Should Cyber Offense and Defense Be Separate?
By COL Charles R. McGrue
| Gray Space, 2026 E-Edition
Read Time: < 8 mins
In the world of cybersecurity, there are multiple disciplines and areas of focus. Some of these focus areas include offensive cyber, defensive cyber, digital forensics, cyber threat intelligence, auditing, asset management, “ethical” hacking or penetration testing, zero-trust architectures, and red, blue, or purple teams. None of these exist as stand-alone factors. All these areas of focus and disciplines work together to educate and build upon one another, each informing the other to create a more sound and secure cybersecurity culture. In their most raw form, these disciplines fall either in the offensive or defensive area of cybersecurity. Whether they are focused on using offensive techniques to enhance defensive capabilities or improving defenses through auditing and continual hardening, they are either offensive or defensive cyber. For the purposes of this writing, incident response, forensics, governance, compliance, risk management, zero-trust architecture, and penetration testing will all be part of defensive cybersecurity as they are focused on supporting the defense of the organization. Even though penetration testing is an offensive technique, its purpose is to provide insight into improving or enhancing the defensive posture of the organization.
Offensive and defensive cyber should not be separated. Separating them can remove the value of lessons learned from the shared functions. Whether they are novices, seasoned professionals, or experts in cybersecurity, there is always an opportunity to learn from the combination of the two. The separation would decrease creativity in addressing global threats. Across the cybersecurity landscape, no two threat actors operate the same, which means being single-minded or biased about how a vulnerability can be exploited may inhibit creativity in addressing the concern. The separation can affect the ability to enhance the capabilities of a cybersecurity professional. When providing cybersecurity professional training across multiple disciplines, trainers can use what they have learned to develop a more robust solution. If the two are separated, it will cause a reduction in the organization’s ability to defend against threats. Maintaining the two will support creativity in a manner that leverages employed controls to decrease the threat surface of the organization. It is imperative that both offense and defense understand how the other will act and respond, which supports unification of offensive and defensive cybersecurity.
Separating offensive and defensive cybersecurity can remove the value of lessons learned across the two core functions. Core and ancillary capabilities serve both defensive and offensive functions. Separating them could be detrimental to informing other operations and decrease an organization’s capabilities overall. Regardless of the cyber professional’s experience, there is always something to learn in the field. Someone who spends years in a security operations center will likely only know how operations work in that space because they monitor actions and threats daily. However, when an offensive actor crafts a packet using hacker tools, that packet can look like normal traffic. Either the analyst or their tools must recognize a crafted packet to detect it. If it goes unnoticed, the analyst must determine how it was missed and identify the oversight. The crafting of packets is not a novice-level skill although a novice can learn and practice the craft. That is why the most valuable aspect of this practice is when the offensive team (red team) uses this tactic and debriefs the defensive team (blue team) on the tools, techniques, and procedures used to conduct this exploit. This touches upon the lessons-learned aspect from having red, blue, and purple teams sit down and talk.
Multiple researchers support this sentiment. In the article “Roles of Three Lines of Defense for Information Security and Governance” by Ho (2018), she alludes to the use of offensive and defensive cybersecurity in applying sound governance, shaping risk tolerance, and supporting information security compliance. This is echoed by Moyle (2022) in his article “The Three Lines of Defense as a Means to Foster, not Inhibit, Collaboration.” Although they both speak about the three lines of defense, the main area of focus deals with compliance, controls, and risk management. When an organization establishes the right set of controls and tests them through offensive operations, the results inform the defensive operations through exposure of vulnerabilities and attack paths.
Offensive cyber teams have the capability to provide valuable insight into how they are able to penetrate a system or bypass defenses. This enables defensive cyber teams to internalize this information, validate it with compliance requirements, and make the applicable adjustments needed to secure vulnerabilities. It is imperative that these two teams collaborate to address vulnerabilities and enhance the defensive posture of their network. A failure to do so may result in the organization’s inability to improve on how they operate in addressing cybersecurity threats. If the offensive team cannot circumvent the defensive controls, the defensive team can chalk this up as a win but should continue leveraging the offensive team to address any vulnerabilities that may arise in the future.
Separating offensive and defensive cybersecurity reduces perspectives and effectiveness. When you are biased from learning how to do something just one way, your ability to be creative is affected by a lack of knowledge and experience. Being able to see two sides of the same coin can help to improve creativity. This also contributes to improving what some might call “operational art,” or the ability to leverage experiences to achieve an objective. Operational art is a military term that examines how a military commander leverages their experience to creatively address an operational requirement (U.S. Joint Chiefs of Staff, 2020). They can do this because they have been challenged over the years and have developed the necessary experience to address various problems. They also gain knowledge from debriefs and lessons learned, which help elevate their expertise. While new or uncommon challenges may arise, this is where the concept of wargaming comes into play. Wargaming is conducting a thought exercise to address a problem (Perla, 1990). Wargaming requires decision-makers to make choices as the simulation plays out, resulting in an improved understanding of the operations in progress. Upon completing the war game, lessons learned aid in learning while also increasing future creativity in solving a problem.
To understand how this supports the integration of offensive and defensive cybersecurity working in tandem, an experienced individual can leverage creativity in addressing cybersecurity challenges. For example, if an offensive cyber operator accesses a system and realizes it is a honeypot, they can disengage and re-enter the real network. The defensive team should analyze how this was done and why the offensive actor was able to differentiate between the honeypot and the real network. The offensive cyber operator’s years of experience in understanding how networks are set up provides valuable insight that defenders can use to improve cybersecurity defense in the organization. This scenario is also beneficial when training other offensive team members to conduct a penetration test. Likewise, a defender’s experience in securing networks subject to compliance requirements can enable the offensive cyber operators to be more creative and dynamic when devising attack strategies.
Separating offense and defense personnel can result in a negative impact on trained capabilities as a cybersecurity professional. Cyber professionals enhance their overall professionalism by developing their skills across various cybersecurity disciplines. Among others, this includes training in areas such as digital forensics, penetration testing, system log analysis, auditing, and control implementation. These disciplines typically fall under either offensive or defensive cyber at their core. Employing a combination of offensive and defensive cyber, also known as red and blue, results in what is known as purple teaming. As a cybersecurity professional, I found that taking offensive and other courses complemented my initial training in overall defensive requirements. Therefore, I took courses on penetration testing, incident response, and digital forensics, which all directly complemented my training and understanding of defensive operations.
Dale (2019) emphasized leveraging a combination of the two teams to create a purple team, which enhances the cybersecurity posture for an organization. This increased posture improves as the red team continues to challenge the blue team’s capabilities. However, the blue team also increases their capabilities as they develop an understanding of how red teams perform offensive cyber operations. The red team’s job is made more difficult because the blue team has an understanding of the red team’s tactics, techniques, and procedures (TTPs) (Dale, 2019). As alluded to earlier, this approach enhances the skills of internal teams to become more proficient in both offensive and defensive cyber operations. This rise in proficiency allows for an improvement in compliance with a reduction in overall risk for an organization. This also means that whether you divide your teams across multiple disciplines or maintain their core components of offensive and defensive, you can reduce the threat landscape of your organization, meet compliance requirements, increase staff capabilities, and create a synergistic team that will thrive within the organization’s cybersecurity culture.
Separating out cybersecurity roles is a way to strengthen skills within a specific area of focus. These areas allow for a depth of knowledge in either offensive or defensive cybersecurity skillsets—for example, a strong understanding of the meticulous process of digital forensics or having common controls committed to memory. However, it takes away from the benefits gained through keeping offensive and defensive cyber united. When combined, you can develop and share lessons learned that can improve the creativity and knowledge of the different players in the world of cybersecurity. This knowledge will help increase the level of professionalism and further hone the skills across disciplines. Even if an individual joins the organization with just an understanding of one discipline, they will get the opportunity to improve across other areas of cybersecurity focus. This is a huge win for the teams and the organization they are defending. Therefore, it is essential to embrace the concept of purple teaming and leave offensive and defensive cybersecurity as two sides of the same coin.
References
Dale, C. (2019). Red, blue and purple teams: Combining your security capabilities for the best outcome. SANS Institute Information Security Reading Room. https://www.sans.org/media/analyst-program/red-blue-purple-teams-combining-security-capabilities-outcome-39190.pdf
Ho, A. (2018). Roles of three lines of defense for information security and governance. ISACA Journal, 4. Retrieved September 8, 2025, from https://www.isaca.org/resources/isaca-journal/issues/2018/volume-4/roles-of-three-lines-of-defense-for-information-security-and-governance
Moyle, E. (2022). The three lines of defense as a means to foster, not inhibit, collaboration. ISACA Journal. https://www.isaca.org/resources/news-and-trends/newsletters/atisaca/2022/volume-38/the-three-lines-of-defense-as-a-means-to-foster-not-inhibit-collaboration
Perla, P. P. (1990). The art of wargaming: A guide for professionals and hobbyists (p. 15). Naval Institute Press.
U.S. Joint Chiefs of Staff. (2020). Joint planning (Joint Publication 5-0, p. I-3). U.S. Department of Defense. https://www.jcs.mil/doctrine/joint-doctrine-pubs/5-0-planning-series