Attackers automate. With AI-native adversaries now using frontier models like Mythos or Astra to adapt tradecraft and scale operations at machine speed, the gap between attacker tempo and defender tempo is widening fast. Yet most organizations still validate their defenses once or twice a year and assume the results hold up. They rarely do: infrastructure changes, detection rules quietly break, and an attacker only needs to slightly vary their approach to get past controls that worked six months ago. Meanwhile, regulations like DORA and NIS2 increasingly expect you to demonstrate that your defenses actually work right now, not just that they were tested at some point in the past.
This talk makes the case for Continuous Purple Teaming (CPT): using automated, repeatable attack simulations to continuously answer the one question that matters: are our security controls protecting us against the threat that matters today?
CPT validates your controls in two directions. Bottom-up, simulations act as a regression test for your detection stack, verifying that what you could detect yesterday you can still detect today. Top-down, you simulate the threats most relevant to your organization and get an immediate, fact-based view of your coverage across frameworks like MITRE ATT&CK. Because every result combines the offensive view (how dangerous is this technique?) with the defensive view (did our controls block or detect it?), CPT also tells you which gaps to fix first, so your team spends its limited time where it counts.
Fixing those gaps is where most programs stall, and where CPT changes the game for your SOC and detection engineering teams. By isolating the exact attacker behavior behind each simulation and pairing every gap with targeted guidance, CPT turns findings into custom detection rules in a fraction of the usual time. The result is detections built on behavior rather than tools, protecting you not just against yesterday’s known attacks but against the AI-equipped attacker of tomorrow.