Red Team / Blue Team / Purple Team, Concepts & Use Cases
Introduction
"Red team", "blue team" and "purple team" are frequently used as synonyms for penetration testing – incorrectly. The three engagement types differ fundamentally in objective, methodology, detection assumptions and cost structure. A penetration test is a time-boxed, scope-defined vulnerability assessment; a red team engagement is an objective-led, multi-week simulation of a realistic adversary that explicitly tests the defender's detection and response capability. The blue team is the operational defence – SOC, incident response, detection engineering. Purple teaming is the structured, collaborative format between the two, designed to improve detection logic systematically against known adversary tactics, techniques and procedures (TTPs).
This article delivers:
- A precise definition of each engagement type with clear demarcation from penetration testing
- Decision logic: when each format actually adds value
- Deliverables, report structures and realistic effort estimates
- The MITRE ATT&CK bridge between offence, defence and compliance
- Swiss specifics: TIBER-EU / DORA TLPT, FINMA expectations, legal framework
Red team
A red team engagement simulates a realistic, targeted adversary against a previously defined business objective ("flag") – for example: access to the core banking system, exfiltration of an R&D document library, manipulation of an industrial control system. It is objective-led, not scope-led. Duration is typically six to sixteen weeks, the attack runs covertly ("adversary emulation"), and the number of people aware inside the client ("white cell") is tightly restricted to three to five. Rules of Engagement (RoE) spell out permitted techniques, excluded systems, abort criteria, evidence handling and escalation paths.
Substantively, credible red teams combine initial access (phishing, external exposure, supply chain), persistence, privilege escalation, lateral movement, defense evasion and data exfiltration along MITRE ATT&CK tactics TA0001 through TA0010. Realistic engagements operate command-and-control infrastructure, malleable profiles and implants that evade common EDRs. Tooling questions – Cobalt Strike, Brute Ratel, Mythic – should be discussed openly in procurement, as should whether the red team brings its own zero-days (rare and only in TIBER-EU / TLPT mandates) or relies on known techniques.
Blue team
The blue team is your organisation's operational defence – not an engagement format but a permanent function. It typically includes SOC analysts (Tier 1-3), threat hunters, detection engineers, incident responders, forensic specialists and, in mature organisations, a dedicated threat-intelligence team. Responsibilities range from real-time triage and use-case development in the SIEM/XDR, through reverse engineering of suspicious artefacts, to communication with authorities (BACS/NCSC, FDPIC/EDÖB, FINMA) and the executive board.
Blue-team performance is measured against three KPIs: detection coverage (share of relevant MITRE techniques covered – realistic figures are 35-55% for Swiss mid-market, 60-75% for financial groups), Mean Time to Detect/Respond (2026 industry benchmarks: MTTD <10 min for high/critical, MTTR <30 min) and false-positive rate (target band 5-15%; substantially higher signals lack of tuning, substantially lower signals over-suppression). A blue team without continuous adversary simulation against its own detections loses effectiveness within 12 months because adversary TTPs evolve faster than detection logic. Purple teaming exists precisely to close that gap.
Purple team
Purple teaming is the structured, transparent collaboration between red and blue teams aimed at measurably improving detection and response. Unlike a covert red team, a purple-team engagement runs in the open: both sides see one another, the red team executes techniques, the blue team checks whether and how they are detected, and detection logic is sharpened jointly. Engagements typically last two to four weeks with daily stand-ups and a documented plan grounded in MITRE ATT&CK.
The value is measurable output: per tested technique, an entry in a detection-coverage matrix with status (detected / partially detected / missed), the relevant SIEM rule ID, MTTD, and concrete engineering tasks to close gaps. A typical quarterly purple-team programme in a Swiss mid-market organisation lifts MITRE coverage by 15-25 percentage points. Precondition: the blue team has the engineering capacity to implement the identified tasks – otherwise the output is a report, not a security gain. Purple teaming is particularly valuable after major architecture shifts (migration to Microsoft 365 E5, EDR replacement, introduction of a SOC-as-a-Service solution).
Which format when
Choosing between penetration test, red team, purple team and continuous blue-team tuning depends on maturity and business need:
- Penetration test: when a specific application, infrastructure or perimeter must be assessed for vulnerabilities – e.g. pre-go-live, after major releases, or as the annual obligation under ISO/IEC 27001:2022 Annex A.8.29.
- Red team: when you want to test whether your organisation can detect a realistic, targeted attack at all. Sensible from maturity level 3 onwards (defined SOC, EDR on all endpoints, documented incident-response process). Mandatory for FINMA-supervised institutions under DORA TLPT applying the TIBER-EU methodology.
- Purple team: when you have a SOC or MDR and want to lift detection coverage measurably. Ideal after a red-team findings report, after tooling changes, or as an annual hardening programme.
- Continuous validation: tools like AttackIQ, SafeBreach and Cymulate enable daily automated testing of individual techniques. They complement – not replace – red and purple teaming.
A sensible three-year roadmap combines: year 1 a penetration test plus an initial red-team reality check, year 2 a purple-team programme in two waves, year 3 a repeat red team with harder objectives plus continuous validation as a permanent rail.
MITRE ATT&CK as common language
The MITRE ATT&CK framework (currently v15) is the de facto shared language across red, blue and purple. It classifies adversary behaviour into tactics (objectives), techniques (methods) and sub-techniques (variants). For Switzerland the particularly relevant techniques include T1566 (phishing), T1078 (valid accounts), T1059 (command and scripting interpreter), T1486 (data encrypted for impact / ransomware), T1190 (exploit public-facing application) and T1083 (file and directory discovery).
A professional red-team report lists each executed action with its ATT&CK ID, variant used, timestamp and – when observed – the blue team's detection response. A purple-team report adds the detection-engineering tasks with responsible owner and due date. To plan SOC maturity, additionally apply the logic of MITRE D3FEND and MITRE Engage – both are defensive counterparts that let you map defensive and deception measures to each attack technique. This end-to-end chain (threat intel → ATT&CK technique → D3FEND countermeasure → SIEM rule → purple-team trial) is the gold standard for ISO/IEC 27001:2022 Annex A.5.7 (Threat Intelligence).
Legal framework and contracting in Switzerland
In Switzerland, red- and purple-team engagements are legally straightforward provided there is an explicit, written authorisation from the competent representative body and the scope is unambiguously defined. Without that authorisation, testers commit the offences of unauthorised access to a data-processing system (Art. 143bis SCC) and damage to data (Art. 144bis SCC). Contracts therefore mandatorily include precise rules of engagement, emergency contact chains, evidence preservation, mutual non-disclosure, liability caps appropriate to the risk, proof of insurance and a data-processing agreement under Art. 9 DSG where personal data may be exfiltrated.
For FINMA-supervised institutions, the framework has tightened since DORA entered force in the EU (January 2025) and parallel FINMA practice: Threat-Led Penetration Testing (TLPT) per TIBER-EU methodology, with threat-intelligence provider and red-team provider in separate roles, a preparation phase of three to six months, an engagement phase of 10-12 weeks and closure with a replay workshop. Reports are shared with FINMA and the relevant EU supervisor. For Swiss banks operating in the EU, TLPT is a de facto every-three-years standard. Organisations outside finance may adopt the TIBER logic voluntarily – it remains the methodologically cleanest engagement structure on the market.
How SIDD supports you
SIDD delivers penetration tests, red-team engagements and purple-team programmes for Swiss mid-market organisations, corporates and FINMA-supervised institutions. Our tester team holds OSCP, OSEP, CRTO and CREST certifications and has practical experience in TIBER-EU / DORA TLPT mandates. We provide ATT&CK-mapped reports, detection-engineering recommendations and, on request, implementation support in your SIEM/XDR of choice. For organisations approaching their first red team we typically recommend a preceding penetration test or vulnerability scan for pre-hardening. To embed detection engineering structurally, combine the engagement with an ISO 27001 ISMS implementation or an external CISO mandate, in which we bridge executive board, SOC provider and audit. Speak with us via our contact form or request an indicative quote – we deliver a scoped proposal including a draft RoE within five working days.
