PIPEDA, Contracts, and the Compliance Baseline Canadian SMBs Keep Missing
May 13, 2025Identity Is the New Perimeter: Locking Down Access in the Cloud Era
June 10, 2025Buying security tools is easy. Knowing whether they will actually catch an attacker is harder, and far more important. Purple teaming, where offensive and defensive work happen collaboratively rather than as an adversarial contest, is one of the most cost-effective ways for a Canadian organization to answer that question honestly.
Red, blue, and the value of working together
Traditional red teaming pits attackers against defenders. It is valuable but can end as a report of failures with little learning. Purple teaming instead has the offensive side simulate specific techniques while the defensive side watches to confirm whether each one is detected and, if not, why. The point is not to win but to improve, technique by technique.
How to run a lightweight exercise
- Pick a framework. MITRE ATTACK gives a shared vocabulary of real-world attacker techniques to test against.
- Choose relevant techniques used against your sector, such as credential access, lateral movement, and data exfiltration.
- Emulate and observe. Safely reproduce a technique and check whether your logging, endpoint tooling, and alerts fire as expected.
- Fix the gaps. Where detection failed, tune or build it, then rerun to confirm.
Why it beats assumptions
Organizations routinely discover that expensive tools were misconfigured, that critical logs were not being collected, or that alerts fired into a queue no one watched. Finding this during a controlled exercise is vastly cheaper than finding it during a real breach. Run these exercises regularly, because environments drift and attacker techniques evolve.
Takeaway
Do not assume your defenses work; prove it. Use ATTACK to emulate the techniques attackers actually use against your sector, watch whether your tooling detects them, close the gaps you find, and repeat. Validated detection is worth far more than an unverified stack of tools.
