Showing posts from December, 2023

Why you need to be purple!

 It's Bad For those who have worked with me for longer periods, you would have heard me say at least once that I don't believe in the commonly prescribed structure of blue and red team operations as much as there are good intentions behind the separation of operations, human behaviour has prevailed and there exists a quite toxic environment between the two (wrongly opposing) sides. This is a direct contradiction to  our purpose in cybersecurity which is to harden environments and increase resiliency to cyber-attacks. We need to change While purple teaming was not created to replace blue and red operations I have adopted it to do exactly that. Too often I experience clashes between red team operators and defenders whether its online shouting contests or during client engagements behaviour that does not support the iterative improvement of cybersecurity is simply not welcome. Particularly SOC analysts will know this as they will have experienced their fair share of red team eng