The Market Turns Toward Hospitals and Grids
The red teaming market has long been a financial-services story. Banks and insurers bought continuous attack simulation because regulators demanded it and breaches cost millions. Now the buying center is shifting. Hospitals and power utilities — sectors where downtime can kill — are signing contracts for always-on red teaming at an accelerating pace.
The numbers confirm the turn. The global Red Team as a Service market reached roughly $1.4 billion in 2024, GrowthMarketReports reported, and projects to triple within a decade, per analyses from DataIntelo and GrowthMarketReports. North America still commands the largest slice, 43% of global revenue, or about $600 million last year, but the growth conversation has moved to who is buying.
| Region | 2024 Revenue (DataIntelo) | 2024 Revenue (GrowthMarketReports) | Projected CAGR (DataIntelo) | Projected CAGR (GrowthMarketReports) |
|---|---|---|---|---|
| North America | USD 593 million | USD 610 million, GrowthMarketReports' data shows | 13.2% | Not specified |
| Europe | USD 414 million | USD 370 million, GrowthMarketReports found | Not specified | 17.2% |
| Asia Pacific | USD 276 million | USD 280 million, GrowthMarketReports' figures put | 17.1% | 22.4% |
The BFSI sector still holds the largest single vertical share, but research flags healthcare and energy & utilities as the next adoption wave. Healthcare is driven by stringent data-protection rules and ransomware. Energy providers focus on critical infrastructure protection, language that appears in both research digests.
What distinguishes this expansion is the deployment model. In 2024, cloud-based deployment accounted for a significant share of new implementations across organizations of all sizes. The scalability of cloud-delivered platforms makes continuous simulation feasible for hospital systems and regional utilities that lack the security headcount of large financial institutions. The services segment, human-led engagements, not just software, still holds the dominant revenue share, reflecting the reality that effective red teaming requires adversarial expertise most critical-infrastructure operators cannot hire internally.
Large enterprises remain the primary revenue base, but a rising SME tier is pulled in by supply-chain mandates: large organizations increasingly require vendors and partners to undergo regular red teaming. That dynamic extends the market downward into regional health networks and municipal power authorities.
Regulatory frameworks, including HIPAA, GDPR, PCI DSS, and emerging critical-infrastructure mandates, compel proactive testing. Digital transformation in both sectors has exploded the attack surface: connected medical devices, telemedicine platforms, SCADA systems, and smart-grid infrastructure. Traditional penetration testing, a point-in-time snapshot, cannot keep pace. Continuous simulation can. That is the market logic driving the expansion.
Why the Attack Surface Won't Wait
Healthcare and energy aren't adopting continuous red teaming because it's trendy. They adopt because their attack surfaces have become unmanageable by periodic testing, and regulators are moving beyond check-the-box compliance as a substitute for security.
Start with healthcare. The sector runs on a collision of decades-old legacy systems and explosive IoMT growth — infusion pumps, imaging devices, patient monitors — all speaking unencrypted HL7 and DICOM protocols that anyone sniffing traffic can read for PHI. Akamai's 2024 healthcare threat report documented a monthly average of 21 million web application and API attacks against providers, plus 415 million Layer 7 DDoS attacks. Payers absorbed 41% of API attacks targeting the healthcare ecosystem, driven by CMS interoperability rules mandating Patient Access APIs, Provider Directory APIs, and Payer-to-Payer APIs, all built on FHIR standards requiring web application firewalls, authentication, encryption, and microsegmentation. The Prior Authorization API mandate is coming next. Each new API is a new entry point; API sprawl means shadow APIs live outside security controls entirely.
Ransomware exploits the gap. Healthcare posts the highest breach costs of any industry for 13 consecutive years, with a $9.77 million average in 2024 versus $6.08 million for financial services. HHS data shows 3,604 patient records breached every hour. The February 2024 Change Healthcare attack that paralyzed pharmacy payments nationwide proved the cascade: no records, no coordination, ambulances diverted, paper charts resurrected. Double-extortion ransomware now exfiltrates before encrypting; Darktrace observed 200+ MB uploaded to external endpoints matching a single JA3 hash before SMB-based propagation encrypted thousands of files across a hospital network.
The ransomware crisis has forced hospital boards to treat security as a patient-safety issue, not an IT line item.
Energy faces a different but converging problem. Fortinet's 2024 OT security report found 31% of organizations suffered six or more intrusions, up from 11% a year prior. Only 5% maintain full visibility of OT activity in central security operations, down from 13% in 2022. Phishing targeting OT environments jumped from 49% to 76% year-over-year. Killnet's DDoS campaigns disproportionately hit pharmaceutical and biotechnology firms, and ENISA attributes the DDoS surge directly to geopolitical developments and pro-Russian hacktivist groups.
The convergence is the accelerant. IT, OT, and IoMT are already merged; threat actors know it. Darktrace's 2026 analysis of top-20 U.S. hospitals found one — one — full-time employee with an OT cybersecurity certification. Top-20 utilities had 73. Financial services had 18. Hospitals divert security spend toward ransomware-prone IT systems, leaving OT exposed.
Regulation hardens. The SEC's Cybersecurity Incident Disclosure Provision demands timely public breach announcements. CMS rules enforce FHIR security baselines. HIPAA and HITRUST have long existed, but Akamai notes that between a quarter and half of top-1,000 hospitals still use the same spreadsheet-based security checklist to onboard vendors, shifting risk via Business Associate Agreements instead of building expertise. That model is collapsing. Periodic penetration tests cannot validate defenses against adversaries who operate continuously. Continuous red teaming is the way to test detection and response at the speed the attack surface now demands.
GhostEye Rewires Its Agents for the Physics Layer
GhostEye pivoted from insider-threat prediction to autonomous red-team automation in 2025. The New York team, backed by Y Combinator, rebuilt the platform around a continuous "autonomous security loop": map each employee's public OSINT exposure, generate personalized phishing, voice, SMS, and deepfake campaigns, then follow successful compromises into internal systems to validate whether detections and EDR catch what gets through.
For healthcare and energy customers, that loop required modifications. First, GhostEye extended the IRIS reconnaissance suite, originally tuned for corporate email and LinkedIn footprints, to ingest medical-device vendor portals, HL7/FHIR interface documentation, and FDA recall notices. Second, GhostEye added SCADA-specific social-engineering playbooks to the voice-agent module, built to test help-desk MFA bypasses. Third, GhostEye wired the post-exploitation validation layer for the SIEM stacks common in regulated environments. The platform maps each simulated kill chain to NIST CSF 2.0 controls PR.AT (awareness training) and ID.RA (risk assessment), giving compliance teams a single evidence package for auditors.
Early adopters report that the continuous, adaptive campaigns, spaced-repetition training triggered by actual failure modes, not calendar dates, cut click rates 58 percent in one quarter while tripling phish-reporting volume, because the simulations mirror live tradecraft instead of recycled templates. The hiring plan reflects the domain shift: GhostEye's two open roles in operations and engineering now list OT protocol familiarity and healthcare data-flow experience as preferred qualifications.
Where the Evidence Runs Thin
The evidence base for continuous red-team adoption in healthcare and energy remains thinner than the market narrative suggests. GhostEye's own published testimonials, the most concrete source available, show one clear healthcare customer and a handful of technology and finance references, but no named utility or energy-sector pilots with disclosed metrics.
Fella Health, a digital health company, is the only healthcare organization GhostEye identifies by name. Its VP of Engineering, Gzim Helshani, said the platform "helps us move beyond checkbox security awareness with realistic, role-specific simulations that reflect how attackers would actually target our team." GhostEye disclosed no click-rate reduction, reporting uplift, or detection-time improvement. The company's size, regulatory environment, and simulation scope remain undisclosed.
GhostEye's only quantified outcome comes from a Fortune 500 financial services CISO: click rates dropped 58% and reporting tripled in one quarter. That is a finance result, not healthcare or energy. The same page lists Eight Sleep (consumer hardware), ZeroPath (security vendor), and Casco (unnamed sector) with qualitative endorsements but no numbers.
No utility, grid operator, or energy company appears in GhostEye's public reference list. The Raytheon GhostEye MR radar, a completely separate air-defense system, has documented test results with NASAMS and U.S. Air Force validation, but those are missile-defense exercises, not cyber red-team pilots.
Other vendors are similarly sparse on named critical-infrastructure pilots. Bishop Fox markets continuous testing platforms (Cosmos) and lists enterprise customers, but public case studies emphasize financial services, SaaS, and retail. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) runs vulnerability scanning for critical infrastructure, not adversary simulation. The Department of Energy's Cybersecurity for Energy Delivery Systems (CEDS) program funds research into OT-specific red teaming, yet publicly disclosed pilot outcomes with commercial RTaaS vendors are absent from recent program reports.
The gap matters. Healthcare and energy buyers face constraints — patient-safety regulations, OT change-control boards, safety-instrumented-system certification — that make "authorized attacks on your people, followed into your systems" (GhostEye's tagline) harder to scope than in a bank. Vendors claim OT-safe simulation modes, but without named pilots showing detection-rate improvements in those environments, the claims are unvalidated.
Research shows a pattern: early adopters in healthcare are digital-health or health-tech firms (Fella Health, Eight Sleep) with modern stacks and fewer legacy OT dependencies. Traditional hospital systems and integrated delivery networks, Epic-on-prem, VLAN-segmented, biomedical-device-heavy, are not yet in the public reference set. Energy is further behind. Until a regional transmission organization or a Generation 3 nuclear operator publishes a pilot report with before/after detection metrics, the "early pilots" chapter for critical infrastructure remains largely unwritten.
The Old Guard Chooses Sides
The always-on red team wave forces established firms to choose: build continuous platforms, partner with specialists, or watch the market bifurcate. Bishop Fox, an Arizona-based firm that has run offensive engagements since 2005, made its move explicit in 2024 by becoming a Health-ISAC Affiliate Partner, a designation that requires meeting the healthcare sharing center's vetting standards for sector-specific expertise. The partnership covers penetration testing, red teaming, continuous threat exposure management, and incident response simulations tailored to EHR/EMR platforms, medical devices, health plan systems, clinical applications, and third-party vendor ecosystems. Bishop Fox says it aligns testing and reporting to the frameworks that govern the sector: HIPAA, HITECH, FDA 21 CFR Part 11 for medical device cybersecurity, HHS 405(d), CMS requirements, NIST CSF, SOC 2, ISO/IEC 27001, and CISA healthcare guidance. The firm also offers ransomware readiness assessments and tabletop exercises designed for healthcare executives, security teams, and operational leaders, and performs hardware and software assessments of connected medical devices subject to FDA 21 CFR cybersecurity requirements.
Bishop Fox's Cosmos platform, recognized as Best Emerging Technology by SC Media, is the vehicle for that shift. The platform extends the firm's traditional consulting model into continuous attack surface management, and the company has opened remote roles for red team consultants in the U.S. and Mexico to staff the recurring engagements that Cosmos enables. With 1,700-plus customers, including 80 percent of the top 10 tech firms and a quarter of the Fortune 100, plus a reported 70 NPS, Bishop Fox has the scale to convert its project-based backlog into recurring revenue.
Mandiant, now operating under Google Cloud, takes a different route. Its penetration tests remain tailored to an organization's environment, assessing critical systems, networks, applications, and physical security controls, while Mandiant Technical Assurance Consulting focuses on validating security response plans, staff capabilities, and operational controls under pressure. The differentiator Mandiant leans on is the Mandiant Threat Intelligence Portal, free access for customers, which feeds real-time actor profiles into the scoping of each engagement.
Meanwhile, AI-native entrants compress the timeline from scope to first finding. Strike, a cybersecurity startup, markets an AI-powered continuous penetration testing platform that automates the testing process, enabling enterprises to launch tests rapidly, monitor vulnerabilities in real time, and generate reports without the weeks-long scheduling dance of traditional firms. In Tel Aviv, Tenzai raised $75 million to build what it calls "synthetic hackers" — autonomous agents that find and exploit vulnerabilities on their own. The bet across both camps is that the labor constraint that kept red teaming episodic can be broken by agentic tooling, and that healthcare and energy buyers will pay a premium for speed and repeatability.
The talent market already reflects the shift. Bishop Fox's open roles emphasize red teaming experience in remote, distributed teams. Mandiant's consulting listings stress incident response and threat hunting backgrounds. For the newer platforms, the hiring profile skews toward ML engineers who can harden agent logic against false positives in OT and medical device networks. None of the established players has published a public energy-sector partner program yet, but the Health-ISAC move suggests a playbook: pick a regulated vertical, codify the regulatory mapping, then productize the engagement model.
Three Walls That Code Can't Scale
The push into healthcare and energy collides with three hard constraints that no AI platform can code around. First, the talent pipeline for offensive security with domain fluency is effectively broken. The (ISC)² 2024 Cybersecurity Workforce Study puts the global gap at 4.8 million unfilled roles, a 19 percent year-over-year jump, with demand at 10.2 million against a workforce of 5.5 million. In healthcare, only 14 percent of IT leaders say their security teams are fully staffed; nearly 30 percent describe them as understaffed or severely understaffed. Public-sector organizations, which include many utilities, fare worse: 49 percent lack the talent to meet security goals, up a third from 2023. Budget cuts have overtaken talent scarcity as the primary driver, with a third of leaders citing lack of budget and 39 percent citing skills gaps, and 2024 saw 37 percent of organizations cut cybersecurity budgets, a quarter lay off security staff, and 38 percent freeze hiring. The skills gaps that matter most for continuous red teaming, including AI/ML security, cloud security, zero trust, digital forensics, and web application penetration testing, are precisely the specialties healthcare and energy demand. Nearly a third of security teams have zero entry-level professionals, choking the pipeline before it starts.
Second, deploying continuous simulations on live operational technology is a different problem set than phishing a corporate inbox. Energy utilities run SCADA systems, historians, and safety instrumented systems that cannot tolerate the latency, traffic patterns, or unpredictable behavior of an active red team agent. A simulation that triggers an emergency shutdown or corrupts a historian database creates the very outage it was meant to prevent. OT networks often lack the monitoring infrastructure, such as SPAN taps, NetFlow, and EDR, that IT teams take for granted, so the "follow them into your systems" validation loop breaks down at the Purdue Level 3/2 boundary. Vendors are building OT-safe modes, including read-only reconnaissance, scheduled windows, and synthetic traffic replay, but each concession narrows the realism that makes continuous testing valuable. The IT/OT convergence driving regulatory pressure also means the attack surface spans both domains, yet the talent who understand both is vanishingly small.
Third, patient and data privacy restrictions turn every simulation into a compliance review. The Change Healthcare attack exposed 192 million records. HIPAA's proposed 2026 Security Rule updates will tighten requirements for penetration testing scope, data handling, and breach notification. Simulated phishing that touches protected health information, even in a test harness, triggers the same audit trail as a real incident. Deepfake vishing against a hospital help desk must avoid generating or storing voice prints that constitute biometric data under state privacy laws. Energy utilities face NERC CIP standards that treat certain simulation artifacts as critical energy infrastructure information, restricting how results are stored and shared. Vendors that once sold a SaaS dashboard now need on-premises deployment options, data residency guarantees, and evidence destruction workflows, each a product engineering investment that slows the very speed-to-value that continuous testing promises.
The loop closes on itself: the sectors with the most urgent need for continuous red teaming are the ones where talent, OT safety, and privacy constraints make it hardest to deliver. Organizations with high security skills shortages already pay a $1.76 million premium on breach costs. AI and automation can shave more than $2 million off that delta and close detection gaps by nearly 100 days, but only if they can be deployed without violating the constraints above. The vendors that solve the deployment model — not just the simulation engine — will own the market.
Working in frontier tech? Zero G Talent tracks the openings: see every open ASML role, browse frontier tech jobs, openings at Stripe, and the people building the field.