Businesses are adopting AI and other new technologies faster than ever, creating new attack surfaces at an exponential rate. This blog – from Six Degrees’ Cyber Security Assurance Technical Director Andy Swift and Claranet’s Offensive Security Senior Manager Simon Kubicsek – explores how effective red teaming is evolving beyond point-in-time testing to deliver collaborative, attack chain-driven engagements that improve detection, response, and overall cyber resilience.
If you are responsible for maintaining your business’ cyber security posture in 2026, there’s a lot on your shoulders. Attackers are becoming more sophisticated, your business is likely adopting new technologies at an unprecedented speed, and your teams are being asked to do more with often limited resources.
These circumstances mean that traditional approaches to offensive security testing are no longer enough. Businesses need to think differently about what they expect from a red team engagement and, more importantly, what outcomes they want it to deliver.
Here are three ways in which red teaming is evolving from a one-off technical exercise into a strategic capability that helps businesses improve their resilience against real-world threats.
Note: In this blog we’ll refer to red teaming, blue teaming, and purple teaming. To summarise them briefly in terms of offensive security exercises, red teams act as attackers, blue teams act as defenders, and purple teams combine both groups to share knowledge and fix gaps.
1. AI Has Created an Entirely New Attack Surface
The most obvious shift in the threat landscape is the growing use of agentic AI by attackers. Automated tools are enabling threat actors to operate at greater scale and speed than ever before, while simultaneously lowering the barrier to entry for sophisticated attacks.
However, the bigger challenge for many businesses isn’t attackers using AI – it’s the widespread adoption of AI within their own environments.
Businesses are rapidly integrating large language models (LLMs) and AI-powered capabilities into products, services, and internal workflows. Vendors are embedding AI across their platforms, while businesses are deploying AI tools to improve productivity and accelerate innovation. In many cases, security test scoping and testing practices have not yet caught up.
AI systems introduce entirely new attack surfaces and classes of vulnerability and as such methodology has also rapidly had to play catch up. Prompt injection attacks, data leakage, model manipulation, excessive permissions, and deterministic behaviours can all create opportunities for attackers to access sensitive or valuable information.
We’re increasingly seeing AI-enabled systems become a path of least resistance during engagements. Businesses that have invested heavily in securing their infrastructure and applications may inadvertently expose critical data through poorly implemented AI capabilities.
For businesses, this means red teaming can no longer focus solely on networks, endpoints, and applications. Security testing must evolve to include AI systems and understand how attackers might exploit them as part of a broader attack chain.
The businesses that will be best positioned in 2026 are those treating AI as a new security domain rather than simply another business tool.
Five Ways We’ve Seen Agentic AI Change Real Attacks
Agentic AI is undoubtedly changing the threat landscape, but perhaps not in the way many people expect. The biggest shift isn’t the emergence of entirely new forms of cyber-attack. Instead, we’re seeing AI accelerate existing techniques, increase attack volume, and reduce the time between vulnerability disclosure and exploitation. Across our offensive security engagements, five trends are consistently emerging:
1. Exploit Weaponisation Is Happening Much Faster
What’s changed
One of the biggest changes we’ve observed is the speed at which newly disclosed vulnerabilities are being weaponised. Previously, there was often a meaningful delay between a CVE or proof-of-concept exploit being published and attackers adapting it for real-world use. Today, AI is dramatically reducing that timeframe by helping attackers understand, modify, and repurpose exploit code in minutes rather than days or weeks.
Rather than inventing entirely new attacks, agentic AI is accelerating existing ones.
Why it matters
Businesses now have a much smaller window to identify exposed systems, assess risk, and apply mitigations before working exploits become widely available. As that window continues to shrink, vulnerability management programmes need to become faster and more risk-driven than ever before.
What businesses should do
Prioritise remediation based on exploitability rather than severity alone, and assume that publicly disclosed vulnerabilities will be weaponised rapidly. Security teams should also review how quickly threat intelligence, vulnerability management, and patching processes work together following major disclosures.
2. AI Has Become a Force Multiplier for Attackers
What’s changed
The barrier to entry for conducting sophisticated attacks is becoming lower, as agentic AI is enabling smaller threat actors to carry out attacks that previously required larger teams or specialist expertise. Tasks such as reconnaissance, payload generation, and exploit adaptation can now be partially automated, allowing individuals or small groups to operate with significantly greater speed and scale.
Why it matters
Businesses are no longer defending themselves solely against highly resourced attackers. A much broader range of threat actors can now conduct attacks that would previously have required greater technical capability or manpower. This increases both the volume of attacks and the likelihood of businesses being targeted.
What businesses should do
Assume that attack activity will become more frequent rather than simply more sophisticated. Businesses should ensure their security monitoring, threat detection, and incident response capabilities can identify repeated automated activity, rather than relying solely on preventative controls.
3. Initial Access Is Becoming Increasingly Automated
What’s changed
We’ve seen evidence that agentic AI is increasingly being used to automate the early stages of an attack. Rather than targeting a small number of known vulnerabilities, AI agents can continuously assess large numbers of internet-facing systems, determine which vulnerabilities apply to each target, and decide which attack path is most likely to succeed.
This allows attackers to scale reconnaissance and initial compromise efforts far beyond what was previously practical.
Why it matters
Internet-facing assets that might previously have escaped attention are now far more likely to be discovered and assessed by automated attackers. Any unnecessary exposure significantly increases the likelihood of compromise.
What businesses should do
Minimise your external attack surface wherever possible. Review which systems and management interfaces are exposed to the internet, remove unnecessary services, and ensure externally accessible assets are continuously monitored and tested.
4. Stolen Data Can Be Analysed at Machine Speed
What’s changed
AI is changing what happens after attackers gain access. Instead of relying on manual analysis, attackers can use AI to process large volumes of stolen information rapidly, identifying credentials, sensitive documents, intellectual property, and other valuable data in a fraction of the time previously required. The human bottleneck has largely disappeared.
Why it matters
Once data has been exfiltrated, attackers can extract value from it much more quickly. This shortens the time businesses have to detect and respond before sensitive information is abused or sold.
What businesses should do
Focus not only on preventing data theft but also on detecting and disrupting data exfiltration. Businesses should ensure they have visibility into unusual data movement and regularly test whether exfiltration attempts would be identified before significant amounts of information leave the environment.
5. AI Is Increasing the Scale and Persistence of Attacks
What’s changed
Perhaps the most significant shift is not that AI has introduced entirely new attack techniques, but that it enables existing techniques to be executed continuously, at scale, and with minimal human intervention. AI agents do not become fatigued, work fixed hours, or abandon targets simply because they are difficult to compromise.
Attackers can now maintain persistent pressure across a much wider range of targets than ever before.
Why it matters
Security teams should expect more frequent probing, repeated exploitation attempts, and greater coverage of their attack surface. Systems or configurations that might previously have gone unnoticed are increasingly likely to be discovered over time.
What businesses should do
Design security on the assumption that every exposed asset will eventually be tested. Reduce unnecessary attack surface, implement defence in depth, and carry out regular threat-led security testing to validate that critical systems remain resilient as attacker capabilities continue to evolve.
2. The Lines Between Red and Purple Teaming Are Blurring
There is a growing industry shift towards the convergence of red and purple teaming, and for good reason. Traditional red teaming has often been viewed as an adversarial exercise designed to demonstrate how an attacker could compromise a business. While valuable, this approach can sometimes leave security teams with a report of findings but limited understanding of how the attack unfolded or how to prevent it from happening again.
Modern red team engagements frequently involve cutting-edge techniques, bespoke tooling, and in some cases approaches that closely resemble zero-day attacks. Simply presenting the outcome of an engagement isn’t enough to deliver meaningful improvements in security posture.
Increasingly, businesses are demanding more from their red team providers. They want to understand:
- What techniques were used
- How the attack was successful
- Which controls failed
- How similar activity can be detected in future
- What defensive improvements will deliver the greatest impact
This is where the convergence of red and purple teaming delivers significant value.
By working collaboratively with defensive teams throughout or following an engagement, businesses can translate offensive findings into practical improvements across detection, response, and security operations. The objective is no longer simply to prove compromise is possible; it’s to improve the business’ ability to detect, prevent, and respond to real-world attacks.
That’s why highly capable providers like Six Degrees and Claranet are increasingly working in a mobius loop-style pattern, where blue teams generate threat intelligence that informs red team activity. The result is a far greater return on investment from red team exercises, tangible improvements in defensive maturity, and the ability to align to regulatory standards like DORA which ask for evidence of threat-led approaches.
How Our Offensive Security Team Applies This in Practice
The role of a modern offensive security team has evolved significantly over the past few years. Businesses are no longer looking for a red team that simply demonstrates compromise is possible. They want a partner that helps them understand how attackers operate, validates the effectiveness of their existing controls, and strengthens their ability to detect and respond to real-world threats.
Extending beyond the vulnerability
That’s why our engagements increasingly extend beyond identifying vulnerabilities. We work alongside defensive teams to understand not only how an attacker gained access, but which controls failed, which detections worked, where visibility was lost, and how similar activity can be identified and prevented in future.
Continuous feedback loops
Rather than viewing red, blue and purple teaming as separate disciplines, we’re seeing the greatest value delivered when they operate as part of a continuous feedback loop. Offensive findings help improve defensive monitoring, while lessons learned from live incident response and SOC operations directly influence how future red team engagements are planned. This creates a cycle of continuous improvement that reflects how attackers evolve in the real world.
Regulatory influence
For businesses operating in regulated sectors, this collaborative approach is becoming increasingly important. Frameworks such as DORA place greater emphasis on threat-led testing that produces meaningful improvements to security controls, not simply a list of technical findings. By combining offensive testing with practical remediation guidance, businesses can demonstrate that they are continuously improving their cyber resilience rather than treating red teaming as a point-in-time compliance exercise.
What happens next
We’re also seeing customers place far greater emphasis on what happens after an engagement. Historically, a red team might have delivered a report explaining how compromise was achieved before moving on to the next assessment. Today, businesses expect considerably more. They want support prioritising remediation, validating security improvements, tuning detection rules, and ensuring their investment in security tools delivers measurable outcomes.
Detection engineering
One area where this collaborative model is delivering significant value is detection engineering. During engagements, we don’t simply demonstrate how an attack succeeds; we also validate whether key stages of the attack would have been detected. We assess which alerts are generated, where monitoring gaps exist, and how defensive teams can improve visibility into techniques such as privilege escalation, lateral movement and data exfiltration. This allows businesses to strengthen both their preventative controls and their ability to respond when an attack occurs.
Ultimately, the objective of offensive security is no longer just to prove that compromise is possible. It’s to help businesses continually improve their ability to prevent, detect, and respond to attacks. That’s why the most effective red team engagements are those that combine offensive expertise with practical defensive improvements, leaving businesses measurably more resilient than they were before the engagement began.
3. Red Teaming Is Becoming About Attack Chains, Not Individual Vulnerabilities
Perhaps the most important evolution in red teaming is the move away from point-in-time or single-exploit testing towards full attack chain simulation.
Security teams are facing an unprecedented volume of vulnerabilities, alerts, and remediation activities. Fixing everything simply isn’t realistic. Understanding what matters most has become just as important as identifying weaknesses in the first place.
Attack chain simulation focuses on how attackers operate in the real world, rather than demonstrating a single vulnerability or control weakness in isolation. Red teams simulate an end-to-end compromise to understand how multiple issues can be combined to achieve a specific objective.
This approach provides several benefits:
- It identifies which control failures are genuinely critical
- It highlights where businesses should prioritise remediation efforts
- It demonstrates how attackers move through environments once initial access is gained
- It helps security teams understand which weaknesses pose the greatest business risk
Crucially, attack chain simulation allows businesses to focus on breaking attack paths early. In many cases, addressing one or two critical control failures can prevent multiple attack scenarios from succeeding.
At a time when vulnerability discovery continues to accelerate and security teams remain under significant pressure, prioritisation is essential. Red teaming should help businesses make better security decisions, not simply provide a longer list of issues to fix.
Three AI Attack Paths We’ve Started Testing
The rise of AI-enabled applications has fundamentally changed how we approach offensive security testing. Unlike traditional applications, AI systems aren’t a single attack surface. They’re an ecosystem consisting of models, prompts, APIs, retrieval mechanisms, memory, training data, and connected business systems.
That requires a very different testing methodology.
AI-powered support ticketing systems
One engagement our teams recently undertook involved a support platform where AI automatically processed incoming tickets.
By manipulating how information entered the system, our consultants demonstrated that prompt injection techniques could influence the model’s behaviour and cause it to disclose information that shouldn’t have been returned.
Rather than testing the application itself, the assessment focused on how the AI interpreted user-supplied content.
AI website chatbots
In another engagement, our team assessed an AI chatbot embedded within a website.
Through unexpected language translation behaviour, they identified a route that allowed injected content to be interpreted differently by the model, creating an attack path that wouldn’t exist in a traditional web application.
The vulnerability wasn’t in the chatbot interface itself – it emerged from the interaction between translation, prompt handling, and application logic.
End-to-end AI ecosystem testing
Perhaps the biggest change is that we no longer test the model in isolation. Instead, we assess:
- Model behaviour
- Memory
- Retrieval mechanisms
- Connected APIs
- Underlying data stores
- Permissions
- Observability
- Training data
- Bias
- Prompt handling
The attack surface is now the entire AI ecosystem, not just the language model.
Lessons We’ve Learned from Recent Red Team Engagements
Across recent engagements, several themes continue to emerge.
AI accelerates existing attacks far more than it invents new ones
The greatest risk isn’t necessarily novel AI attacks – it’s familiar attack techniques being executed at much greater speed and scale.
The biggest risks often come from attack chains
Customers frequently focus on individual vulnerabilities. However, our consultants repeatedly see medium and low-risk issues combining to create high-impact compromises. Looking at vulnerabilities in isolation rarely reflects how attackers actually operate.
Identity is becoming more important than exploits
Many modern attack paths begin with legitimate credentials rather than sophisticated technical exploits. Compromised identities allow attackers to access sensitive data without exploiting a traditional vulnerability, making identity security increasingly central to red team engagements.
Detection gaps are often more important than exploitation
One recurring lesson from incident response work is that businesses frequently discover compromises only after data appears for sale or is published online. Finding the vulnerability matters, but understanding whether the activity would have been detected is often even more valuable.
The best engagements improve both offence and defence
The businesses seeing the greatest value from red teaming treat it as a continuous improvement exercise rather than a one-off assessment. Each engagement strengthens detection, improves monitoring, and helps defensive teams recognise similar activity in future.
How Has Red Teaming Changed Since 2016 – And What Will Change Next?
2016 | Today (2026) | What’s Next |
Focus on individual vulnerabilities Success was often measured by the number of vulnerabilities discovered during a point-in-time engagement. | Focus on attack chains Modern red teams demonstrate how multiple weaknesses combine to achieve a business-impacting compromise. | Focus on business resilience Red teaming will increasingly prioritise the attack paths that present the greatest operational and regulatory risk, rather than simply identifying technical weaknesses. |
Traditional infrastructure testing Networks, servers, and web applications formed the primary attack surface. | Testing complex digital ecosystems Cloud, identity, SaaS, APIs, and AI systems are now all part of the engagement scope. | Continuous AI ecosystem testing Testing will expand to include autonomous AI agents, MCP servers, retrieval pipelines, and machine-to-machine interactions. |
Red teams worked independently Reports were delivered after the engagement with limited collaboration. | Red, blue and purple teams work together Offensive findings now drive improvements in detection engineering, monitoring, and incident response. | Continuous validation loops Threat intelligence, incident response, SOC operations, and offensive testing will become increasingly interconnected, creating ongoing security improvement rather than annual assessments. |
Testing ended with exploitation Demonstrating compromise was often considered the end goal. | Testing continues through detection and response Businesses increasingly want to understand whether attacks would be detected, contained, and investigated effectively. | Outcome-driven engagements Success will increasingly be measured by improvements to defensive capability rather than the number of vulnerabilities discovered. |
Manual attacker workflows Reconnaissance, exploit development, and attack progression relied heavily on human effort. | AI-accelerated attacker workflows Agentic AI is dramatically reducing the time needed to adapt exploits, perform reconnaissance, and scale attacks. | Autonomous attack orchestration Attackers will increasingly use AI agents to plan, adapt, and execute multi-stage attacks with minimal human intervention. |
Compliance-driven penetration testing Many businesses tested primarily to satisfy audit requirements. | Threat-led assurance Regulations such as DORA are encouraging more realistic, intelligence-led exercises that improve resilience rather than simply achieve compliance. | Evidence-based resilience Boards and regulators will increasingly expect businesses to demonstrate not only that testing has taken place, but that findings have driven measurable improvements to security posture. |
Reactive security improvement Lessons from engagements were often addressed in isolation. | Continuous improvement Red team findings increasingly feed directly into detection engineering, SOC tuning, and security architecture decisions. | Continuous attack simulation As AI enables attackers to operate continuously, businesses will need to validate their controls more frequently through ongoing attack simulation and purple teaming rather than relying on annual engagements. |
What Does This Mean for Your Business?
The role of red teaming in 2026 is fundamentally different from what it was just a few years ago. Businesses can no longer view it as an occasional penetration test designed to tick a compliance box or validate a single control.
Effective red teaming now needs to answer broader questions:
- Could an attacker exploit our AI systems?
- How would our defensive teams detect and respond to a sophisticated attack?
- Which control failures represent our greatest risk?
- Where should we prioritise remediation efforts to maximise resilience?
The most valuable red team engagements are those that help businesses understand how attackers think, improve defensive capabilities, and prioritise investments that meaningfully reduce risk.
As attack techniques continue to evolve, red teaming must evolve with them. Businesses that embrace this more collaborative, attack-chain-driven approach will be significantly better positioned to defend against the threats of today and tomorrow.
Five Things Mature Businesses Are Doing Differently
As attacker techniques continue to evolve, we’re seeing a clear difference between businesses that are simply reacting to threats and those that are continuously improving their security posture. While every business has different priorities and risk profiles, the most mature security programmes consistently share several characteristics.
1. They Focus on Attack Paths, Not Individual Vulnerabilities
One of the biggest shifts we’re seeing is businesses moving away from treating vulnerabilities as isolated technical issues.
The most mature businesses understand that attackers don’t exploit one vulnerability in isolation. They combine multiple weaknesses – whether technical vulnerabilities, excessive permissions, identity compromise or configuration issues – to achieve their objectives.
Rather than asking, “How many critical vulnerabilities do we have?”, they’re asking, “Which attack paths could realistically lead to business impact?” This allows remediation efforts to focus on the weaknesses that genuinely reduce risk, rather than simply reducing vulnerability counts.
2. They Treat Red Teaming as a Continuous Improvement Process
We’re seeing the greatest value from businesses that don’t view red teaming as an annual compliance exercise. Instead, offensive security findings feed directly into defensive improvements. Detection rules are refined, monitoring gaps are addressed, incident response processes are updated, and future engagements are shaped by lessons learned from previous ones.
Rather than asking whether an attack was successful, mature businesses want to understand why it succeeded, whether it would have been detected, and what changes will prevent similar techniques succeeding in future.
3. They Prioritise Visibility as Much as Prevention
Preventing every attack is unrealistic, particularly as AI enables attackers to operate faster and at greater scale. What we’re seeing work with our clients is a greater focus on visibility. Mature businesses want to know whether they would detect privilege escalation, lateral movement and, critically, data exfiltration – not simply whether an attacker gained initial access.
This shift recognises that improving detection and response capability often delivers greater resilience than relying solely on preventative controls.
4. They Minimise Their Attack Surface Before Chasing Every Vulnerability
As the volume of vulnerabilities continues to increase, mature businesses are recognising that they can’t patch everything immediately. Instead, they’re investing time in understanding and reducing their attack surface. Unnecessary internet-facing services are removed, management interfaces are restricted, and systems are designed with the principle of exposing only what’s genuinely required.
This makes it significantly harder for automated attackers and AI agents to identify viable entry points in the first place.
5. They Recognise That AI Requires a Different Testing Approach
Perhaps the biggest change we’re seeing is that mature businesses no longer treat AI-enabled applications like traditional software. Instead of focusing solely on infrastructure or individual vulnerabilities, they’re beginning to assess the entire AI ecosystem, including prompts, APIs, memory, retrieval mechanisms, connected data sources, and the permissions granted to AI agents.
As AI becomes embedded within business-critical processes, businesses are recognising that security testing must evolve alongside it.
Closing Thoughts from Our Red Teaming Experts
“Everyone wants to talk about AI, but many businesses are overlooking the fundamentals. Some of our most successful red team engagements still begin with social engineering or physical compromise because technology is only one part of the attack surface.”
Andy Swift, Cyber Security Assurance Technical Director, Six Degrees
“I’d like to see businesses spend less time prioritising individual vulnerabilities and more time understanding the attack chains that connect them. That’s much closer to how real attackers operate and ultimately gives a far more accurate picture of business risk.”
Simon Kubicsek, Offensive Security Senior Manager, Claranet
Subscribe to the newsletter today
Related posts
How Red Teaming is Evolving in 2026…
Businesses are adopting AI and other new technologies…
Grosvenor Health & Social Care Connectivity
Grosvenor Health & Social Care Large national health…