IC Technology & Cyber — 2026-08-26
CISA Red Team Breaches Two Critical Infrastructure Organizations Revealing Stark Differences in SOC Effectiveness
BLUFDocumented escalation procedures and unified SOC authority determined whether identical intrusion tradecraft succeeded or failed, making process gaps a more reliable predictor of compromise than technical controls.
CISA published an advisory on August 25 detailing two simultaneous, unnamed red team assessments using nearly identical tradecraft against a Government Services and Facilities Sector organization (Organization A) and a Water and Wastewater Systems Sector organization (Organization B) 1. In both cases the red team gained initial access via phishing, then exploited a default Machine Account Quota and misconfigured Active Directory Certificate Services templates to escalate privileges and reach sensitive business systems and cloud resources 12. Organization A's SOC did not detect the intrusion, allowing the team to read SOC staff emails and deploy keyloggers on defenders' machines undetected. CISA attributed this to multiple uncoordinated SOCs, thousands of false-positive alerts, and no defined escalation procedures 12. Organization B's SOC isolated compromised workstations within 2 to 20 minutes of the phishing payload executing and later blocked a suspicious Azure sign-in and isolated a compromised OT-zone bastion host after CISA moved to an "assume breach" model 13. CyberScoop identified Organization A as a government entity and Organization B as a water utility; CISA did not name either organization 3.
Analysis
Identical tradecraft against both organizations, phishing followed by Machine Account Quota abuse and ESC1 certificate template exploitation, produced opposite outcomes driven by process rather than technology: uncoordinated SOCs and undefined escalation authority let the red team read defender email and plant keyloggers undetected at one organization, while structured triage at the other contained workstations within minutes and later caught a cloud sign-in and OT bastion compromise under a CISA-imposed assume-breach extension. That clean containment record may reflect controlled access CISA granted after detection rather than defenses that would hold against a persistent, uncooperative adversary. Reporting rests solely on CISA's advisory, with trade press supplying sector identification rather than independent confirmation. The exposed misconfigurations are common across critical infrastructure regardless of sector or budget, meaning any organization without documented escalation procedures and cross-team alert triage carries the same blind spot independent of EDR tooling or staffing levels.
3 sources
- A Tale of Two SOCs: Insights From Two Red Team Assessments - CISA
- CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps - Cyber Security News
- Water sector passes, government sector fails attempts to spot and halt simulated CISA attack - CyberScoop
View in full brief →