The latest findings from the Cybersecurity and Infrastructure Security Agency (CISA) highlight significant security vulnerabilities within critical infrastructure systems, emphasizing the necessity of skilled analysts to effectively address security alerts. Despite substantial financial investments, these systems can still be compromised without proper human oversight.
Comparative Red Team Engagements
CISA’s report, “A Tale of Two SOCs,” outlines two simultaneous red team evaluations targeting different sectors: one focusing on a Government Services organization and the other on a Water and Wastewater Systems entity. Although similar attack methods were employed, outcomes varied drastically between the two.
Both incursions began with phishing attacks to establish an initial foothold. Red team operatives exploited misconfigurations in Active Directory, such as inadequate Machine Account Quota settings and flawed Active Directory Certificate Services templates, to elevate privileges and navigate the networks laterally.
Case Study of Organization A
In the case of Organization A, the CISA red team successfully infiltrated the network, achieving high-level domain privileges without detection. They accessed sensitive business systems and cloud assets, even reading the emails of Security Operations Center (SOC) personnel and deploying keyloggers on defender systems undetected.
Conversely, Organization B swiftly responded to the breach by isolating compromised workstations within minutes, effectively disrupting command-and-control channels before the intrusion spread. As a result, CISA adjusted its strategy to an “assume breach” model, simulating deeper access had the phishing attempt gone unnoticed.
Security Lessons and Recommendations
Despite gaining extensive access through similar vulnerabilities, Organization B’s defense mechanisms, including isolating compromised systems and recognizing suspicious Azure logins, proved robust even under compromised conditions. This highlights the importance of layered detection and proactive defense strategies.
Organization A’s shortcomings were attributed not to a lack of security tools but to operational inefficiencies. Multiple SOCs and Endpoint Detection and Response (EDR) platforms operated in silos, while genuine threats were lost among numerous false positives. Analysts had unclear escalation protocols and limited authority, leading to missed alerts.
CISA advises critical infrastructure operators to address common Active Directory weaknesses, implement credential expiration policies, and enforce Conditional Access to enhance application permissions. Furthermore, establishing clear escalation procedures and empowering analysts are crucial for effective incident response.
Organizations must prioritize swift threat identification and isolation to prevent incidents caused by delayed investigations.
