Summary
Cas van Cooten’s core message is that continuous purple teaming can reduce the uncertainty created by point-in-time security assessments by turning attack simulation, defensive measurement, and prioritization into an automated feedback loop. He frames the value proposition around a mismatch between modern attackers and defenders: attackers, especially with AI-assisted iteration, can build tools and scale campaigns in minutes or hours, while defenders often depend on slower manual validation through penetration tests, red teams, or similar human-led assessments. Those assessments may be accurate when delivered, but security environments change afterward through vendor updates, configuration changes, new systems, new people, and SOC tuning, creating what he calls control drift.
Key Topics
5 key topics from Cas van Cooten at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Automate repetitive attack validation to reduce control drift.
- Regression-test detections continuously, not only after assessments.
- Operationalize threat intelligence into realistic attack simulations.
- Measure behavior, not just known malicious tools.
- Use purple teaming to connect offensive and defensive learning.
“put the hackers on the fun stuff, automate the boring stuff.”

Cas van Cooten
Up Next


Next in agenda
Single Country of Failure is the metric you’re missing


Also on cybersecurity
VShell: Tracking a State-Actor C2 Framework in the Wild



Also on threat intelligence
