Industries in Focus

Penetration Testing and Red Teaming: What Companies May and Must Do

Penetration Testing and Red Teaming: What Companies May and Must Do

Penetration Testing and Red Teaming: What Companies May and Must Do

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann

A team of IT security experts attacks its own systems. Not out of sabotage, but on commission. They step into the role of real attackers, look for vulnerabilities, test passwords, try to penetrate networks – and document everything. What sounds like a paradoxical exercise is today one of the most effective methods of cyber defense: the penetration test. And for many companies, it has long since ceased to be a voluntary option and has become a legal obligation.

In his research, Teichmann has precisely analyzed both the regulatory requirements and the criminal law boundaries of such tests. The question of what companies are allowed, required, and must absolutely avoid doing during penetration tests and red teaming has an answer – but it is more complex than many assume (Teichmann & Boticiu, An Overview of the Benefits, Challenges, and Legal Aspects of Penetration Testing and Red Teaming, International Cybersecurity Law Review 2023, pp. 1–11).

What Penetration Testing and Red Teaming Are

A penetration test is an authorized, simulated attack on IT systems, networks, or applications with the aim of identifying security vulnerabilities before real attackers do. The penetration tester acts on behalf of the company, with its express written permission, within a defined scope and at an agreed time.

Red teaming goes one step further. While a classic penetration test is often focused on specific systems, a red team simulates a full, realistic attack on the company – often without the internal IT security team's knowledge. The goal is not only to identify technical vulnerabilities, but to test the organization's entire detection and response capability (Teichmann & Boticiu, ICLR 2023, pp. 1–11).

The difference is significant: A penetration test answers the question "What technical vulnerabilities do we have?" A red team engagement answers the question "Could a real attacker compromise our company – and would we even notice?"

Why Penetration Tests Are Mandatory Today – or Will Be Soon

DORA explicitly obligates significant financial institutions to conduct regular threat-led penetration tests (TLPT). These red team exercises must be carried out at least once every three years by independent, qualified testers and according to an EU-wide harmonized framework. The results must be reported to the supervisory authority, and critical findings must be remediated within specified deadlines. The model is the TIBER-EU framework, which was already established in Germany as TIBER-DE (Teichmann, Digital Operational Resilience Act – EU-widely uniform IT security rules for financial institutions, BB 2025, pp. 2760–2770).

NIS-2 requires essential and important entities to take appropriate technical and organizational measures. Regular penetration tests are considered an accepted part of the state of the art and are therefore implicitly required. Anyone who does not conduct them risks having to prove, in the event of an incident, that they nevertheless complied with the state of the art without these measures – a difficult proof to establish (Teichmann, NIS2 training obligation of the management, Computer and Law 2025, pp. 718–725).

The IT Security Act 2.0 has obligated CRITIS operators since May 2023 to use attack detection systems that continuously and automatically monitor operating parameters. Penetration tests are the tool used to verify whether these detection systems actually work (Teichmann, IT Security Act 2.0 in Practice: Attack Detection and Critical Components, BB 2025, pp. 1993–1998).

The Criminal Law Boundary: When Does the Ethical Hacker Become a Criminal?

Section 202a of the German Criminal Code (StGB) criminalizes the spying on of data – up to three years of imprisonment for anyone who obtains unauthorized access to specifically secured data. Section 202c StGB – the so-called hacker paragraph – criminalizes even the preparation of such acts, i.e., obtaining or producing hacking tools. And Section 303b StGB, computer sabotage, applies when IT systems are disrupted by testing activities.

The decisive ground for justification is the consent of the authorized party. Anyone who, as the owner or operator, gives explicit permission to a penetration tester thereby removes the illegality of the otherwise punishable acts.

But this consent must meet certain requirements. It must be granted by the person who is actually authorized to dispose of the system. It must be granted before the start of the test – subsequent authorization does not cure a criminal offense. It must cover the specific scope of the test: actions outside the agreed scope lose the protection of consent. And it must be documented in writing, because in the event of a dispute, it must be proven that valid consent was present (Teichmann & Boticiu, ICLR 2023, pp. 1–11).

What the Contract Must Accomplish

A legally secure penetration test contract must contain several core elements. The scope must be precisely defined: Which systems, networks, applications, and IP address ranges may be tested? What is explicitly excluded? The time period must be established. The permitted methods must be described: May social engineering be used? Physical access? Denial-of-service simulations? Data exfiltration to test detection?

Regulations for emergencies are emergency elements: What happens if the tester encounters actual, non-simulated attacks? A hotline number through which the test can be aborted immediately is mandatory. And confidentiality regulations must ensure that the test results do not fall into the wrong hands (Teichmann & Boticiu, ICLR 2023, pp. 1–11).

Third-Party Providers and the Cloud: The Underestimated Legal Problem

In the modern IT landscape, almost all companies use cloud services, SaaS applications, and external hosting providers – and these third-party providers have their own terms of use that may restrict or prohibit penetration tests on their infrastructure. Major cloud providers allow testing on rented infrastructure but require either prior notification or exclude certain testing methods. Anyone who ignores this risks not only the termination of the cloud contract but also legal consequences.

The NIS-2 regime addresses this issue through supply chain responsibility: companies must actively manage the security of their IT service providers and have the right to request security audits. This right of audit should already be anchored when concluding contracts with IT service providers – a penetration test that does not cover third-party provider infrastructure only provides an incomplete picture of the actual attack surface.

Red Teaming and Special Diligence

Red team exercises without the knowledge of the blue team involve special risks. The internal IT security team may react to the simulated attack as if it were a real one: shutting down systems, informing external bodies, activating emergency plans. Teichmann therefore recommends a clear escalation structure: A small group of trusted individuals – typically the CISO and executive management – knows about the exercise and can intervene in an emergency. A hotline that can be reached immediately is mandatory. And the legal documentation must be designed in such a way that it can be presented immediately to authorities or law enforcement in an emergency (Teichmann & Boticiu, ICLR 2023, pp. 1–11).

Taking Results Seriously – A Legal Mandate

Teichmann's research shows that many companies have penetration tests conducted without actually utilizing the results. A test whose findings disappear into a drawer is not only wasted budget – it legally creates a dangerous situation. Anyone who knows that vulnerabilities exist and does not remediate them acts culpably. Under DORA, financial institutions are explicitly required to address critical findings from TLPT tests within specified deadlines and to report on them to the supervisor (Teichmann, BB 2025, pp. 2760–2770).

Conclusion: Attack as the Best Defense – Legally Secured

Penetration tests and red team exercises are today the most effective tool to measure a company's actual resilience against cyberattacks. No technical concept and no security audit can replace what an ethically simulated attack brings to light.

Teichmann's research shows that the legal foundations for such tests are clear but demanding. Valid consent, precise scope, legally secure contracts, and a structured remediation process are the fundamental prerequisites. And for more and more companies, this test is no longer an option – but a duty.

All sources refer to published scientific contributions by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the publication index (as of May 2026).

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.