Welcome! This short survey (about 7–10 minutes) asks about your experience with our red-team program over the past 12 months. Your responses are confidential and will be aggregated to improve the program. Please answer based on your direct experience.
Which best describes your primary involvement with red-team exercises in the past 12 months?
- Consume findings to make decisions
- Implement technical fixes
- Defensive operations/blue team
- Product or operations stakeholder
- Compliance/governance
- Executive/leadership sponsor
- Other
Approximately how many red-team exercises have you directly engaged with in the past 12 months?
In the past 12 months, how well did red-team exercises cover the following areas?
Overall, how confident are you that red-teaming is focusing on our highest-risk areas?
Allocate 100 points to the areas where additional red-team focus would most reduce risk over the next 6 months.
Which areas seem under-tested relative to their potential impact? (Select up to 3)
- Crown-jewel applications
- Secrets management
- Privilege escalation paths
- Data exfiltration routes
- Human factors/social engineering
- Third-party integrations
- Cloud control plane
- Lateral movement
What reporting cadence do you prefer for red-team results and trends?
Rank the most valuable elements of a red-team report (top = most valuable).
Please rate your agreement with the following statements about our red-team reporting.
Overall, how valuable are red-team findings to your work?
How quickly can teams act on red-team findings after report delivery?
What most hinders follow-through on red-team findings?
- Limited engineering bandwidth
- Disagreement on risk/severity
- Unclear ownership
- Tooling or visibility gaps
- Vendor or third-party dependency
- Competing priorities
- Budget constraints
Please share one example from the past 12 months where a red-team finding led to a meaningful improvement or fix.
Max 600 chars
Attention check: To confirm you are reading the questions, please select "Blue" below.
How mature is our red-teaming program today?
If you could change one thing for the next cycle, what would it be?
Max 100 chars
Which best describes your primary function?
- Engineering/Development
- Security (including blue team)
- IT/Infrastructure
- Product/Operations
- Compliance/Risk/GRC
- Executive/Leadership
- Other
How long have you been in your current role at this company?
Where are you primarily located?
What is your typical work arrangement?
- Onsite
- Hybrid
- Remote
- Prefer not to say
Any other comments or context you want to share?
Max 600 chars
AI Interview: 2 Follow-up Questions on Red-Teaming
Thank you for your time—your input directly informs how we improve red-teaming impact and reporting.