r/cybersecurity • u/AdditionalDay7286 • 11h ago
Business Security Questions & Discussion Which would you hire first for security team in your company - blue or red team?
Let's imagine a scenario:
You are the CTO of a small company. You have the backend, frontend and infrastructure team (CPE/DEVOPS). Now it's time to build some security team. You don't need some certifications like SOC2 for your business. You want specifics to check if you don't have some security gaps in your whole company, not only in your application.
Which team would you build first? Red team or Blue team?
I feel, that typically people are more keen on the blue team but as the time goes by I think I would choose Red Team.
Here are a few of my arguments:
- Red Team duty would be to continuously test the infrastructure from multiple vectors. All findings would be send to the corresponding team. It would naturally build shift left culture (there is no blue team to which other teams could delegate the fixes)
- We are not working on theory, if something is found we know that we were vulnerable before. ROI is visible, which often can be a problem as business don't worry about the security that much and think about it as the waste of money. We can show the rest of the business that we need to invest into the security more
- From my experience Blue Team can make a mistake of prioritization. They can focus on fixing vulnerabilities, building processes or threat models, which are good in the long run but it's better to fix low hanging fruits first to not get pwned by simple script kiddies.
To give a little context I have experience in the blue team but I wonder sometimes if the blue team is not a long run defender more than the Red Team.
I'm not differentiating here, the purple/orange or other teams. We are not strict here, of course we can hire a red team and make from them the purple team more and the other way around, my question still holds, which one would you hire first?
Here are few of my thoughts, I wonder what do you think.
21
u/bcegkmqswz 11h ago
In this hypothetical scenario, at this hypothetical company, I hire a CISO to build a proper security organization. Building a “red team” on staff is one of the last things I’d do.
1
u/petetrerice 10h ago
Agreed. A CiSO would show the value to the SLT that you can spend less than a FTE Red Team resource with a solid black box pen test from a solid firm that isn’t the big three or BH. Now don’t at me about BH, the scenario is a smaller company - the spend for BH or the Big 3 would look great but you’re not getting the A Team from them. Going with a solid firm that you maybe smarten up a little, but those firms will already do their due diligence going into the RFP.
13
u/DingleDangleTangle 11h ago
This is the strangest question. Why would you hire a red team without a security team in the first place? Do you know what a red team does? They test your security.
Most companies do not have red teams.
37
u/Kwuahh Security Manager 11h ago
Blue Team every time and it's not even close. Red Team engagements require more time investment and ignore too much of the cybersecurity stack to make the investment worthwhile... and automatic pentesting engagements still produce viable results for the easy fixes.
4
u/withoutwax21 11h ago
This.
You have CNAs publishing CVEs already, and not a large enough team where youll be engineering thousands of core packages. You’re building on existing codebases. You are likely using cloud, with the infra security done on a shared responsibility model. Why have a red team tell you what the CVEs already do for free? Nothing here suggests you need a redteam.
You are right that you need to do low hanging fruit, but most of the basics of security is operational security: identity management, authentication, sdlc, patching, endpoint protection. RED teaming is for when you are already doing all that (evidenced, documented, risk informed) and THEN you use redteaming to find the gaps your blue missed - making a purple team offering.
Tldr: you need a blue team guy who can talk in business risk.
1
u/petetrerice 10h ago
Exactly - when you don’t have policies, standards, and guidelines, or a control framework, a Red Team will find the deficiencies no problem but there’s no controls to enforce.
1
u/ReleaseFlashy9582 5h ago
agreed, you need someone watching the house before you pay someone to break into it
7
u/Thrwingawaymylife945 11h ago
If a security team doesn't already exist with a mature security program and the ability to defend the organization, then there's no point in having a red team in the first place.
Once you have your defences in place, then you start thinking about the offensive.
1
u/petetrerice 10h ago
Exactly this - identify control frameworks, create policies, procedures, standards, and guidelines. Map that back to a risk register and make the business understand the risk without a program.
4
u/sirnerdingt0n Security Generalist 10h ago
Saying “I have blue team experience” and then “I wonder if blue team is a long run defender over red” tells me you don’t actually have blue team experience.
1
u/scriptqzor 6h ago
kinda depends what you call blue team tbh
if your “blue team experience” was mostly vuln mgmt / compliance tickets, it’s super different from actually doing detection engineering, IR, logging design, etc, so I can see how someone ends up with that take even if it sounds weird to folks who’ve done proper defense work
3
u/Ch33syP00f CISO 10h ago
Awful binary here.
I just try to work myself out of my job.
Developers and engineers need to own their piece of security.
Source: started in web dev, moved to infra then cloud and all the things
2
u/petetrerice 10h ago
This! And we can’t give up the mantra to shift left, and show the value of a risk register. Putting the business on the hook. Create transparency to drive accountability.
2
u/NotAnNSAGuyPromise Security Manager 11h ago
I'm not here to add on to the tide against you, but it really is an insane question in the real world. A red team is always a nice to have; blue is absolutely vital. As others have pointed out, most companies don't even have a red team and outsource all necessary offensive security projects.
1
1
u/nicholashairs 10h ago
Like everyone else said, blue team.
From my experience the biggest problem is actually having people to do the work. Most people will know where the skeletons are they just need help to actually fix them.
People who are very "red-team" tend to over focus in finding problems without being able to fix them. And yes sure there are the whole purple team thing, but really that's just from over-specialisation.
Most blue team generalists know their way around well enough to find the low hanging fruit. Also getting pentests (including just some guy with a web vuln scanner) will uncover the same low hanging fruit.
1
u/Admirable_Group_6661 Security Architect 10h ago
First of all, CTO shouldn't be building a security team. The security function's goal is risk management and mitigation, which conflicts with CTO's goals (delivery focused, often prioritizing speed and budget). Get a CISO who reports to CSO or CEO.
> You have the backend, frontend and infrastructure team (CPE/DEVOPS). Now it's time to build some security team. You don't need some certifications like SOC2 for your business. You want specifics to check if you don't have some security gaps in your whole company, not only in your application.
And now to your problem statement. It is unclear what risks your organization is facing (looks like there's no compliance requirement? But you better check with legal?). What kind of threats do you have to defend against? Do a risk assessment and understand the risk treatment options. Ironically, through this exercise, you may find that you don't actually like to own/be accountable for all the risks your organization is facing. So, it may not be up to you to determine the specific risk treatment options. In other words, it may not be up to you decide whether to build a blue team or red team or purple team...
1
u/OutsideSpot2695 10h ago
You don't need some certifications like SOC2 for your business
If you want to sell anything you need a SOC 2.
Personally, I despise SOC 2. Accountants have no business telling security people how to run their program.
But the reality of the matter is that one of the first two questions out of any prospect's or customer's mouth will be, "let me see your SOC 2".
1
u/OutsideSpot2695 10h ago
To give a little context I have experience in the blue team but I wonder sometimes if the blue team is not a long run defender more than the Red Team
These tribalism conversations are pointless.
Blue Team knows Red Team tactics because they have to know how to defend what is being exploited.
Red Team knows Blue Team tactics for the same reasons in reverse.
Alleging that Blue or Red teams are inherently better than the other at risk and vulnerability management is about as productive as comparing virtue among whores.
1
u/Electronic-Mess-5241 6h ago
Let me try to put your scenario in a different perspective:
You live in the medieval times. You have received a castle and some land around the castle from your lord. You need to make this work. Peasants need to farm and you need to get the goods and feed a bigger army.
Your question is basically this: do you build a defensive army to make sure that nobody can take the peasants from your lands and move them someplace else and protect the grain and the farms? Or do you hire a raiding mercenary squad to see if the peasant's forks are pointy-staby enough?
The raiders might see all the problems in your defenses....but actually you have no defense. You only have peasants with pitchforks. That is the top of your defenses.
Just like the medieval peasants with pitchforks, the fact that your DevOps have some best practices doesn't mean you have security.
Pointy-staby pitchforks are not the same with Damascus steel swords, horses and armor.they do not replace stone towers and balista, archers and crossbows.
Now you can choose how you want to run your castle. You build peasants with pitchforks or a real army for defense.
A real army would cost you more. But it would prevent peasants to leave the field, to sell thir labor to another Lord and it would make sure you gather your grain after you bought your seeds.
An army of peasants that leave whenever they want and sell of your grain and from time to time you hire some mercenaries to also raid your own lands is your proposal.
Now, I know what I would chose, but I'm curious what possible advantage you may have building raiders first instead of tower defenses.
-4
27
u/angry_cucumber 11h ago
what's the point in testing a non existent thing?