Blue team
The defence team that protects an organisation's systems, detects attacks and responds to them, or that function as a whole.
- 01
Why it matters
The blue team's work is unglamorous but constant: watching logs, triaging alerts, hardening systems and responding to incidents. An attacker needs only one successful attempt, while the defence has to work correctly every day. Exercises show in advance how the blue team will act in a real attack.
- 02
Example
After a red team exercise, the blue team writes new detection rules for the steps it missed and tries the same techniques again a month later; this time the attack is spotted within the first hour.
- 03
Common mistake
Measuring defence by tools alone. What matters is not how many tools there are but how quickly an attack is spotted and stopped; those times should be measured regularly.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.