CISA Ran the Same Attack Against Two Critical Infrastructure Firms. One Saw Nothing.

The federal cyber agency's red team fully took over both networks. One defender caught almost every step. The other missed the intrusion entirely.

ThreatVectr Newsdesk· 4 min read
AI analyzing network data
Share

Key points

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ran two simultaneous red team exercises against two critical infrastructure operators and published the results in a joint advisory.
  • Both organisations were fully taken over at the domain level, meaning the testers gained control of the accounts that manage every user and computer on the network.
  • One defender's security team detected and responded to most of the intrusion steps; the other detected almost nothing.
  • CISA said the two exercises used similar attacker techniques, so the gap in outcomes points to defensive readiness, not attacker skill.
  • The advisory lists specific gaps in logging, alerting and staff training that the weaker organisation should close.

CISA has released the findings of two red team exercises, controlled attacks run by government hackers to test a company's defences, and the contrast between the two targets is the whole story.

Both targets were critical infrastructure operators. CISA has not named them. The agency ran the two engagements at the same time, using what it called similar tradecraft, so the exercises work as something close to a controlled experiment.

In both cases, the red team achieved domain compromise. In plain terms, the testers ended up controlling the central directory that decides who can log in to what across the whole network. From there, an attacker can reach almost any system they want.

One organisation's security team saw it happening. They spotted the early intrusion, tracked the testers as they moved through the network, and responded. The other organisation's team, working against the same style of attack, did not detect the activity in any meaningful way.

The report was first covered by The Hacker News.

Why does this matter for a regulator's playbook?

Because it hands CISA a clean piece of evidence for the argument it has been making in rulemakings and guidance for two years: detection and response, not just prevention, is what separates a survivable incident from a catastrophic one.

The agency's red team assessments are voluntary and confidential by default. When CISA chooses to publish, it is usually to move policy. Expect this advisory to be cited in comment letters on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) proposed rule, published in the Federal Register on 4 April 2024, which would require covered entities to report significant cyber incidents within 72 hours. The comment period on that proposed rule has closed; a final rule is still pending.

What did the weaker defender actually miss?

According to CISA, the organisation that failed to detect the intrusion lacked reliable logging on key systems, did not alert on suspicious use of valid administrator accounts, and had gaps in staff training around unusual login activity.

The stronger defender, by contrast, had working alerts tied to identity events (someone using an admin account at an odd hour, from an odd place) and a team that knew what to do when those alerts fired.

Item Organisation A Organisation B
Domain-level takeover by red team Yes Yes
Detected initial intrusion Yes No
Tracked lateral movement Mostly No
Responded during the exercise Yes No

Should ordinary customers be worried?

Not in a direct, act-today sense. No real attacker breached these companies, and CISA has withheld their names. The value here is what it tells regulators and boards about the state of critical infrastructure defence: two similar organisations, same attack, wildly different outcomes.

For anyone whose water, power or transport depends on operators like these, the honest read is that the sector is uneven. Some defenders are ready. Some are not. That is the case CISA is now making, with data, ahead of the next round of rules.

Common questions

What is a red team exercise?

It is a controlled attack run by friendly hackers, with permission, to test whether a company's defenders can spot and stop a real intrusion. The goal is to find gaps before a criminal does.

What does 'domain compromise' mean?

It means the testers took control of the system that manages all user accounts and computers on the network. Once that is gone, an attacker can typically reach anything.

© 2026 Threat Vectr