The traditional split hands a red team's report to a blue team weeks later, and the feedback loop that should exist never closes: the attacker never learns which of their techniques the defences would now catch, and the defender never learns whether the fix works against the real thing or only against the description of it.
Purple team collapses that. The same engagement finds the weakness, applies the fix and re-runs the original attack, which means the deliverable is a verified control rather than a recommendation. It also produces a shorter report, because a finding that was fixed and re-tested takes one line instead of a page of caveats.
It is a working arrangement rather than a third team. The word describes red and blue operating together, and on a small engagement it can be one person doing both halves — which is the version that removes the handover entirely.
Related terms
Penetration test
An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.
Red team
The offensive side: people whose job is to get in, using whatever an actual attacker would use.
Blue team
The defensive side: hardening the systems, watching them, and handling it when something happens.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
