The Cybersecurity Color Wheel
The Core Model (Primary Roles)
1 Red Team (Offense)
- Focuses on simulated attacks, penetration testing, and ethical hacking to identify vulnerabilities before real attackers do.
2 Blue Team (Defense)
- Focuses on active defense, continuous monitoring, threat detection, and incident response (SOC).
3 Yellow Team (Build & Architecture)
- Focuses on software engineering, system design, and infrastructure development.
The Extended Framework (Hybrid Roles)
4 Purple Team (Red + Blue)
- Fosters collaboration between offensive and defensive teams to improve detection mechanisms and validate security controls in real time.
5 Green Team (Blue + Yellow)
- Integrates defense directly into software development (DevSecOps) to ensure infrastructure is built securely by design.
6 Orange Team (Red + Yellow)
- Focuses on secure coding education, using offensive techniques to train developers on how attackers think.
7 White Team (Governance & Oversight)
- Manages policy, compliance, logistics, and acts as the impartial referee/organizer for security exercises.
Additional Specialist Teams
*8 Black Team
- Handles physical security assessment, facility lockpicking, and real-world social engineering scenarios.
*9 Gold Team
- Comprises C-level executive management, legal advisors, and PR representatives responsible for strategic crisis management.
*10 Brown Team
- Focuses on day-to-day operations, systems administration, and patching infrastructure to keep networks running cleanly.