Two SOCs, Same Attack: CISA Red Team Walks Through One Network, Gets Caught in the Other

CISA ran identical red team drills against a government agency and a water utility. One let the attackers roam for weeks. The other spotted them within hours.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: two different security operations centers (one dimly lit, one brightly lit)
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • The Cybersecurity and Infrastructure Security Agency (CISA) ran two simultaneous red team drills in 2026, one at a government services agency and one at a water and wastewater utility.
  • Both organisations were fully compromised at the domain level, but only the water utility detected and contained the initial break-in.
  • The government agency missed a phishing attack that gave the red team access to four staff workstations, then let attackers reach sensitive business systems and cloud resources undetected.
  • CISA attributed the government agency's failure to untuned alerts, siloed teams and weak cloud security controls.
  • The advisory urges critical infrastructure operators to baseline their alerts, give defenders authority to act fast, and write real playbooks for cloud break-ins.

CISA sent its red team into two organisations at once. Same tradecraft. Wildly different results.

One target was a federal government services agency. The other was a water and wastewater utility. Both ended up fully compromised at the top level of their Windows networks. Only one noticed.

The advisory from CISA, published 25 August 2026, calls the pair "A Tale of Two SOCs." A SOC is a security operations centre, the team of analysts watching alerts and hunting for intruders. It's uncomfortable reading for anyone running one. Six days earlier, we reported on a separate CISA warning about attackers targeting water sector systems, which makes the utility's strong showing here worth underlining.

How did the red team get in?

Through a web application with default usernames and passwords nobody had changed. The red team used those built-in accounts to send phishing emails from a real internal address, fake messages designed to look legitimate and trick staff into clicking. Four people at the government agency clicked. That was enough.

From those four workstations, the attackers ran a modified version of BloodHound, a tool that maps who has access to what inside a Windows network. They'd tweaked it to slip past the agency's endpoint detection and response software, the security tool watching each computer for suspicious behaviour.

Then they found two more openings. The network let ordinary users add up to ten new computer accounts to the domain. And the certificate service, which issues digital identity credentials, was misconfigured in a way known as ESC1, letting any user request a certificate impersonating anyone else, including administrators.

The red team created a machine account, requested a certificate as a privileged user, and had full control.

What did Organisation A miss?

Nearly everything. Alerts were firing, but nobody had tuned them, so real attacks blurred into a wall of false positives. Analysts didn't know who owned which system. Defenders lacked authority to isolate machines without sign-off from other teams. By the time anyone might have looked, the red team was already inside sensitive business systems and cloud accounts.

Why did Organisation B do better?

Defenders spotted the initial break-in and quarantined the affected machines fast. The red team had to switch to what CISA calls an "assume breach" model: the utility handed them access to a test host so the drill could continue, mimicking what the attackers would have reached had they not been caught.

Even then, when the red team moved toward the operational technology network, the systems that physically run pumps and treatment processes, through a bastion host in the DMZ, defenders caught them again and isolated it. Detection tools are only as good as the people behind them. The utility didn't have better software. It had a better-organised team.

Should you worry?

If your SOC can't say who owns each asset on the network, yes. The government agency's failure wasn't exotic; it was a tuning problem and a bureaucracy problem. Both are fixable before a real attacker shows up.

What does CISA want organisations to do?

Weakness at Org A CISA's recommended fix
Untuned alerts, too much noise Build a baseline of normal activity, filter routine alerts
Siloed teams, slow response Give defenders authority to isolate systems without waiting for approval
Weak cloud controls Apply Conditional Access to workload identities, review permissions
No cloud breach playbook Write and rehearse procedures for revoking access tokens
© 2026 Threat Vectr