cisatrade-pressNewsThe Broadside2 min read

Water utility detects CISA red team; government agency doesn't

The government SOC wasn't asleep; thousands of false-positive alerts buried the real ones, and organizational silos did the rest.


TL;DR

CISA published a rare public red-team report Tuesday detailing two voluntary assessments: one a government organization, the other a water utility. Both were breached through spearphishing. The water utility's SOC triaged phishing alerts and quarantined affected workstations in 2, 10, and 20 minutes; the government agency's SOC received the alerts but didn't respond, its defenders numbed by thousands of false positives that included higher-severity noise. Both organizations had identical blind spots. Cloud risk was underestimated. Conditional Access for workload identities was missing. And neither had a process to revoke compromised access tokens.

CISA's red team breached both organizations the same way, using spearphishing that convinced users to click malicious links. The responses diverged immediately. At the water utility, the security operations center triaged the alerts and quarantined the three compromised workstations in 2, 10, and 20 minutes respectively. At the government agency, the SOC received low- and medium-severity endpoint detection and response alerts and did nothing with them.

The government failure wasn't a matter of missing tools. CISA's red team accessed the SOC's own email and watched the alerts arrive. The problem was signal-to-noise: thousands of false positives, including some at higher severity, had trained defenders to treat every alert as background radiation. Organizational silos compounded it: detection and response in different groups, handoffs that failed.

The water utility's performance deserves the headline, but CISA's report makes clear it wasn't flawless. After the initial detection, the red team shifted to an "assume breach" model: the utility's trusted agents gave them access equivalent to what they would have had if defenders hadn't caught them. From that position, the red team escalated privileges and moved laterally, reaching the operational technology DMZ through a bastion host after traversing sensitive business systems and cloud resources. Defenders caught them again and isolated the system. Detection worked. The fact that the red team could reach the OT DMZ at all is the finding the water-sector CISO should lose sleep over.

Both organizations shared three specific weaknesses: they underestimated cloud risk, lacked Conditional Access policies for workload identities, and had no process for revoking compromised access and refresh tokens. These aren't exotic gaps. They're the same ones CISA has been flagging in advisories since at least 2023, when it first published red-team findings. Those advisories have been sparse since. CISA said last year it hadn't "laid off" its red team after contractor exits, but the infrequency of public reporting leaves the broader community with fewer of these comparative case studies than it needs.


Published ·Updated ·Deep Fathom