Plan my session
Plan a concrete work block with agenda, roles, preparation, and a copyable result artifact.
Session: Red Teaming
The plan translates the method into a concrete facilitated work block. Your inputs flow directly into the session brief and work artifact.
Method session with 3-8. The plan uses the existing method logic and the runsheet.
RunsheetUse the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
The session works directly toward Challenge Findings. After the session, the artifact should be shareable, reviewable, or reusable.
- 1
Phase 1: Red Team preparation
4-8 hRed Team studies the artifact. Generates attack tree or list. Per attack: vector, required capabilities, effect, probability, existing mitigation. Hint: Red Team needs time and distance. Without preparation, Red Teaming becomes discussion round. External people are often more creative than internal ones.
FacilitatorChallenge Findings - 2
Phase 2: Context and rules
30 minModerator briefly presents artifact. Red Team and original team ask understanding questions. Rules clear: original team listens, answers facts, does not defend. Hint: Defense reflex is the most common method error. Clear rule: discussion only in Phase 4.
FacilitatorRisk Register - 3
Phase 3: Attack presentation
2-3 hRed Team presents attacks systematically. Per attack: vector, scenario, effect. Original team asks only for understanding, not rebuttal. Hint: If original team interrupts and defends, moderator interrupts back. Presentation must be complete before evaluation starts.
FacilitatorMitigation Plan - 4
Phase 4: Evaluation and prioritization
90 minPer attack, evaluate effect, probability and mitigation effort. Original team adds context that changes probability. Top attacks go to risk register as risks. Hint: Probability is subjective. Consensus is not required, but rationale must be documented.
FacilitatorChallenge Findings - 5
Phase 5: Mitigations and follow-ups
60-90 minSketch mitigation per top attack (prevention, detection, response). Owner and deadline. Log changes to artifact. Hint: Mitigation must be concrete. "More monitoring" without detail is not mitigation. Owner mandatory.
OwnerRisk Register - 6
Publish artifact
10 minCheck the artifact for completeness, define location, set version or status, and name review recipients.
OwnerChallenge Findings
Session Brief
For invitations, boards, tickets, PR descriptions, or workshop notes.
session-brief.md
Session Brief: Red Teaming
Goal
Artifact: Challenge Findings
Working Question
Which attack vectors, weaknesses or entry paths overcome the artifact, and which of these vectors are likely enough to justify mitigation?
Context
Provide artifact 2-3 days before workshop; clarify context and assumptions; known attack patterns in domain (security: OWASP; business: competitor moves); time limit for Red Team preparation.
Setup
- Format: Method session
- Duration: 1-2 days (1 day preparation, 4-8 h workshop)
- Mode: Workshop
- Participants: One Red Team (3-5 people), ideally external to the original team; one original-team representative for understanding questions (not defense); one moderator; one scribe.
- Owner: One Red Team (3-5 people), ideally external to the original team
- Participation mode: Team round, shared work and alignment
- Outcome logic: Finish artifact
Participation Logic
Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.
Outcome Logic
The session works directly toward Challenge Findings. After the session, the artifact should be shareable, reviewable, or reusable.
Input
Complete documents for the artifact (strategy, architecture, plan); whiteboard or Miro with attack table (attack vector, effect, probability, mitigation); STRIDE/PASTA templates for security if needed.
Preparation
Red Team works autonomously on attack strategies before workshop. Workshop has clear rules: original team does not defend, but listens and notes. Q&A only after complete presentation.
Agenda
-
Phase 1: Red Team preparation (4-8 h) Owner: Facilitator Action: Red Team studies the artifact. Generates attack tree or list. Per attack: vector, required capabilities, effect, probability, existing mitigation. Hint: Red Team needs time and distance. Without preparation, Red Teaming becomes discussion round. External people are often more creative than internal ones. Output: Challenge Findings
-
Phase 2: Context and rules (30 min) Owner: Facilitator Action: Moderator briefly presents artifact. Red Team and original team ask understanding questions. Rules clear: original team listens, answers facts, does not defend. Hint: Defense reflex is the most common method error. Clear rule: discussion only in Phase 4. Output: Risk Register
-
Phase 3: Attack presentation (2-3 h) Owner: Facilitator Action: Red Team presents attacks systematically. Per attack: vector, scenario, effect. Original team asks only for understanding, not rebuttal. Hint: If original team interrupts and defends, moderator interrupts back. Presentation must be complete before evaluation starts. Output: Mitigation Plan
-
Phase 4: Evaluation and prioritization (90 min) Owner: Facilitator Action: Per attack, evaluate effect, probability and mitigation effort. Original team adds context that changes probability. Top attacks go to risk register as risks. Hint: Probability is subjective. Consensus is not required, but rationale must be documented. Output: Challenge Findings
-
Phase 5: Mitigations and follow-ups (60-90 min) Owner: Owner Action: Sketch mitigation per top attack (prevention, detection, response). Owner and deadline. Log changes to artifact. Hint: Mitigation must be concrete. "More monitoring" without detail is not mitigation. Owner mandatory. Output: Risk Register
-
Publish artifact (10 min) Owner: Owner Action: Check the artifact for completeness, define location, set version or status, and name review recipients. Output: Challenge Findings
Closeout
- Update result artifact: Challenge Findings
- Define location, version, and review recipients.
- Define owner, next step, and review date.
Work artifact
Pre-filled starting point based on the matching template.
work-artifact.md
Challenge Findings: Red Teaming
Working Question
Which attack vectors, weaknesses or entry paths overcome the artifact, and which of these vectors are likely enough to justify mitigation?
Context
Provide artifact 2-3 days before workshop; clarify context and assumptions; known attack patterns in domain (security: OWASP; business: competitor moves); time limit for Red Team preparation.
Participants
- Owner: One Red Team (3-5 people), ideally external to the original team
- Participants: One Red Team (3-5 people), ideally external to the original team; one original-team representative for understanding questions (not defense); one moderator; one scribe.
Input
Complete documents for the artifact (strategy, architecture, plan); whiteboard or Miro with attack table (attack vector, effect, probability, mitigation); STRIDE/PASTA templates for security if needed.
Template
Red Teaming Working Template
Goal
Challenge assumptions, expose weak spots, and strengthen the plan, strategy, or design.
Context
When and for what do we use this method?
Input
Which data, observations, decisions, or materials are available?
Working area
- Scope:
- Attack points:
- Weak assumptions:
- Findings:
- Mitigations:
Output artifacts
- Challenge notes:
- Risk register:
- Mitigation plan:
Open questions
- ...
Next step
Owner, date, and success signal.
Completion Check
- Challenge Findings is complete enough for review:
- Location:
- Version / status:
- Review by:
- Next step:
Next Step
- Review result
- Mark open questions
- Schedule review or decision
Red Teaming Working Template
View templateCompact working template for Red Teaming with challenge scope, attack points, findings, and mitigations.markdown
red-teaming-working-template.md
Compact working template for Red Teaming with challenge scope, attack points, findings, and mitigations.
Red Teaming Working Template
Goal
Challenge assumptions, expose weak spots, and strengthen the plan, strategy, or design.
Context
When and for what do we use this method?
Input
Which data, observations, decisions, or materials are available?
Working area
- Scope:
- Attack points:
- Weak assumptions:
- Findings:
- Mitigations:
Output artifacts
- Challenge notes:
- Risk register:
- Mitigation plan:
Open questions
- ...
Next step
Owner, date, and success signal.
- Working question, owner, and target artifact are visible.
- The result fits Challenge Findings.
- One entry per Red Team session with date and artifact version. Mitigations tracked separately over time. New Red Team run for major changes to artifact.
- Open questions are noted as follow-ups.
- The next review or decision point is scheduled.