CISA Red Team Tests Expose a Divide in How Security Teams Respond to Intrusions
Key Takeaways
- Detection Made the Difference: CISA’s red team went undetected after gaining access, elevating privileges and moving laterally at one critical infrastructure organization. At the second, the SOC detected and quarantined the initial intrusion.
- Security Tools Are Only Part of the Defense: CISA’s findings emphasize the importance of strong baselines, effective alert filtering and monitoring practices that allow defenders to recognize meaningful activity.
- Organizational Barriers Can Become Security Weaknesses: Silos and bureaucratic hurdles can interfere with detection and incident response, making internal processes part of an organization’s cyber risk.
- Cloud Environments Need the Right Controls: CISA called for security controls and processes appropriate to cloud environments as organizations defend increasingly complex combinations of IT, cloud and operational technology.
- Assumed-Breach Testing Raised the Bar: After the second organization blocked CISA’s initial access, the red team shifted to an assumed-breach model. The SOC went on to detect and quarantine some of the follow-on activity.
Deep Dive
At one critical infrastructure organization, CISA’s red team got in and kept going. It compromised multiple workstations, elevated its privileges over the domain and began moving laterally into other systems and resources. The security operations center never detected it.
At a second organization, the same basic premise produced a very different exercise. The SOC spotted the red team’s initial access and quarantined it, forcing CISA to switch to an assumed-breach model. When the team continued operating from inside the environment, defenders caught and quarantined some of that activity too.
Those two assessments form the basis of a CISA advisory, A Tale of Two SOCs: Insights From Two Red Team Assessments. Both exercises were conducted at the request of the critical infrastructure organizations involved, and both were intended to answer a question that security teams spend enormous amounts of money preparing for: What actually happens when somebody gets in?
CISA’s answer is not especially flattering to the idea that technology alone can settle the matter.
The agency uses adversarial techniques during red team assessments to simulate malicious cyber operations and watch how an organization responds. The point is not simply to find a vulnerable system. CISA is testing whether defenders notice suspicious activity, investigate it and respond effectively as an intrusion develops.
The first organization struggled at the most fundamental stage. Its SOC failed to detect the red team even after the operation had progressed beyond initial access. By then, CISA had elevated privileges over the domain and moved laterally to additional systems and resources.
The second organization stopped the initial compromise quickly enough that CISA had to change the terms of the exercise. Rather than continue trying to establish access that defenders had already cut off, the red team proceeded as though a breach had occurred. The SOC subsequently detected and quarantined some of that follow-on activity.
CISA does not identify either organization in the press release. Nor does the agency present the comparison as a simple contest between a good SOC and a bad one. Instead, it uses what happened inside the two environments to draw attention to weaknesses that can sit around the technology itself.
Organizations need strong baselines for normal network activity and monitoring capable of distinguishing meaningful signals from the surrounding noise, CISA said. They also need to remove organizational silos and bureaucratic obstacles that can interfere with detection and response. Cloud environments require security controls and processes designed for the way those environments actually operate.
That last point matters because the assessments were not confined to a neat corporate network. CISA said the lessons are intended to strengthen protections across information technology, cloud and operational technology environments, the mixture of systems that critical infrastructure organizations increasingly have to defend as a single security problem even when they are managed as several organizational ones.
The advisory’s findings make the consequences of those divisions unusually concrete. Detecting suspicious activity is useful only if someone can make sense of it. An investigation matters only if the people conducting it can get the information they need. A response plan does little good if organizational boundaries or approval processes slow the response while an intruder keeps moving.
Security teams have long known this in principle. A red team has the useful habit of demonstrating it in practice.
“This advisory demonstrates CISA’s commitment to empowering critical infrastructure organizations with the tools and insights they need to outpace sophisticated cyber threats,” Chris Butera, CISA’s acting executive assistant director for cybersecurity, said in announcing the advisory.
Butera urged organizations to sharpen their detection, response and threat-hunting capabilities and to assess their own cybersecurity posture against CISA’s recommendations. He also described the agency’s Red Team as focused on helping federal and critical infrastructure partners identify and mitigate their most significant vulnerabilities and weaknesses.
The advisory was developed in coordination with the two organizations that underwent the assessments. After each exercise, CISA provided the organization with its findings and recommendations for improving cybersecurity posture and resilience to a potential incident.
By publishing the lessons more broadly, CISA is asking network defenders, system administrators and other technical personnel to do something less dramatic than a red team exercise and potentially just as revealing: look at their own environments and decide whether the same weaknesses are there.
The comparison between the two SOCs gives them a fairly unforgiving benchmark. At one organization, defenders interrupted the operation at initial access and continued catching activity after CISA changed tactics. At the other, the red team was already moving through the environment with elevated privileges before the exercise ended without SOC detection.
The difference was not whether somebody managed to get through the front door. In cybersecurity, that is a comforting standard that organizations cannot afford to depend on. What separated the two assessments was what happened next, and whether anyone was watching closely enough to see it.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

