CISA Red Team Exercise Reveals Stark Defensive Deficiencies in Government Sector, Water Sector Shows Resilience
A CISA red team exercise found a government organization vulnerable to undetected domain compromise, while a water sector organization successfully detected and contained a similar simulated attack.

The Cybersecurity and Infrastructure Security Agency (CISA) recently conducted a red team exercise against two organizations, one in the government sector and another in the water sector, to test their defensive capabilities. The results, detailed in a rare public report, highlighted significant disparities in security posture. In the government organization, dubbed "Organization A," red teamers successfully gained initial access to multiple workstations via phishing, escalated privileges to domain administrator level, and moved laterally to sensitive business systems and cloud resources without detection.
CISA's analysis of "Organization A" revealed that defenders missed critical alerts due to a combination of overwhelming false positives and organizational silos. Security operations center personnel observed low- and medium-severity endpoint detection and response alerts triggered by the red team's activity, but these were obscured by thousands of other alerts, preventing timely response. The report specifically cited "organizational silos" as a contributing factor to the lack of effective defense.
In contrast, the water sector organization, "Organization B," demonstrated a much more robust defensive capability. When faced with a similar spearphishing campaign that successfully compromised three user workstations, the security operations center triaged the alerts and quarantined the affected systems within minutes. This rapid detection and containment significantly hampered the red team's progress.
Despite the initial success in detecting the simulated attack, the red team attempted to pivot to an "assume breach" scenario with the cooperation of "Organization B's" IT team, who were aware of the exercise. Even in this more challenging scenario, where the red team was provided with pre-compromised access, defenders were able to detect further lateral movement and isolate systems, including those in an operational technology (OT) demilitarized zone (DMZ).
However, CISA noted that both organizations exhibited critical defensive gaps. Neither organization had implemented Conditional Access for workload identities, a key Microsoft security tool. Furthermore, both lacked adequate processes for revoking compromised access and refreshing tokens, leaving them vulnerable to persistent threats even after initial detection.
The exercise comes at a time of heightened concern for the water sector, following recent revelations of targeting of water facilities across the United States and numerous government warnings. CISA's public reporting on its red team activities, while infrequent, provides valuable insights into real-world defensive strengths and weaknesses.
While "Organization B" showcased a commendable ability to detect and respond to threats, the exercise underscores that even resilient organizations can have exploitable vulnerabilities. The persistent challenges faced by "Organization A" serve as a stark warning about the impact of alert fatigue, poor alert triage, and internal communication breakdowns on an organization's ability to defend itself against sophisticated adversaries.
CISA's findings emphasize the need for organizations across all sectors to continuously evaluate and mature their security operations, focusing on effective alert management, robust identity and access controls, and streamlined incident response processes to counter evolving cyber threats.