Skip to main content
CybersecurityHacking

CISA Red Team Tests Expose Organizational Vulnerabilities

Security analysts work amidst multiple computer screens in a monitoring room with subtle signs of disarray.

CISA found the red team was undetected by the security operations center (SOC) when it gained initial access to several workstations, escalated privileges over the domain, and moved laterally to other systems.

Two critical-infrastructure exercises commissioned CISA

Red team tests were conducted at the behest of two critical infrastructure organizations and the lessons learned were published by the Cybersecurity and Infrastructure Security Agency (CISA). The assessments used adversarial tradecraft to replicate malicious activity and to measure each organization’s ability to detect, probe, and respond to threats.

First organization: undetected access, privilege escalation, lateral movement

In the first assessment, CISA’s red team obtained initial access to several workstations and was not detected by the organization’s SOC. After gaining that initial access, the red team heightened privileges over the domain and shifted laterally to other systems — a sequence CISA documented as occurring without SOC detection.

Second organization: quarantine on initial access, assumed-breach follow-up

By contrast, in the second assessment the SOC identified and quarantined the red team when it first gained access. The red team then adjusted its activity to an assumed-breach model; some of that follow-on activity was detected and contained by the SOC, according to CISA’s published account.

Lessons CISA called out

  • Without tuning, detection tools miss threats.
  • Siloes and bureaucratic complexity inhibit effective response.
  • Cloud environments hold risk that is often underestimated.

Key actions CISA recommends

CISA published four primary actions derived from the exercises:

  • Fine tune tools to enact and sustain a baseline, thus reducing false alert noise.
  • Overcome siloes to empower security workers.
  • Establish policies for conditional access and monitor for unused or excessive permissions.
  • Implement and consistently review procedures for detection and remediation in the event of cloud compromise.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams — Fine tuning detection tools and maintaining a reliable baseline are direct priorities; teams will also need to monitor permissions and review cloud incident procedures in line with CISA’s actions.
  • Policymakers and regulators — The finding that siloes and bureaucratic complexity inhibit response presents a policy lever: actions that reduce organizational friction and empower SOC personnel align with CISA’s recommendations.
  • Affected enterprises and procurement leaders — Establishing conditional access policies, tracking unused or excessive permissions, and instituting repeatable cloud remediation procedures are named, concrete steps that enterprises can adopt to address the risks highlighted by the exercises.

CISA’s paired exercises offer a clear contrast: one organization’s tooling and processes failed to surface an active intrusion that escalated to domain-level privileges and lateral movement; the other organization contained initial access and detected at least some later activity after the red team adopted an assumed-breach posture. The agency’s published lessons and key actions map directly to those outcomes — tuning detection, breaking down siloes, tightening access policies, and preparing for cloud compromise. The remaining question posed by the report is straightforward and operational: will organizations adopt and sustain the specific tuning, access controls, and cloud procedures CISA lists so that the outcomes resemble the second exercise more often than the first?

Original story