TechNewsReel
Live

CISA Red Team Tests Reveal Stark Gap in Critical Infrastructure Defense

A new CISA advisory shows that while two targets suffered full domain compromise, one detected nothing while the other responded in minutes.

TechNewsReel Newsroom · August 26, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) recently conducted simultaneous red team assessments against two critical infrastructure organizations, revealing a stark divide in defensive capabilities. Despite facing similar adversarial tradecraft, the two organizations experienced vastly different outcomes in their ability to detect and contain the simulated attacks.

According to a CISA advisory titled "A Tale of Two SOCs" (AA26-237a) published on August 25, 2026, both organizations suffered full domain compromise. The red team successfully gained unauthorized access to cloud resources and sensitive business systems in both environments. However, the defensive responses differed drastically: Organization A failed to detect or contain any of the activity, while Organization B rapidly identified initial compromise attempts and isolated affected workstations within two to 20 minutes. This efficiency forced the CISA red team to shift to an "assume breach" model to proceed.

The Human Element of Defense

These assessments were performed at the request of the organizations to evaluate their real-world ability to investigate and respond to threats across IT, cloud, and operational technology (OT) environments. The disparity in results was most evident in the performance of the Security Operations Centers (SOCs). In the case of Organization A, the failure was absolute; the red team went as far as accessing the emails of SOC staff and deploying keyloggers directly on the machines of the defenders themselves.

Why Tools Aren't Enough

CISA notes that these results highlight a critical industry lesson: security outcomes depend on more than the deployment of expensive tools. The agency emphasizes that effectiveness relies heavily on the operational maturity of the SOC, the establishment of clear behavioral baselines to identify anomalies, and the removal of bureaucratic hurdles that can slow down rapid incident response. When defenders are hampered by red tape or lack a baseline of "normal" network behavior, even advanced tools fail to prevent a total takeover.

Strengthening Infrastructure

Chris Butera, CISA Acting Executive Assistant Director for Cybersecurity, stated that the advisory demonstrates the agency's commitment to providing critical infrastructure organizations with the insights needed to outpace sophisticated threats. As attackers increasingly target critical sectors, the shift toward the "assume breach" mentality—where defenders operate under the premise that the perimeter has already been breached—is becoming a necessity for survival.

Moving forward, network defenders and systems administrators are encouraged to use the "A Tale of Two SOCs" findings to audit their own response times and internal communication chains. The primary remaining challenge for many organizations is transitioning from a tool-centric security posture to one focused on active, agile detection and containment.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.