CISA Releases Cybersecurity Advisory Detailing Insights from Two Red Team Assessments Conducted at Critical Infrastructure Organizations

08/25/2026 11:00 AM EST

Banner for the Cybersecurity and Infrastructure Security Agency featuring the agency's logo and a digital globe with cyber elements.

The Cybersecurity and Infrastructure Security Agency (CISA) released a Cybersecurity Advisory, A Tale of Two SOCs: Insights From Two Red Team Assessments, sharing lessons learned from simultaneous CISA red team assessments conducted by request at two critical infrastructure organizations.

CISAโ€™s red team simulated real-world threat actor tradecraft to assess each organizationโ€™s ability to detect, investigate and respond to malicious activity across enterprise IT, cloud identity and applications. For Organization B in particular, the team also tested pathways toward the operational technology (OT) environment. Although the red team used similar tradecraft in both environments, the defensive outcomes differed significantly:

  • Organization A (Government Services and Facilities Sector): The red team gained initial access to multiple workstations, escalated privileges to domain-level control, and moved laterally to sensitive business systems (SBSs) and cloud resources without effective defensive intervention.
  • Organization B (Water and Wastewater Systems Sector): Defenders rapidly detected and contained the initial compromise by isolating affected workstations, forcing the red team to move to an assume breach model. Defenders also detected and isolated and blocked suspicious cloud account activity.

The advisory highlights that security outcomes depend on more than tools and underscores that cloud identity and application security remains a common risk area, even for organizations with strong on-premises detection and response capabilities.

CISA urges organizations, especially those operating in hybrid identity environments and/or those with IT-OT connectivity, to review the advisory and implement mitigations, including the following key actions:

  • Establish and continuously maintain a baseline; reduce alert noise by fine tuning.
  • Break down silos and empower network defenders.
  • Implement Conditional Access policies for workload identities and monitor for excessive or unused permissions.
  • Establish and regularly review comprehensive procedures for detecting, remediating, and revoking access/refresh tokens in the event of a cloud compromise.

Read the full advisory for more information.

The red team findings also highlight the impact of isolation as a critical defense measure. To learn more about CISAโ€™s guidance on isolation and recovery, visit the CI Fortify webpage.


Discover more from #News247WorldPress

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading