VYPR
advisoryPublished Aug 25, 2026· 2 sources

CISA Red Team Assessments Highlight Critical Defensive Gaps in Two Organizations

CISA's red team exercises revealed stark differences in cybersecurity defenses, with one organization falling victim to undetected domain compromise while another rapidly detected and contained threats.

The Cybersecurity and Infrastructure Security Agency (CISA) recently conducted two simultaneous red team assessments, simulating real-world cyber threats against two critical infrastructure organizations. The exercises aimed to evaluate the effectiveness of each organization's security operations centers (SOCs) and overall defensive posture. While both red teams successfully achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources, the outcomes diverged significantly, offering critical lessons for the broader cybersecurity community.

In Organization A, the red team operated with near-complete impunity. After gaining initial access to multiple workstations, they were able to elevate privileges across the domain and move laterally to access sensitive business systems and cloud environments without triggering any alerts. This complete lack of detection underscores profound weaknesses in Organization A's security monitoring, incident response, and overall threat detection capabilities. The red team's undetected access highlights a critical failure to identify and stop malicious activity, leaving sensitive data and operations vulnerable.

Organization B, however, presented a starkly different picture. Defenders in this organization rapidly identified the initial compromise attempts, quickly isolating affected systems. This swift action forced the red team to shift to an "assume breach" model, where they were provided with a compromised host to simulate the level of access they would have achieved had they not been detected. Even within this constrained scenario, defenders again detected and isolated the red team's activity when they attempted to access Operational Technology (OT) systems in a demilitarized zone (DMZ).

The key lessons derived from these contrasting outcomes point to several critical areas for improvement. Firstly, the assessments revealed that untuned detection tools, overwhelmed by alert noise and lacking well-defined baselines, lead to missed threats. Effective defense requires meticulous configuration and continuous tuning of security monitoring solutions. Secondly, organizational silos and bureaucratic hurdles significantly impede effective incident response. Fragmented communication, unclear responsibilities, and limited defender authority can cripple an organization's ability to react swiftly and decisively to an attack.

Furthermore, the assessments highlighted that cloud environments often represent an underestimated risk. Many organizations lack adequate security controls and robust incident response processes specifically tailored for cloud compromises. The ease with which the red team accessed cloud resources in Organization A suggests a common gap in securing these increasingly vital digital assets. This underscores the need for organizations to extend their security frameworks and response plans to encompass cloud infrastructure comprehensively.

CISA's advisory provides actionable recommendations for organizations to bolster their defenses. These include establishing and continuously maintaining a baseline of normal network activity to reduce alert noise, breaking down organizational silos to empower network defenders, and implementing Conditional Access policies for workload identities. Monitoring for excessive or unused permissions in cloud environments is also crucial.

Additionally, organizations are urged to establish and regularly review comprehensive procedures for detecting, remediating, and revoking access or refresh tokens in the event of a cloud compromise. By implementing these measures, critical infrastructure organizations can significantly enhance their ability to detect, respond to, and ultimately prevent sophisticated cyber threats, strengthening their overall cybersecurity posture across IT, cloud, and OT environments.

This new report from CISA's red team provides a deeper dive into the "A Tale of Two SOCs" engagements, detailing the specific Active Directory misconfigurations exploited, such as default Machine Account Quota and misconfigured AD Certificate Services templates. It highlights that Organization A was completely undetected, even accessing SOC staff emails and deploying keyloggers, while Organization B's rapid response within minutes prevented widespread compromise, underscoring the critical role of human analysis and effective processes over mere tooling.

Synthesized by Vypr AI