and a single cloud provider typically engages at the lower end of the pricing band. A multinational with hundreds of applications, multiple cloud environments, and dedicated red team objectives engages at the upper end. Scope is reviewed each year and can scale up or down based on your environment's evolution.
- Can this program support our compliance audits?For organisations preparing for DORA TLPT, TIBER-EU, or CBEST engagements, see our Resilience & Threat-Led Assurance program — we deliver readiness testing and remediation ahead of your accredited assessment, not the accredited assessment itself.
- How much does continuous red teaming cost?
Plans start at $5,000 a month for Core, $9,500 a month for Pro, and from $16,000 a month for Enterprise, billed quarterly on a 12-month term. A 10-day Attack Path Sprint is available for $18,000 if you want to start smaller.
- How is this different from automated continuous testing tools?
Automated tools replay known techniques at scale. Our operators think like an attacker. They chain identity, cloud, AI agents, people and physical access toward your crown jewels, and they prove impact. Many clients run both.
- Is this only for large enterprises?
No. Core is built for growth-stage SaaS and fintech companies with a security team but no internal red team. Enterprise covers larger and regulated organizations.
- What is the minimum commitment?
12 months, billed quarterly in advance. Retests, live findings and quarterly reviews are included from month one.
- Can we try it before committing to a year?
Yes. Run a 10-day Attack Path Sprint. If you move to a plan within 60 days of the readout, half the Sprint fee is credited to your first year.







