We are an Austin-based logistics software company with 35 employees. We used to do routine annual penetration testing and our budget was typically between 7,000 and 9,000 dollars. A new cybersecurity consulting firm we reached out to this year told us that a traditional pentest won't add much value anymore and pitched doing a purple team exercise instead.
They quoted a 16,000 dollar budget and a two-week collaborative schedule. As they explained it, their attack team and our internal defense team would run a live exercise, closing gaps in our security rules and alerts in real time. It sounds nice, but we don't even have a full-time internal SOC or dedicated cyber defense team; we only have two senior sysadmins and one DevOps engineer.
What exactly is this purple team concept, and how does it differ from a standard penetration test? Is it worth dedicating this much budget and company time at our scale, or would we just be buying an unnecessary luxury?