CISA Red Team Report Contrasts SOC Responses Across Two Critical Infrastructure Orgs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published a comparative red team assessment report on August 25, 2026, examining security operations at two organizations — one from the Government Services sector and one from the Water and Wastewater Systems sector. In Organization A, attackers moved from an initial web application compromise through Active Directory, sensitive business systems, and cloud resources without effective detection, hampered by high alert volumes, siloed SOC teams, and unclear responsibilities. Organization B's defenders rapidly isolated three compromised endpoints within minutes and severed the command-and-control connection, though CISA continued the assessment using an assume-breach model to evaluate deeper infrastructure risks. From that simulated foothold, assessors found exploitable misconfigurations in SCCM, excessive service account privileges, and AD CS vulnerabilities, ultimately reaching domain-level access. CISA emphasized that both organizations reaching full domain compromise should not be read as equivalent outcomes, stressing that Organization B's swift initial containment represented a meaningful defensive success.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in