Evolving Security Operations - The Paradigm Shift We All Need To Make
Tom Clancy’s Rainbox Six: Seige
“You don’t have a malware problem; you have an adversary problem”
Every organisation needs security, or security operations, more specifically. It goes without saying that anything of value must be protected.
In a business sense, this primarily involves establishing a security team to manage the monumental task of protecting the business from an ever-increasing number of threats.
This practice is widely known as security operations.
Establishing a blue team is where every organisation commonly starts. Defence. Protecting the business based on the typical drivers for Cybersecurity. This includes, but is not limited to:
Regulatory compliance
Business transformation, cloud adoption/migration activities
Strategic transactions / M&A
We always start with the blue team.
As we grow and mature, we strengthen our capabilities by adding a red team. Offence. Providing an adversarial approach with offensive security involves performing regular penetration testing to get a more accurate and validated understanding of your current security posture.
This is how security operations have been operating for many years now: defending business-critical systems and performing routine penetration testing, emulating adversary tactics, techniques, and procedures (TTPs) against exposed applications and systems. Blue and red teams work together but not always in harmony.
Where do we go from here? Enter the purple team.
A purple team/function within an organisation should not be a separate dedicated unit. Rather, an effective purple team is the unification and tight collaboration among the two existing sides (teams) within information security: the red team and the blue team.
This is where we need to get to. Purple Team Operations.
Purple team operations focus on the collaboration between Cyber Threat Intelligence (research, adversary behaviours, tactics, techniques and procedures); the Red Team, emulating adversary TTPs and validating attack paths; and the Blue Team, the defenders that include the Security Operations Centre (SOC), threat hunters, digital forensics and incident responders (DFIR) and/or managed security service providers (MSSPs).
In reality, adversaries don’t start by going directly after your most valuable and highly-protected business-critical assets. They find much more subtle and sophisticated ways to attack them.
The purple team enables a vital threat-informed approach to strengthening security operations' capability, creating a culture of proactive threat defence.
Purple Team Operations enables proactive and continuous threat defence.