Two organizations. The same attack playbook. Wildly different outcomes.

That’s the story behind a new advisory just released by the Cybersecurity and Infrastructure Security Agency (CISA), which ran simultaneous red team assessments — simulated cyberattacks — against two critical infrastructure organizations. One caught the intruders in minutes. The other never noticed at all, even as attackers read staff emails and logged their keystrokes (CISA AA26-237A).

For any organization that handles sensitive data — municipalities, healthcare providers, manufacturers, financial firms — this report is a real-world case study in what separates a security program that works from one that only looks good on paper.

What CISA Actually Did

CISA’s red team plays the role of a real attacker. Their job is to break in, move around, and see how far they can get before someone notices (CISA AA26-237A).

They tested two organizations at the same time, using nearly identical tactics:

  • Organization A, a government services entity, never detected the intrusion. Attackers phished four employees, exploited a misconfigured Active Directory setting, and escalated all the way to full control of the network, business systems, and cloud email — undetected the entire time.
  • Organization B, a water utility, caught the attackers within 2 to 20 minutes of the initial phishing click and immediately isolated the infected machines. CISA then had the utility’s own staff simulate a deeper breach so the red team could keep testing — and even then, defenders caught and shut down a second intrusion attempt into their operational technology network.

The Real Difference Wasn’t the Attack. It Was the Response.

Both organizations faced the same tricks: phishing emails, weak Active Directory settings, and overly permissive cloud accounts. What set them apart was how prepared their teams were to notice and act.

Organization A’s security team was buried under thousands of low-priority alerts from normal business activity, so the real threat blended in and got missed. Organization B had tuned its alerts to filter out the noise, so anything unusual stood out immediately (CISA AA26-237A).

Organization A also had multiple disconnected security teams that didn’t talk to each other or have clear authority to act. When one team saw a suspicious alert about an unfamiliar system, they couldn’t identify who owned it or what it did — so they marked it a false positive and moved on. Organization B empowered its staff to isolate a suspicious machine first and ask questions later.

The lesson: tools alone don’t stop breaches. Trained people with clear authority and clean alerts do.

The Cloud Is Everyone’s Blind Spot

Here’s the part that should worry every organization, even the ones with strong on-site defenses: both organizations got compromised in the cloud.

Attackers found applications with far more permissions than they needed — the kind of access that lets a piece of software read every employee’s email without anyone signing off on it. Neither organization had “Conditional Access for workload identities” turned on, a Microsoft feature that limits how and when applications can use their permissions (CISA AA26-237A).

Organization A also used cloud access keys that never expired. If those keys had leaked publicly instead of being found by CISA’s testers, an attacker could have had standing access to sensitive cloud systems indefinitely.

Four Things Every Organization Should Do Now

CISA’s advisory maps directly onto its Cross-Sector Cybersecurity Performance Goals, and the takeaways apply well beyond critical infrastructure:

  1. Tune your alerts. If your team is drowning in false positives, real threats will slip through. A baseline of “normal” activity makes anomalies easy to spot.
  2. Give your security team clear authority. Isolating a suspicious device should not require a committee meeting. Define who can act, and let them act fast.
  3. Lock down application permissions in the cloud. Review what your Microsoft 365, Entra ID, or Google Workspace applications can actually access, and turn on Conditional Access policies for those applications — not just for human users.
  4. Kill standing access. Rotate credentials, expire cloud access keys, and build a real process for revoking tokens the moment you suspect a compromise.

Why This Matters for You

Most organizations don’t have a CISA red team testing their defenses before a real attacker does. That’s exactly the gap a managed detection and response partner is built to close — tuned alerting, 24/7 monitoring, and a clear incident response process, so your team isn’t the one buried in noise when it counts.

If you’re not confident your organization would respond like Organization B, let’s talk. A short conversation now is a lot cheaper than finding out the hard way.


Source: CISA Cybersecurity Advisory AA26-237A, “A Tale of Two SOCs: Insights From Two Red Team Assessments,” published August 25, 2026

Leave a Reply

Your email address will not be published. Required fields are marked *