|
|
|
|
|
by olivierduval
2197 days ago
|
|
Allowing Blue Team to fight back maybe? Or to be able to actively track the red team instead, using an active defense, instead of only passive defense? Moreover, the outcomes are different for both teams: - RedTeam success => they are seen as "real" hackers/heros and the BlueTeam are the poor incompetent - RedTeam fail => the BlueTeam did "only" its job, the investments in cybersec for the company paid off... so the budget for the cybersec can be reduced. So, for RedTeam, it's either a win or a tie. And for BlueTeam it's either a tie or a loss... If the BlueTeam could fight back, maybe this could change... |
|
On the other side the attackers have the more exciting job and only need one success which they can achieve by using whatever means they see fit.
You'll see this outside of IT just as well, like in sports. Goalkeepers (defenders) vs. strikers come to mind but at least there they all operate within the same set of rules.