Many security professionals are prone to performing red team security testing, aka "ethical hacking," over blue team security assessments and analyses, according to an Exabeam survey of 276 IT security professionals conducted at this month's Black Hat USA cybersecurity conference in Las Vegas, Nevada.Key findings from Exabeam's survey included:
In addition, 74 percent of IT security professionals have seen their organizations increase their security infrastructure investments as a result of red and blue team testing, according to the Exabeam survey. Meanwhile, 18 percent of survey respondents called these budget changes "significant," and 25 percent claimed that their organization has not increased its security budget after performing red and blue team tests.
- 72 percent of respondents said their organization conducts red team exercises regularly; comparatively, 60 percent said their organization conducts blue team exercises regularly.
- 68 percent said they find red team exercises to be more effective than blue team testing.
- 35 percent said their blue team never or rarely catches their red team.

