How Walmart Turned Its Security Red Team and Blue Team Into Allies
Rather than letting offensive and defensive security testers work against each other in secret, Walmart's security chief put them in the same room and changed the rules of the exercise.

Key points
- Walmart's Global VP of Security Operations, Jason O'Dell, physically moved its red and blue security teams into the same building and the same business unit.
- The company uses a "trusted agent" model, where two blue-team members sit with the red team during live attack simulations to watch for problems in real time.
- The goal of every exercise is organisational improvement, not deciding which team "won".
- O'Dell says the approach also helps retain staff, because both teams always have something new to learn.
Walmart runs one of the largest private security operations in the world, and for years it faced the same friction that slows down most large companies: the people paid to break things (the red team) and the people paid to stop them (the blue team) barely talked to each other.
Jason O'Dell, Walmart's Global VP of Security Operations, decided that model was producing limited value. He told Dark Reading the two teams were essentially working in silos, running exercises in isolation, and occasionally developing something close to a rivalry. The result was a report delivered at the end, a few lessons filed away, and not much lasting change.
So he scrapped it.
How does the new model actually work?
O'Dell moved the red team and the blue team into the same physical space and the same business unit, then built what he calls a "trusted agent" approach to purple teaming. Purple teaming, in plain terms, is when a company runs a security exercise where the attackers and the defenders actively share information instead of operating in total secrecy.
Under Walmart's version, when a live attack simulation begins, two blue-team members sit directly with the red team. They watch every move in real time, checking whether the company's detection systems, logs, and alerts are firing as they should. They also act as a safety valve, making sure the simulated attack does not accidentally disrupt real business systems.
"As long as you have great blue team members that won't throw a hint over to their brothers and sisters on the blue team, it works really well," O'Dell said.
The key rule is that those observers stay quiet during the exercise. They watch, they learn, but they do not tip off their defensive colleagues.
Why does sharing information help rather than spoil the exercise?
After a simulation, the red team tells the blue team exactly what techniques they used and what the defenders could do to make things harder next time. That feedback forces the red team to adapt its approach for the following exercise, which pushes the blue team to adapt further, and so on.
"What happens over time is you get this incremental increase in both your red team and blue team that drives value to your organisation," O'Dell said, "because they're both getting better."
A traditional approach, where the red team attacks silently and hands over a written report weeks later, produces some useful findings. But it does not build the fast, continuous feedback loop that O'Dell describes.
| Approach | Teams | Information shared? | Outcome |
|---|---|---|---|
| Traditional red team | Separate, siloed | No | Report delivered after exercise |
| Standard purple team | Separate with liaison | Partial | Some shared learning |
| Walmart trusted agent | Co-located, same unit | Yes, in real time | Continuous skill growth on both sides |
O'Dell also frames every exercise around one question: did the company become more secure as a result? Winning or losing is not the point. That cultural shift, he says, is what makes the model stick.
Staff retention has improved too. When both teams know they will always walk away having learned something new, the exercises feel like investment rather than judgment.
For ordinary Walmart customers and suppliers, the practical upshot is straightforward: a company that practices its defences this way is more likely to catch a real intrusion early, before personal data or payment information is affected.



