{"id":15775,"date":"2026-02-11T08:15:36","date_gmt":"2026-02-11T08:15:36","guid":{"rendered":"https:\/\/newestek.com\/?p=15775"},"modified":"2026-02-11T08:15:36","modified_gmt":"2026-02-11T08:15:36","slug":"the-hard-part-of-purple-teaming-starts-after-detection","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=15775","title":{"rendered":"The hard part of purple teaming starts after detection"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p>In my recent articles for CSO, I\u2019ve talked about <a href=\"https:\/\/www.csoonline.com\/article\/4035333\/7-reasons-the-soc-is-in-crisis-and-5-steps-to-fix-it.html\">the limits of current SOC models<\/a> and <a href=\"https:\/\/www.csoonline.com\/article\/4083612\/the-soc-parachute-needs-more-than-packing-it-needs-practice.html\">the importance of rehearsal<\/a>. This time, I want to focus on something that\u2019s becoming increasingly clear: purple teaming has lost its depth.<\/p>\n<p>We\u2019ve turned one of the most powerful tools for resilience into a transactional exercise that feels reassuring but reveals very little about how an organization will cope when the pressure is real.<\/p>\n<p>Care and attention have become rare assets in our world. Distraction dominates both the consuming and supply sides of cybersecurity. Clients are pulled into complexity and novelty, while services providers are pulled into deadlines and deliverables.<\/p>\n<p>Meanwhile, attackers \u2014 increasingly powered by AI \u2014 are becoming faster, quieter, and more determined.<\/p>\n<p>When threats accelerate, surface-level testing is no longer enough.<\/p>\n<h2 class=\"wp-block-heading\" id=\"the-absence-of-findings-is-not-the-absence-of-risk\">The absence of findings is not the absence of risk<\/h2>\n<p>I\u2019ve seen this pattern everywhere: a <a href=\"https:\/\/www.csoonline.com\/article\/652476\/4-steps-for-purple-team-success.html\">purple team engagement<\/a> produces a set of impressive outcomes. The report looks good. Findings correlate with expectations. Leadership feels reassured.<\/p>\n<p>But a result is often treated as<em> the<\/em> result, as if the absence of findings means the absence of risk. This is a flaw.<\/p>\n<p>The industry\u2019s default approach is shaped by time pressure, commercial constraints, and scopes that are too narrow. None of this is malicious, it\u2019s simply how the system has evolved. Providers deliver what they\u2019re contracted to deliver, and clients take the report as a sign of depth.<\/p>\n<p>Omissions, often caused by time pressure or lack of mental space, are invisible. And invisible omissions are the most dangerous kind.<\/p>\n<h2 class=\"wp-block-heading\" id=\"two-clients-who-shouldnt-have-been-breakable\">Two clients who \u201cshouldn\u2019t have been breakable\u201d<\/h2>\n<p>Recently, we worked with two extremely mature organizations. On paper, both looked close to unbreakable.<\/p>\n<p>Instead of running a standard purple team, we co-designed the engagement with them. We looked at the problem as a determined attacker would, and we shared tacit knowledge openly, both our own and theirs. Crucially, everyone involved had visibility into the controls in place. It was a genuine cyber security partnership, not an audit.<\/p>\n<p>And both organisations were compromised \u2014 deeply \u2014 with almost no sign of compromise.<\/p>\n<p>In one case, there was a single indicator of compromise: \u201cdomain admin.\u201d Nothing about <em>how<\/em> it happened. Nothing about <em>what to do next<\/em>. No instinctive or automated response. Just <a href=\"https:\/\/chaleit.com\/blog\/red-bubble-trap-how-cyber-security-tools-are-hijacking-our-priorities\/\">a light turning red<\/a> with no playbook behind it.<\/p>\n<p>In the other case, the SOC detected multiple signals but never acted in time. Detection without action is just noise.<\/p>\n<p>The experience was humbling. And it forced a blunt question: \u201cYou saw us. So what?\u201d<\/p>\n<p>That\u2019s the real test. Not whether the SOC sees something. Whether it <em>does something<\/em> \u2014 fast enough and accurately enough \u2014 to stop the damage.<\/p>\n<h2 class=\"wp-block-heading\" id=\"standard-purple-teaming-cant-get-you-there\">Standard purple teaming can\u2019t get you there<\/h2>\n<p>Purple teaming should be the discipline that reveals these realities, but the current model rarely does. Service providers tend to focus on the bypass, the exploit, the \u201cwin.\u201d Clients focus on closing tickets, finishing the engagement, and getting the report.<\/p>\n<p>Neither mindset creates the space needed for deep thinking.<\/p>\n<p>Had we rushed through our work we would never have found what we did. Time pressure shapes outcomes more than most organizations realize. When testing is constrained by a standard 9\u20135, it limits how far teams can explore the conditions that lead to real compromise.<\/p>\n<h2 class=\"wp-block-heading\" id=\"resilience-is-the-brake-moment\">Resilience is the \u201cbrake\u201d moment<\/h2>\n<p>Imagine you\u2019re driving, and you see the car ahead braking suddenly. Awareness helps, but it\u2019s your immediate reaction that avoids the collision. Insurance plans don\u2019t matter at that moment. Nor do compliance reports or dashboards.<\/p>\n<p>Only vigilance and rehearsal matter.<\/p>\n<p>Cyber resilience works the same way. You can\u2019t build the instinct required to act by running one simulation a year. You build it through repetition. Through testing how specific scenarios unfold. Through examining not only how adversaries get in, but also how they move, escalate, evade, and exfiltrate.<\/p>\n<p>This is the heart of real <a href=\"https:\/\/chaleit.com\/blog\/purple-team-exercises-turning-security-investment-into-real-protection\/\">purple teaming<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"ai-didnt-help-either-organisation\">AI didn\u2019t help either organisation<\/h2>\n<p>Both clients had <a href=\"https:\/\/chaleit.com\/blog\/ai-security-testing-new-attack-vectors-and-strategies-in-application-security\/\">AI embedded in their SOCs<\/a>. And it made no difference.<\/p>\n<p>AI can accelerate analysis, but it can\u2019t replace intuition, design, or the judgment required to act. If the organization hasn\u2019t rehearsed what to do when the signal appears, AI only accelerates the moment when everyone realises they don\u2019t know what happens next.<\/p>\n<p>This is why so much testing today only addresses opportunistic attacks. It cleans up the low-hanging fruit. But if organized crime wanted these organisations, they would have had them. And that\u2019s not an easy sentence to write.<\/p>\n<h2 class=\"wp-block-heading\" id=\"a-model-that-creates-false-confidence\">A model that creates false confidence<\/h2>\n<p>The standard testing model traps everyone involved:<\/p>\n<ul class=\"wp-block-list\">\n<li>One-off tests create false confidence.<\/li>\n<li>Scopes limit imagination.<\/li>\n<li>Time pressure eliminates depth.<\/li>\n<li>Commercial structures discourage collaboration.<\/li>\n<li>Tooling gives the illusion of capability.<\/li>\n<li>Compliance encourages the appearance of rigour instead of the reality of it.<\/li>\n<\/ul>\n<p>This is why purple teaming often becomes \u201cjump out, stabilize, pull the chute, roll on landing.\u201d But what about the hard scenarios? What about partial deployments? What about complex failures? That\u2019s where resilience is built.<\/p>\n<p>And today, resilience is the only meaningful metric.<\/p>\n<h2 class=\"wp-block-heading\" id=\"new-mindset-slow-consistent-engaged-outcome-driven\">New mindset: slow, consistent, engaged, outcome-driven<\/h2>\n<p>In my experience, purple teaming that works requires:<\/p>\n<ul class=\"wp-block-list\">\n<li>Co-ownership of the mission.<\/li>\n<li>Tacit knowledge shared on both sides.<\/li>\n<li>Full visibility into controls.<\/li>\n<li>Scenarios designed, not bought.<\/li>\n<li>Repetition and rehearsal.<\/li>\n<li>Space for thinking.<\/li>\n<li>Disciplined simplicity.<\/li>\n<li>A focus on the \u201cso what,\u201d not the bypass.<\/li>\n<\/ul>\n<p>This is systems thinking. Engineering. Psychology. It is, in every sense, harder work than the standard model.<\/p>\n<p>But the seemingly impossible becomes possible when both sides push each other, and when the aim is not to produce a report but to reveal reality.<\/p>\n<p>Purple teaming is about getting in, sure. But it\u2019s also about what happens after that. Without a different approach, focused on consistency and outcomes, organizations will keep passing tests while failing in practice.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>In my recent articles for CSO, I\u2019ve talked about the limits of current SOC models and the importance of rehearsal. This time, I want to focus on something that\u2019s becoming increasingly clear: purple teaming has lost its depth. We\u2019ve turned one of the most powerful tools for resilience into a transactional exercise that feels reassuring but reveals very little about how an organization will cope&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=15775\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-15775","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/15775","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15775"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/15775\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}