Ejercicio de Red TeamRed Team Exercise
Ataque realista prolongado basado en objetivos concretos.Prolonged, realistic attack driven by specific objectives.
¿Qué es este servicio?What is this service?
Es un ejercicio de ataque realista y prolongado, orientado a objetivos concretos y no a encontrar todas las vulnerabilidades posibles. Se combinan vectores técnicos, humanos y a veces físicos, con el equipo defensor sin avisar.
A realistic, extended attack exercise driven by specific objectives rather than by finding every possible vulnerability. It combines technical, human and sometimes physical vectors, with the defending team unaware.
¿Para qué se usa?What is it used for?
Responde una pregunta que un pentest no responde: si un atacante decidido va detrás de la información más valiosa de la organización, ¿lo consigue y alguien lo advierte? El objetivo se define de antemano —llegar a la base de datos de clientes, ejecutar una transferencia, sacar el código fuente— y lo que se mide es si se consiguió y cuánto tardó la organización en verlo.
It answers a question a penetration test does not: if a determined attacker goes after the most valuable information the organisation holds, do they get it and does anybody notice? The objective is defined up front — reach the customer database, execute a transfer, exfiltrate source code — and what gets measured is whether it was achieved and how long the organisation took to see it.
Qué beneficios traeBenefits it delivers
- Mide la detección y la respuesta de verdad, no en un simulacro anunciado.
- Encuentra cadenas de ataque completas, que es como ocurren los incidentes reales, en vez de hallazgos sueltos.
- Da a la dirección una respuesta clara y sin tecnicismos a la pregunta de si estamos preparados.
- Genera casos de detección concretos para mejorar el SOC, que es donde queda el valor permanente.
- Genuinely measures detection and response, not in an announced drill.
- Finds complete attack chains, which is how real incidents happen, instead of isolated findings.
- Gives management a clear, jargon-free answer to whether the organisation is prepared.
- Produces concrete detection use cases to improve the SOC, where the lasting value sits.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No es obligatorio en Costa Rica por ninguna norma general.
- Para entidades supervisadas puede servir como evidencia robusta de gestión del riesgo tecnológico, pero el Acuerdo CONASSIF 5-24 no lo exige con ese nombre.
- It is not mandatory in Costa Rica under any general rule.
- For supervised entities it can serve as strong evidence of technology risk management, but CONASSIF Agreement 5-24 does not require it by that name.
InternacionalInternational
- DORA exige pruebas de penetración dirigidas por amenazas a las entidades financieras europeas que sean identificadas para ello.
- TIBER-EU es el marco europeo de referencia para ese tipo de ejercicio.
- Fuera de esos casos, el red team es voluntario: ningún marco general lo impone.
- DORA requires threat-led penetration testing from the European financial entities identified for it.
- TIBER-EU is the European reference framework for that kind of exercise.
- Beyond those cases, red teaming is voluntary: no general framework mandates it.
Requisitos mínimosMinimum requirements
- Madurez previa: si no hay capacidad de detección, el ejercicio solo confirma lo evidente y conviene hacer un pentest primero.
- Objetivos definidos y aprobados por la dirección, con un grupo reducido de personas informadas.
- Reglas de compromiso muy detalladas y una carta de autorización que el equipo pueda mostrar si lo detienen.
- Un canal de emergencia para detener el ejercicio si compromete la operación.
- Prior maturity: without detection capability the exercise only confirms the obvious, and a penetration test should come first.
- Objectives defined and approved by management, with a small group of informed people.
- Very detailed rules of engagement and an authorisation letter the team can show if stopped.
- An emergency channel to halt the exercise if it threatens operations.
Plazo típico de entregaTypical delivery time
El rango habitual del mercado va de seis a doce semanas, contando inteligencia previa, ejecución sigilosa e informe. Es más largo que un pentest a propósito: la lentitud es parte del realismo, porque un atacante real no tiene prisa. Los ejercicios bajo marcos regulatorios pueden extenderse a seis meses o más.
The usual market range runs from six to twelve weeks, covering prior intelligence, stealthy execution and reporting. It is deliberately longer than a penetration test: slowness is part of the realism, because a real attacker is not in a hurry. Exercises under regulatory frameworks can extend to six months or more.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.