# Walmart Stopped Letting Its Security Teams Fight Each Other — and Everyone Got Better
At most companies, a purple team exercise ends the same way: red team hands over a report, blue team defends its detection rate, somebody loses politically, and nothing meaningfully changes. The adversarial framing that's supposed to stress-test defenses ends up stress-testing relationships instead.
Jason O'Dell, Walmart's Global VP of Security Operations, decided that model was broken.
## The Problem No One Wants to Admit
The red/blue dynamic has always carried an uncomfortable tension that the industry papers over with jargon. Red teams are incentivized to win — to find the breach, demonstrate access, prove the defenders failed. Blue teams are incentivized to look good — to show their tools fired, their runbooks held. In that environment, sharing tradecraft is career-limiting. Why would a red teamer coach the defenders who'll judge next quarter's exercise?
The result is security theater with a vengeance. Each side performs for the scoreboard rather than the actual adversary, and the organization's real posture improves at a fraction of what it could.
O'Dell's framing is direct: the "innate friction" of pitting team against team isn't a feature of rigorous security testing. It's a bug.
## What Walmart Actually Built
The core of Walmart's approach is physical co-location of offensive and defensive practitioners. That sounds trivial until you consider what it actually does: it turns exercises into conversations that start before the exercise begins and continue after it ends.
The "trusted agent" model is the mechanism that makes co-location functional rather than just logistically convenient. Rather than red team operating covertly against a blue team that discovers the intrusion after the fact, designated observers from both sides participate transparently in planning. This strips out the "gotcha" element and replaces it with something more valuable — granular, real-time feedback on why a detection fired (or didn't), what the attacker's decision tree actually looked like, and where the defensive playbook had gaps the runbook authors never anticipated.
O'Dell runs exercises across three formats: tabletop, attack simulation, and adversary emulation. Each demands different levels of collaboration. A tabletop can be done over a conference table with both teams walking through the scenario together. Full adversary emulation — where the red team replicates a specific threat actor's tooling and behavior — benefits most from the trusted agent model, because the techniques are sophisticated enough that pure discovery-mode blue team response misses most of the learning value.
The cultural shift is equally deliberate. Exercises are explicitly reframed as organizational improvement opportunities rather than competitions. No one "wins" the purple team exercise. The only metric that matters is whether the team leaves with sharper detection logic, better runbooks, or a clearer picture of exposure.
## Why This Is Hard to Copy
Walmart can do this partly because scale demands it. With a security operations function spanning global retail — supply chain, e-commerce, in-store systems, payment infrastructure — the blast radius of a real incident is enormous enough that O'Dell can justify the cultural and structural investment required to make this work.
Smaller security orgs often lack the headcount to maintain meaningful red and blue capability simultaneously, let alone co-locate them. Many rely on third-party red teams for offensive work, which introduces a contractor-client dynamic that's structurally hostile to the trusted agent model. Consultants have scope, deliverables, and engagement timelines. Vulnerability disclosure is a deliverable. Continuous collaborative learning is not in most SOW templates.
The psychological safety dimension is also harder than it sounds. O'Dell is explicit that the culture has to suppress the win/lose instinct deliberately and repeatedly. That's a management problem as much as a technical one — and most security organizations are not set up to solve management problems with the same rigor they apply to technical ones.
## The Part Other Coverage Is Missing
What's not discussed in most writeups of this model is what it means for talent development and retention, which may actually be the more durable advantage.
Security practitioners who work in siloed red or blue roles tend to get narrower over time. Red teamers lose touch with how detection logic works in production environments; blue teamers lose touch with how attacker tooling has evolved. The co-located model forces continuous cross-pollination that functions as structured professional development — and in a labor market where experienced security engineers are acutely hard to retain, that's not a soft benefit. It's an operational advantage.
---
## HackWire Analysis
The red vs. blue narrative has served the security industry for decades as a useful shorthand, but it has also calcified into a structure that actively limits organizational learning. Walmart's approach isn't radical — elements of it appear in DevSecOps literature going back at least fifteen years — but seeing it implemented at Walmart's scale, and framed explicitly around psychological safety rather than just process efficiency, is worth attention.
The deeper pattern here is the security industry's persistent tendency to import military and sports metaphors that fit the sales pitch better than the operational reality. "Red team defeats blue team" is a compelling story. It implies rigor, pressure-testing, and high stakes. What it frequently produces is a competitive dynamic where both sides optimize for the exercise outcome rather than the organization's actual resilience.
The trusted agent model breaks that by making the exercise transparent. Transparency reduces the incentive for gaming and shifts both teams toward a shared objective. This is the same insight behind blameless postmortems in SRE culture — the ritual debrief stops being useful the moment participants feel they're being judged rather than learning.
What Walmart is describing is, at its core, an application of psychological safety research to security operations. That's not new thinking — Amy Edmondson's work on team psychological safety dates to the late 1990s — but it's still rare enough in security orgs that it reads as novel. Most security cultures are structured around individual accountability and competitive credentialing, which actively suppresses the collaborative behavior that makes joint exercises valuable.
Defenders in mid-market organizations should take the structural lesson even if they can't replicate the resourcing: the first thing to fix in any purple team program is the incentive structure, not the tooling.
— HackWire Editorial
---
## Related Coverage