A study from Exabeam, the Smarter SIEM™ company, revealed that more than one-third of security professionals' defensive blue teams fail to catch offensive red teams. The survey, conducted at Black Hat USA 2019, also showed that 68% find red team exercises more effective than blue team testing, and more companies are practising red over blue team testing. 

As cyberattacks become increasingly sophisticated and hack techniques become more highly targeted, organisations must learn how digital adversaries think to help identify gaps in their security programs.

Organisations practicing red and blue exercises speak volumes about their dedication to fortifying their security posture

Red teams consist of internal or hired external security professionals that emulate cybercriminals' behaviours and tactics and gauge the effectiveness of the company's current security technologies. Blue teams consist of the organisation's internal security personnel, tasked with stopping the simulated attacks. In these test scenarios, the blue team must react without preparation, to give the company the most realistic picture of its defensive capabilities. 

The study showed that 72% of respondent organisations conduct red team exercises, with 23% performing them monthly, 17% quarterly, 17% annually, and 15% bi-annually. Sixty-per cent conduct blue team exercises, with 24% performing them monthly, 12% quarterly, 13% annually, and 11% bi-annually. The fact that so many organisations practice these exercises monthly speaks volumes about their maturity and dedication to fortifying their security posture.

Constantly evaluate security investments

Not only do more organisations practice red team testing, but 35% of respondents claim that the blue team never or rarely catches the red team, while 62% say they are caught occasionally or often. Only 2% say they always stop the red team, emphasising that organisations must constantly evaluate and adjust their security investments to keep up with today's adversaries.

Adversaries' offensive tactics evolve more rapidly than the majority of security technologies on the market today."

Promisingly, the study found that 74% of IT security professionals have seen their companies increase security infrastructure investment as a result of red and blue team testing, with 18% calling the budget changes significant. Only 25% claimed that their company has never upped its security budget after performing these tests. The survey also identified communication and teamwork (27%) as the top skill blue teams need to work on, followed by knowledge of the attacks and tactics (23%), threat detection (20%), the incident response time (17%) and persistence (8%).

Technical knowledge a foundation

"Adversaries' offensive tactics evolve more rapidly than the majority of security technologies on the market today. It's abundantly clear that regular and relevant red/blue team testing helps companies develop their security capabilities," said Stephen Moore, chief security strategist, Exabeam.

"The study also demonstrates that while having technical knowledge is a necessary foundation for all security professionals, interpersonal skills are highly sought after to promote more cohesive teams and better cooperation, especially during an incident or intrusion. We encourage companies to employ these types of testing exercises to find and fill security gaps, which, over time, become methods to evaluate the strengths and weaknesses of their cybersecurity defenders."

Download PDF version Download PDF version

In case you missed it

Security predictions 2025: AI, drones, and retail innovations
Security predictions 2025: AI, drones, and retail innovations

With the year 2025 stretched out before us, there are many techniques one could use to predict what will happen in the new year. You might analyse historical data and analyse futur...

2024 was a big year for M&A in the security market
2024 was a big year for M&A in the security market

Big news on the mergers and acquisitions (M&A) front is closing out 2024, a year in which several shifts changed the face of the physical security manufacturer community. Ann...

Anviz Global expands palm vein tech for security
Anviz Global expands palm vein tech for security

The pattern of veins in the hand contains unique information that can be used for identity. Blood flowing through veins in the human body can absorb light waves of specific wavelen...

Quick poll
What is the most significant challenge facing smart building security today?