https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
The Cybersecurity and Infrastructure Security Agency has published a cybersecurity advisory detailing the findings from two simultaneous red team assessments conducted at critical infrastructure organisations, one in the Government Services and Facilities sector and one in the Water and Wastewater Systems sector. The assessments used comparable tradecraft against both targets but produced dramatically different defensive outcomes, with the advisory framed as a practical case study in what effective and ineffective security operations look like under real-world attack conditions. In both environments the red team ultimately achieved full domain compromise and accessed sensitive business systems and cloud resources, but the path to that outcome and the defenders’ ability to detect and respond differed significantly between the two organisations.
At Organisation A, the red team identified a web application using default credentials across multiple built-in user accounts, which allowed them to send emails from an internal address. These were used to conduct phishing campaigns that yielded initial access to four workstations. From those workstations the team used a modified BloodHound collector customised to evade static endpoint detection and response signatures to scrape Active Directory information including users, computers, groups, access control lists, and organisational units. The red team then escalated privileges, moved laterally to sensitive business systems and cloud resources, and completed the assessment without being detected at any stage. Organisation A’s failure was characterised by untuned detection tooling that generated excessive alert noise, organisational silos that fragmented communication and responsibility, and defenders lacking sufficient authority to act decisively. The combination meant that even where tooling existed, the people, processes, and procedures required to make it effective were absent.
Organisation B presented a contrasting picture. When the red team attempted initial compromise, network defenders rapidly detected the activity, quarantined affected systems, and forced the assessment into an assume breach model in which trusted agents provided the red team with access replicating what would have been achieved had the initial detection failed. From that position the red team escalated privileges and moved laterally to sensitive business systems, cloud resources, and a bastion host in the operational technology demilitarised zone, at which point defenders again detected the activity and isolated the affected system. The advisory notes that Organisation B’s success stemmed from well-maintained detection baselines, clear responsibilities, empowered defenders, and effective inter-team communication.
CISA identified three principal lessons from the paired assessments. First, untuned detection tools produce alert volumes that overwhelm defenders and cause genuine threats to be missed, making continuous baseline maintenance and alert filtering essential rather than optional. Second, organisational silos and bureaucratic constraints are themselves a security vulnerability, as detection tooling is only as effective as the human and procedural infrastructure supporting it, and fragmented communication with unclear ownership prevents timely response. Third, cloud environments represent a consistently underestimated risk, with many organisations lacking both the security controls and the incident response procedures needed to detect and respond to cloud compromise. CISA’s recommended mitigations include establishing and continuously refining detection baselines to reduce noise, breaking down organisational silos and empowering network defenders with clear authority, implementing conditional access policies for workload identities with monitoring for excessive or unused permissions, and establishing and regularly reviewing procedures for detecting, remediating, and revoking access and refresh tokens in the event of a cloud compromise.