CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

Walmart's "Trusted Agent" Approach to Purple Teaming

Dark Reading Archived Aug 12, 2026 ✓ Full text saved

Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises

Full text archived locally
✦ AI Summary · Claude Sonnet


    CYBERSECURITY OPERATIONS REMOTE WORKFORCE THREAT INTELLIGENCE СLOUD SECURITY CASE STUDIES Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Walmart's "Trusted Agent" Approach to Purple Teaming Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises Richard Thurston,Contributing Writer, Dark Reading August 12, 2026 3 Min Read SOURCE: ALEKSEI GORODENKOV VIA ALAMY STOCK PHOTO While many organizations struggle with the inherent tension between red and blue teams — where offensive security testers and defensive operators often work in silos or even develop adversarial relationships — Walmart has entirely reimagined this dynamic. Jason O'Dell, the retailer's Global VP of Security Operations, recognizes that the traditional model of rigidly separate teams conducting exercises in isolation delivers limited value and can actually damage team morale and organizational learning. O'Dell addresses this challenge by focusing on building trust and psychological safety within security operations, transforming purple teaming from a competitive win-lose scenario into a collaborative learning environment. By physically co-locating teams, implementing a "trusted agent" observation model, and emphasizing organizational improvement over individual victories, Walmart has created a security operations culture where both offensive and defensive practitioners continuously elevate their skills — and the company's overall security posture benefits from their combined growth. Here's how they do it. Related:Walmart Leaders Transform Security Operations Without Going Bananas Building Learning and Trust Within Operations. Human relationships within the organization are fundamental to O'Dell's success. A sense of togetherness plays out in the way he constructs purple teaming in security operations, which spans tabletop exercises, attack simulation and adversary emulation. Some companies maintain rigidly separate defensive (blue) and offensive (red) teams, and some build a "purple team" to focus on both; O'Dell's approach is more nuanced and more founded in how his teams feel about the exercise. It's important to build trust that rises above the "innate friction" that's a natural by-product of pitting team against team. The culture needs to stress that it is not about winning or losing the exercise, he explains. "I think you have to change that perception," says O'Dell. "You have to make it a safe environment for them to understand that it's about 'Did we drive the best value to the organization in becoming better as a by-product of the campaign and the work we did?'" O'Dell has moved both red and blue teams into the same business unit and physical location and adopted a "trusted agent" model for purple teaming. When doing full-on adversarial emulation, observers are watching that campaign. For example, two members of the blue team will sit with the red team as they conduct their offensive activity and check whether telemetry, logs and detections are in place in real time. They will also protect the red team by ensuring they don't cause any harm to the business during the exercise. Related:From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture "As long as you have great blue team members that won't throw a hint over to their brothers and sisters on the blue team, it works really well," says O'Dell. If the red team only attacks and then delivers a report, "you get a little value out of that," he says. But if the red team representatives tell the blue team what they could do to make things difficult, it changes the dynamic of the exercise, says O'Dell. "What does that cause the red team to do? It causes them to pivot," says O'Dell. "What happens over time is you get this incremental increase in both your red team and blue team that drives value to your organization, 'cause they're both getting better." This is great for staff retention, too; both teams feel that they always have something to learn. Walmart Leaders Transform Security Operations Without Going Bananas is the complete story of how Walmart has transformed its entire security operations strategy — including O'Dell's approach to executive communication, his framework for balancing security value against operational friction, and his philosophy on positioning security as a business enabler. Related:Claude Mythos — Hype vs. Reality: What Security Teams Need to Know About the Author Richard Thurston Contributing Writer, Dark Reading Richard Thurston is a contributing writer for Dark Reading. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections More Webinars You May Also Like CYBERSECURITY OPERATIONS Hand CVE Over to the Private Sector by Brian Martin JAN 27, 2026 CYBERSECURITY OPERATIONS Shutdown Sparks 85% Increase in US Government Cyberattacks by Nate Nelson OCT 24, 2025 CYBERSECURITY OPERATIONS China Imposes One-Hour Reporting Rule for Major Cyber Incidents by Robert Lemos OCT 01, 2025 CYBERSECURITY OPERATIONS CISA, FBI, NSA Warn of Chinese 'Global Espionage System' by Alexander Culafi AUG 28, 2025 Edge Picks APPLICATION SECURITY AI Agents in Browsers Light on Cybersecurity, Bypass Controls CYBER RISK Browser Extensions Pose Heightened, but Manageable, Security Risks CYBERSECURITY OPERATIONS Video Convos: Agentic AI, Apple, EV Chargers; Cybersecurity Peril Abounds ENDPOINT SECURITY Extension Poisoning Campaign Highlights Gaps in Browser Security Latest Articles in The Edge CYBERSECURITY OPERATIONS Walmart Leaders Transform Security Operations Without Going Bananas AUG 12, 2026 CYBER RISK Sherlock Holmes Was the 'OG' Social Engineer AUG 10, 2026 CYBERSECURITY OPERATIONS From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture AUG 6, 2026 DATA PRIVACY DROP Platform Lets Californians Reduce Digital Footprint JUL 31, 2026 Read More The Edge Want more Dark Reading stories in your Google search results? BLACK HAT ASIA | MARINA BAY SANDS, SINGAPORE Experience cutting-edge cybersecurity insights in this four-day event. Use code DARKREADING for a Free Business Pass or $200 off a Briefings Pass. GET YOUR PASS
    💬 Team Notes
    Article Info
    Source
    Dark Reading
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗