For the past couple of years, I’ve been thinking a lot about red teaming. This might sound funny, since I’ve been thinking and talking about red teaming for 20 years. Perhaps it would be more accurate to say that I’ve been rethinking red teaming. As valuable as I continue to believe the practice is, I’m also coming to believe that it remains immature, in large part because, as proponents and practitioners, we find ourselves caught in a trap of our own making.
In the early years, it was often enough to gain buy-in. Simply persuading a decision maker to red team was usually a “win.” Interest and momentum grew quickly after September 11, and the practice gradually achieved a degree of prestige previously unknown, ultimately risking—as it is today—a level of status to which we might attach the labels “boomtown,” “bandwagon,” or “buzzword.”
And herein lies the trap: our success has outstripped our ability to maintain focus, and, perhaps more concerning, induced a largely unacknowledged complacency. Is it possible that we believe red teaming is perpetually innovative simply because the concept is rooted in critical and contrarian thinking? If so, it’s time to shed that misconception.
Despite the growing interest in red teaming, I haven’t seen an exciting, truly new idea emerge from the community in years. In fact, I noticed the same thing a decade ago when I acted as chair and host for a red teaming conference that drew hundreds of red teamers from around the country. (Raiding the critical thinking, heuristics and biases, and military strategy toolkits worked for a while, but c’mon!—you can only do that for so long.)
Offhand, I can think of a few reasons why the community at least appears to have stagnated:
- The true innovators don’t share. This isn’t a criticism; I get it, and, in fact, I generally keep my more inventive methods to myself and a small set of colleagues.
- It’s currently inundated with newcomers who, wowed by the general coolness of red teaming, will take a while to start innovating.
- The basics work; for now, there’s no need to push beyond them.
- We’ve become complacent (as mentioned above).
- The overall narrative of red teaming is inherently self-limiting (more on this in later posts).
- We’re approaching the frontier of what we can do within the current culture (recall Red Teaming “Law” number one).
The “truth” is most likely a mix of these factors. Regardless, I plan over the next few months to share some thoughts on how and why we should reframe and recalibrate (1) what we mean by “red teaming” and (2) how we conduct it. Doing so will, in my opinion, help us unravel the conceptual tangle red teaming has become, in turn helping us recharge our ability to innovate the practice.
I want to start by splitting the currently overloaded concept of “red teaming” into two branches: the critical thinking branch and the adversarial branch. On this site, I’ve always favored the adversarial branch:
Defined loosely, red teaming is the practice of viewing a problem from an adversary or competitor’s perspective. The goal of most red teams is to enhance decision making, either by specifying the adversary’s preferences and strategies or by simply acting as a devil’s advocate.1
While I still like this definition, I must acknowledge that red teaming, as now understood, includes an ever-larger dose of what I characterize as good old-fashioned critical thinking.2 We see this more or less clearly in the four types of red teaming identified in the DoD’s Joint Doctrine Note 1-16 (“Command Red Teams”): decision support red teaming, critical review red teaming, adversary simulation, and vulnerability assessment. While the first two (decision support and critical review) can certainly employ adversarial thinking, they tend to align more closely with all-purpose critical and contrarian thinking. Of the latter two the first (adversary simulation) is explicitly adversarial while the second (vulnerability assessment) is implicitly so.
I’m certainly not the first to recognize this dichotomy, although I might be the first to assert that we need to fork the adversarial branch with a new name.3 For years, I’ve heard red teamers ask if we need a new term for what we do. I’ve always erred on the side of caution: “Why rebrand the term just as it’s gaining currency?” was always my thought. I’ve now changed my mind; the water’s become too muddy to continue mixing the “let’s challenge our assumptions” version of red teaming with the “think like the adversary” version.
I started my career as a wargamer. As most wargamers know, the modern practice of wargaming derives conceptually and linguistically from the Prussian/German practice of Kriegsspiel, or “war game” (ported into English as Kriegspiel—thanks H.M.). In fact, red teamers often point to Kriegspiel as an antecedent to modern red teaming. With this heritage in mind, I propose dubbing the adversarial branch of red teaming Gegenspiel and the critical thinking branch of red teaming Kontraspiel (for the latter term I must again thank H.M.).
In German, gegen means, among other things, against and versus, and the term Gegenspieler refers to an opponent or adversary, interestingly enough.4 The term kontra can also mean against and versus, but as H.M. has informed me, it brings with it the connotation of playing on the same team.
- Gegenspiel is the practice of exploring a situation from the perspective of an adversary or opponent with the purpose of exposing flaws in plans, strategies, and systems,5 and
- Kontraspiel is the practice of exploring a situation from a critical perspective with the purpose of exposing flawed thinking.
For my part, I plan to move forward employing this dichotomy, allowing me to focus on innovating Gegenspiel while detaching Kontraspiel as a separate practice, one that at times informs Gegenspiel but remains focused on employing normative standards of critical thinking. (To hint further at why I think it’s necessary to fork the two concepts, note that Kontraspiel (as now defined) almost exclusively employs Western standards of critical thinking.)
If you care to join me in employing this dichotomy for the purpose of focusing, refining, and innovating the practice of Gegenspiel, please do. I am, after all, a Gegenspieler at heart, and perhaps you are, too.
- This is the longstanding RTJ definition, available here. [↩]
- I’ve always viewed critical and contrarian thinking as aids or complements to adversarial red teaming, although I probably hedged my bet just a bit by slipping devils advocacy into my own definition. [↩]
- Toby Kohlenberg’s recent slide deck dividing red teaming into the red team and red cell points at this issue. [↩]
- In German, Das Gegenspiel is also a counter-play in the game of bridge. [↩]
- Kriegspiel, in my mind, remains the traditional wargame. In this sense, Gegenspiel is a close cousin of Kriegspiel and can itself inform Kriegspiel. Gegenspiel differs from Kriegspiel in its overarching emphasis on emulating an adversary. Kriegspiel is thus more than Gegenspiel in that Kriegspiel emphasizes (or at least should emphasize) the full reciprocity between opponents. Additionally, Kriegspiel and Gegenspiel are both sensitive to context. In other words, the scenario matters, and key to the art of both is the ability to explicitly define the context in which the players will act. Even when the context is the status quo, it is worth considering what that means. [↩]