The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently shared findings from its red team assessments of two critical infrastructure entities, showcasing varied defensive reactions despite employing similar strategies. Both entities were breached at the domain level, with access gained to sensitive business systems and cloud resources.
Red Team Assessment Overview
Dated August 25, 2026, CISA’s advisory, labeled AA26-237A and titled “A Tale of Two SOCs,” details the assessments on two organizations: a Government Services and Facilities Sector entity, referred to as Organization A, and a Water and Wastewater Systems Sector entity, known as Organization B. The evaluations highlighted significant differences in how each organization handled security threats.
For Organization A, the red team exploited a web application using default credentials, enabling them to dispatch phishing emails internally and compromise multiple workstations. The team further elevated their access by manipulating an Active Directory Certificate Services (AD CS) template and using stored cleartext credentials to infiltrate three sensitive business systems.
Organization A’s Security Challenges
Organization A’s defenses failed to detect these breaches, largely due to an overwhelming number of false-positive alerts that masked genuine threats. Multiple security operations centers (SOCs) and endpoint tools operated without shared visibility, and analysts lacked the necessary escalation processes and authority, leading to the dismissal of critical alerts as false positives.
CISA identified several vulnerabilities within Organization A: default Machine Account Quota settings, misconfigured AD CS templates, insecure storage of cleartext credentials, static cloud keys without expiration, and excessive permissions in Entra ID applications.
Organization B’s Proactive Defense
In contrast, Organization B’s SOC quickly identified and neutralized phishing payloads within minutes, isolating affected systems and preventing command-and-control communications. To simulate further access, CISA’s agents executed a red team payload on a non-privileged host, revealing similar underlying issues but without any further breach into its operational technology systems due to effective network restrictions.
CISA credited Organization B’s success to its adept personnel and robust processes, emphasizing that detection tools are only as effective as the teams managing them.
Ultimately, these assessments underscore the critical role of skilled personnel and processes in enhancing cybersecurity defenses, beyond just the technological tools employed.
