Glossary · simply explained

Red team, blue team, purple team

The colour scheme of security describes roles: the red team simulates realistic attacks on the organisation, technology and people; the blue team defends — detecting, analysing and responding day to day. Purple teaming is not a third squad but a working mode: attackers and defenders collaborate openly, technique by technique.

The purpose is always the same: replace assumptions with evidence. Not whether an attack would be possible, but whether it is detected and stopped — that is the question.

How do the exercise formats differ?

A penetration test looks for as many vulnerabilities as possible within a defined scope. A red team engagement pursues one objective — such as access to a specific system — by any path, often over weeks and without warning the defenders: a test of the entire detection and response chain.

Purple teaming turns that into a learning cycle: together, a technique (from MITRE ATT&CK, say) is executed, alerts are checked, detection is sharpened — and repeated. Per exercise day this yields more measurable improvement than any blind test.

Which exercise fits when

  • Penetration test: systematically find vulnerabilities of an application or environment.
  • Red team: realistically test the maturity of detection and response — including people and process.
  • Purple team: close detection gaps deliberately, technique by technique.
  • Tabletop exercise: rehearse management decision paths for the emergency.

Frequently asked questions about Red team, blue team, purple team

What is the difference between pentest and red team?

The pentest inventories vulnerabilities within a defined scope and is known to the defenders. The red team covertly pursues a concrete objective by any path — testing not just technology but the entire detection and response chain.

Does a purple team need its own staff?

No — purple is a format, not a department: attacker and defender sides (internal or external) work in joint sessions. Mid-sized companies in particular bring in the red side as a service and measurably develop their blue team in the process.

How often should you run such exercises?

Pentests for exposed systems at least annually and after major changes; purple sessions work well as a recurring rhythm, say quarterly with changing techniques; a full red teaming every one to two years depending on maturity.

What is the point if the red team always wins?

The gain lies in the how: which steps went undetected, which alerts came too late, where did the process break? A good red team documents the chain so that concrete detection and hardening measures result — that is the actual mandate.

What is a tabletop in comparison?

A tabletop exercise simulates the emergency at the table: management and business units play through decisions, communication and escalation — without technical attacks. It complements technical exercises with the organisational side of response capability.

Open questions about this in your environment? KAEMI advises you in line with your requirements and can also take over ongoing management.