Red team exercises provide the most insight into your blue-team’s readiness to face an attack. The goal you choose to task the red team with will obviously have a material effect on what happens next. The more responsive control the attacker wants over the compromised machine, the easier (at least in theory) it will be for the target organization to detect it. Most red team exercises take at least two weeks to prosecute the more elaborate ones may run for a couple of months. Having an in-house staff who can perform exercises will certainly reduce the perceived cost as long as you don’t run the math on how much you pay them daily.”]
Source: https://www.csoonline.com/article/3250249/anatomy-of-a-well-run-red-team-exercise.html

