The field

Red team, blue team, purple team: what each one actually does

Three colours, three roles, and a good deal of confusion between them. Here is what each one is for, and why the best security work depends on all three talking to each other.

The colours come from war games. For decades, military and government exercises have pitted a red force, the notional enemy, against a blue force, the home side that has to defend. Security borrowed the vocabulary, and it has stuck because it captures something real: the most honest way to find out whether a defence works is to have someone competent try to beat it. What follows is what each role actually does, stripped of the marketing that has grown up around the terms.

What a red team actually does

A red team plays the attacker. Its job is not to catalogue every flaw in a system, but to behave like a specific adversary and pursue an objective the organisation would genuinely fear losing, such as access to a payment system or a sensitive dataset. That focus is what separates a red team engagement from a penetration test. A penetration test tends to sweep a defined scope for as many vulnerabilities as it can find; a red team picks a goal and looks for the quietest route to it, testing not just the technology but the people and the detection around it.

To keep that realistic, mature red teams plan against observed attacker behaviour rather than their own imagination. The MITRE ATT&CK framework, a freely available knowledge base of the tactics and techniques used in real intrusions, gives them a catalogue to draw from, so an exercise reflects how genuine adversaries operate rather than a set of party tricks. In the United Kingdom, this kind of intelligence-led testing has been formalised for the most sensitive sectors: the Bank of England's CBEST scheme and the wider TIBER-EU framework use accredited providers to run threat-led red team tests against financial institutions, precisely because a realistic attack is the only reliable measure of resilience.

What a blue team actually does

A blue team plays the defender, and unlike the red team it never stands down. It is the standing capability that runs an organisation's security day to day: building and tuning monitoring, watching for signs of intrusion, investigating alerts, and responding when something is wrong. When people picture a security operations centre, or the analyst who catches a suspicious login at two in the morning, they are picturing blue team work.

Most of what a blue team does is unglamorous and continuous. The National Cyber Security Centre's guidance returns repeatedly to the same foundations: know what you are defending, keep it patched, log what happens, and be able to detect and respond when prevention fails. Training bodies such as SANS build much of their defensive curriculum around the same cycle of preparation, detection and response. None of it produces a headline. The measure of a good blue team is the incident that is caught early, or the one that never develops at all, which is exactly the kind of quiet, sustained work that is easy to overlook and hard to recognise.

Where purple teaming comes in

The weakness of the red and blue arrangement is that it can become adversarial in an unhelpful way. A red team that simply reports "we got in" and leaves has proved a point but taught little. A blue team that only receives a scorecard weeks later has lost the context it needs to improve. Purple teaming closes that gap. Rather than a third standing team, it is usually a way of working in which the attackers and defenders collaborate directly, walking through each technique together so the blue team can see, in the moment, which steps it detected and which it missed.

On the offensive side, a red team engagement is not a checklist. We pick an objective the business actually cares about, then find the quietest path to it, the way a real intruder would. The value for a blue team is seeing which of those steps they caught and which they missed.

— Zia Bharwani, CEO of Red Team Partners, an offensive-security firm that runs red team and penetration-testing engagements internationally

From the defensive side, the aim was never to catch everything. It was to see enough, fast enough, to act before it mattered. A red team engagement earns its keep the moment it shows us which signals we were missing, and a purple exercise is where that lesson gets fixed the same day rather than a quarter later.

— Jan Hanken, CEO of Claire Security AI, a defensive-security firm

Set beside the offensive account above, the defender's view completes the picture: the two sides describe the same loop from opposite ends. That perspective is one practitioner's account of how the offensive side approaches the work, and it sits alongside the published frameworks above rather than above them. What the named frameworks, NCSC guidance, MITRE ATT&CK and the SANS defensive curriculum, all describe in their own way is the same underlying loop: attack, observe, and improve. Purple teaming is simply the shortest path around that loop, because it removes the delay between an attack being attempted and a defender learning from it.

How the three fit together

Put plainly, the three roles are not rivals but stages of a single discipline. The blue team is the foundation; without monitoring, response and the basic hygiene the NCSC keeps pointing to, there is nothing to test. The red team measures how well that foundation holds against a realistic adversary. Purple teaming is the connective tissue that turns each engagement into concrete improvement rather than a report that gathers dust.

  • Red team. Emulates a real adversary against a chosen objective to test whether defences actually hold. Intermittent, often outsourced, intelligence-led.
  • Blue team. Defends continuously, running detection, monitoring and response. Permanent, internal, and the side being tested.
  • Purple team. A collaborative way of working in which red and blue share findings in real time so lessons are fixed while they are fresh.

An organisation does not have to run all three at once, and the order matters. The defensive foundation comes first, because testing a capability that cannot yet see or respond only confirms what is already known. Once that foundation exists, a red team gives it a genuine measure, and a purple approach makes the results stick. The people who carry this work, on either side of the colour line, are rarely visible outside their own teams, which is part of why recognising them on merit matters at all.

Sources

  • NCSC — UK National Cyber Security Centre, guidance on detection, response and threat-led testing.
  • MITRE ATT&CK — the adversary tactics and techniques knowledge base red teams emulate against.
  • SANS Institute — blue-team and defensive-operations training curriculum.
  • Red Team Partners — practitioner commentary (Zia Bharwani).
FAQ

Red, blue and purple teams, in brief

What is the difference between a red team and a penetration test?

A penetration test aims to find as many vulnerabilities as possible in a defined system within a set window. A red team engagement is narrower and more realistic: it picks a specific objective, emulates a named adversary, and tests whether the organisation as a whole, including its people and its detection, notices and responds. One measures coverage of flaws; the other measures how defences hold up against a genuine intruder.

Is a purple team a permanent team?

Usually not. Purple teaming more often describes a way of working than a standing department. Red and blue practitioners collaborate on an exercise, sharing what was attempted and what was detected in near real time, so lessons are fixed while the context is fresh. Some large organisations do formalise the function, but many run purple exercises periodically with their existing red and blue staff.

What is MITRE ATT&CK and why does it matter here?

MITRE ATT&CK is a freely available knowledge base of the tactics and techniques that real-world attackers use, drawn from observed intrusions. Red teams use it to plan realistic attacks, and blue teams use it to check whether their monitoring can see each technique. Because both sides reference the same framework, it gives them a shared language for describing exactly what was attempted and what was caught.

Which does an organisation need first, a red team or a blue team?

The blue team, in almost every case. There is little value in testing defences with a red team before the basic defensive work exists: asset inventory, logging, monitoring and a response process. A red team engagement is most useful once there is a defensive capability worth measuring. Testing an organisation that cannot yet see or respond only confirms what is already known.