Walmart's "Trusted Agent" Approach to Purple Teaming
Dark ReadingArchived Aug 12, 2026✓ Full text saved
Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
Full text archived locally
✦ AI Summary· Claude Sonnet
CYBERSECURITY OPERATIONS
REMOTE WORKFORCE
THREAT INTELLIGENCE
СLOUD SECURITY
CASE STUDIES
Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know.
Walmart's "Trusted Agent" Approach to Purple Teaming
Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
Richard Thurston,Contributing Writer, Dark Reading
August 12, 2026
3 Min Read
SOURCE: ALEKSEI GORODENKOV VIA ALAMY STOCK PHOTO
While many organizations struggle with the inherent tension between red and blue teams — where offensive security testers and defensive operators often work in silos or even develop adversarial relationships — Walmart has entirely reimagined this dynamic. Jason O'Dell, the retailer's Global VP of Security Operations, recognizes that the traditional model of rigidly separate teams conducting exercises in isolation delivers limited value and can actually damage team morale and organizational learning.
O'Dell addresses this challenge by focusing on building trust and psychological safety within security operations, transforming purple teaming from a competitive win-lose scenario into a collaborative learning environment. By physically co-locating teams, implementing a "trusted agent" observation model, and emphasizing organizational improvement over individual victories, Walmart has created a security operations culture where both offensive and defensive practitioners continuously elevate their skills — and the company's overall security posture benefits from their combined growth. Here's how they do it.
Related:Walmart Leaders Transform Security Operations Without Going Bananas
Building Learning and Trust Within Operations.
Human relationships within the organization are fundamental to O'Dell's success. A sense of togetherness plays out in the way he constructs purple teaming in security operations, which spans tabletop exercises, attack simulation and adversary emulation.
Some companies maintain rigidly separate defensive (blue) and offensive (red) teams, and some build a "purple team" to focus on both; O'Dell's approach is more nuanced and more founded in how his teams feel about the exercise. It's important to build trust that rises above the "innate friction" that's a natural by-product of pitting team against team. The culture needs to stress that it is not about winning or losing the exercise, he explains.
"I think you have to change that perception," says O'Dell. "You have to make it a safe environment for them to understand that it's about 'Did we drive the best value to the organization in becoming better as a by-product of the campaign and the work we did?'"
O'Dell has moved both red and blue teams into the same business unit and physical location and adopted a "trusted agent" model for purple teaming. When doing full-on adversarial emulation, observers are watching that campaign. For example, two members of the blue team will sit with the red team as they conduct their offensive activity and check whether telemetry, logs and detections are in place in real time. They will also protect the red team by ensuring they don't cause any harm to the business during the exercise.
Related:From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
"As long as you have great blue team members that won't throw a hint over to their brothers and sisters on the blue team, it works really well," says O'Dell.
If the red team only attacks and then delivers a report, "you get a little value out of that," he says. But if the red team representatives tell the blue team what they could do to make things difficult, it changes the dynamic of the exercise, says O'Dell.
"What does that cause the red team to do? It causes them to pivot," says O'Dell. "What happens over time is you get this incremental increase in both your red team and blue team that drives value to your organization, 'cause they're both getting better."
This is great for staff retention, too; both teams feel that they always have something to learn.
Walmart Leaders Transform Security Operations Without Going Bananas is the complete story of how Walmart has transformed its entire security operations strategy — including O'Dell's approach to executive communication, his framework for balancing security value against operational friction, and his philosophy on positioning security as a business enabler.
Related:Claude Mythos — Hype vs. Reality: What Security Teams Need to Know
About the Author
Richard Thurston
Contributing Writer, Dark Reading
Richard Thurston is a contributing writer for Dark Reading.
Want more Dark Reading stories in your Google search results?
ADD US NOW
More Insights
Industry Reports
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Access More Research
Webinars
The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember
Building a Secure AI Strategy for the Enterprise
Is your AppSec program Mythos Ready?
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
Prevention at Machine Speed: Hunting Beyond Known Detections
More Webinars
You May Also Like
CYBERSECURITY OPERATIONS
Hand CVE Over to the Private Sector
by Brian Martin
JAN 27, 2026
CYBERSECURITY OPERATIONS
Shutdown Sparks 85% Increase in US Government Cyberattacks
by Nate Nelson
OCT 24, 2025
CYBERSECURITY OPERATIONS
China Imposes One-Hour Reporting Rule for Major Cyber Incidents
by Robert Lemos
OCT 01, 2025
CYBERSECURITY OPERATIONS
CISA, FBI, NSA Warn of Chinese 'Global Espionage System'
by Alexander Culafi
AUG 28, 2025
Edge Picks
APPLICATION SECURITY
AI Agents in Browsers Light on Cybersecurity, Bypass Controls
CYBER RISK
Browser Extensions Pose Heightened, but Manageable, Security Risks
CYBERSECURITY OPERATIONS
Video Convos: Agentic AI, Apple, EV Chargers; Cybersecurity Peril Abounds
ENDPOINT SECURITY
Extension Poisoning Campaign Highlights Gaps in Browser Security
Latest Articles in The Edge
CYBERSECURITY OPERATIONS
Walmart Leaders Transform Security Operations Without Going Bananas
AUG 12, 2026
CYBER RISK
Sherlock Holmes Was the 'OG' Social Engineer
AUG 10, 2026
CYBERSECURITY OPERATIONS
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
AUG 6, 2026
DATA PRIVACY
DROP Platform Lets Californians Reduce Digital Footprint
JUL 31, 2026
Read More The Edge
Want more Dark Reading stories in your Google search results?
BLACK HAT ASIA | MARINA BAY SANDS, SINGAPORE
Experience cutting-edge cybersecurity insights in this four-day event. Use code DARKREADING for a Free Business Pass or $200 off a Briefings Pass.
GET YOUR PASS