The Practice War Is Not the Real War: Why Simulated Attacks Cannot Close the Adversarial Imagination Gap
There is a quiet fiction embedded in the way most enterprises think about red teaming. The fiction goes something like this: if we hire skilled people, give them realistic tools, and task them with breaking our defenses, we will learn what a real adversary would do. We will find the gaps before they do. We will be ready.
It is a compelling story. It is also, in critical ways, structurally false.
The problem is not competence. Many internal red teams and contracted penetration testers are exceptionally skilled. The problem is constraint architecture—the invisible set of rules, timelines, organizational sensitivities, and institutional pressures that govern every simulated engagement but constrain no actual adversary. That asymmetry is not a staffing problem. It cannot be solved by hiring better testers or running longer engagements. It is a foundational property of the exercise itself.
What the Clock Does to a Red Team
A contracted penetration test typically runs for days or weeks. An authorized red team engagement might extend to a few months under favorable conditions. These are not arbitrary numbers; they reflect budget cycles, legal agreements, and the organizational patience of stakeholders who want results before the next board meeting.
A determined nation-state actor or a sophisticated criminal organization operates on no such schedule. Documented intrusions have revealed dwell times measured in months before any lateral movement occurred—adversaries who mapped network architecture, observed authentication patterns, and waited for a specific personnel change before escalating access. The 2020 SolarWinds campaign, to cite the most prominent recent example, involved a supply chain compromise that had been in preparation for well over a year before its payload was delivered to thousands of downstream targets.
No red team engagement is scoped to replicate that patience. The organizational cost of doing so would be prohibitive, and the legal exposure of granting that level of sustained access to a third party is something most general counsels will not authorize. The clock is not a detail. It is a structural advantage that every external adversary holds by default.
The Known-Scenario Problem
Red teams attack what they can see, what they know, and what their methodology accommodates. They arrive with threat intelligence, with frameworks like MITRE ATT&CK, and with a mental model of what a reasonable adversary would attempt. These are genuine assets. They are also, paradoxically, limitations.
External adversaries are not constrained by published frameworks. They innovate against unknown defenses. When your organization deploys a new authentication layer, an internal red team will test it against documented bypass techniques. An adversary with no prior knowledge of your environment will probe it with curiosity that has no methodological ceiling. They will find the interaction between your new authentication layer and your legacy VPN client that nobody thought to include in the threat model because that specific combination had never appeared in a CVE database.
This is the adversarial imagination gap. Defenders prepare for known attack scenarios. Adversaries innovate against unknown defenses. The asymmetry is not about technical sophistication—it is about the direction of information flow. The red team knows what it is looking for. The adversary does not know what it will find, and that ignorance is operationally generative in ways that structured testing cannot reproduce.
Organizational Gravity and the Limits of Internal Simulation
Even the most empowered internal red team operates inside organizational gravity. There are systems that cannot be touched during business hours. There are executives whose workstations are implicitly off-limits. There are third-party integrations where the vendor relationship is too commercially sensitive to stress-test. There are findings from previous engagements that were documented, escalated, and then quietly deprioritized because remediation would have required a platform migration that finance would not fund.
External adversaries feel none of this gravity. They have no relationship with your ERP vendor to protect. They are indifferent to your quarterly earnings cycle. The executive workstation that your red team agreed to exclude from scope is, from an adversary's perspective, simply another high-value target with elevated privileges and a user who is statistically less likely to have received recent security awareness training.
Organizational gravity does not make red teaming worthless. It makes red teaming something different from what it is often sold as: not a rehearsal for the actual conflict, but a constrained diagnostic tool that surfaces a subset of exploitable conditions under a specific set of negotiated rules.
Architectural Honesty as a Response
If the gap cannot be closed, the productive response is to stop pretending it can be and to design security architecture that acknowledges it explicitly.
This begins with a shift in how red team findings are interpreted. A clean engagement does not mean an organization is secure. It means that a skilled team, operating under defined constraints and a finite timeline, did not find a path to the defined objectives. Those are meaningfully different claims. Security leadership that treats the former as evidence of the latter is building confidence on a structural misreading.
Architectural thinking that accepts the adversarial imagination gap tends to produce different design priorities. Rather than optimizing for preventing all initial compromise—a goal that the asymmetry of time and creativity makes increasingly unrealistic—it invests heavily in limiting the blast radius of compromise once it occurs. Micro-segmentation, rigorous identity federation, and aggressive least-privilege enforcement are not primarily about stopping the attacker at the perimeter. They are about ensuring that the adversary who has already entered through the gap your red team never found cannot convert that foothold into a catastrophic outcome.
Detection fidelity becomes equally critical under this framing. If you accept that an adversary may be operating in your environment under conditions your red team never simulated, the question shifts from "how do we prevent entry" to "how quickly and reliably do we detect anomalous behavior that does not match any known attack pattern." Behavioral baselines, anomaly detection tuned to your specific environment rather than generic signatures, and human analysts who are empowered to investigate ambiguous signals without waiting for a high-confidence automated alert all become strategic priorities rather than secondary concerns.
The Honest Red Team Conversation
None of this argues against red teaming. It argues against the mythology that surrounds it. The most valuable red team engagements are not the ones that declare an organization ready for adversarial contact. They are the ones that surface specific, remediable weaknesses while being transparent about the structural limits of the exercise itself.
The red team that tells you it found nothing should prompt more concern, not less. The engagement that surfaces a critical path to domain compromise under artificial time pressure and negotiated scope is delivering genuine intelligence. The engagement that returns a clean report after two weeks of testing is either evidence of exceptional defensive maturity or evidence that the test was not designed to find what an adversary with eighteen months of patience and no organizational constraints would eventually locate.
The adversarial imagination gap is not a failure of the security industry. It is a structural feature of asymmetric conflict. Defenders who understand that asymmetry—who build for it rather than against it—are operating in a more honest and ultimately more resilient posture than those who believe the practice war and the real war are the same engagement.