cisaregulatorNewsThe Broadside3 min read

CISA Twin Red Team Tests Pin Detection Gap on Governance

The difference between the organization that contained the breach and the one that never detected it came down to governance and incident response authority, not tool procurement.


TL;DR

CISA ran simultaneous red team assessments against two critical infrastructure organizations with the same tradecraft. Organization A never detected full domain compromise, cloud access, or lateral movement to sensitive systems. Organization B detected the initial breach within hours, quarantined affected systems, and forced the red team into an assume-breach model. The difference wasn't tool spend. Organization A's detection tools were untuned, its defenders siloed behind unclear incident response authority. Organization B empowered its defenders to act. The assessment shows detection capability is a governance outcome, not a procurement one.

CISA Twin Red Team Tests Pin Detection Gap on Governance
Editorial illustration · drawn by The Broadside

CISA didn't just publish another red team findings report. It published two, side by side, from assessments run simultaneously with the same tradecraft. That design choice (comparing two organizations that faced the same adversary emulation) is what makes this advisory different from the agency's prior red team publications in 2023 and 2024.

The results are stark. Organization A, a Government Services and Facilities Sector entity, never detected the red team's activity. The team gained initial access through default credentials on a web application, phished four workstations, and exploited a misconfigured Machine Account Quota and ADCS certificate templates to escalate to domain admin. From there they moved laterally to sensitive business systems and cloud resources. Organization A's security team saw evidence of the initial activity but didn't act on malicious network traffic through the DMZ or challenge the red team's presence in the Windows environment.

Organization B, a Water and Wastewater Systems Sector organization, told a different story. Its defenders detected the initial compromise quickly, quarantined affected systems, and forced the red team into an assume-breach model, where trusted agents provided a foothold replicating what the team would have achieved had detection failed. From there the red team still escalated and moved laterally to SBSs, cloud resources, and a bastion host in the OT DMZ. Defenders detected that activity too and isolated the system.

The governance gap, not the tool gap

Both organizations had endpoint detection and response tools. Both had security teams. The asymmetry was organizational.

Organization A's detection tools were untuned. Without well-defined baselines and alert filtering, false positives and routine alerts overwhelmed defenders. But CISA's advisory goes further: the technical gap was downstream of a governance gap. Fragmented communication, unclear responsibilities, and limited defender authority meant that even when alerts fired, no one had both the information and the mandate to act. Organizational silos and bureaucratic hurdles prevented effective incident response.

Organization B had addressed these structural problems before the assessment. Its defenders were empowered to make containment decisions without escalating through layers of approval. Detection tools were tuned against baselines of normal network activity. The result wasn't that Organization B had better technology. The technology it had was actually usable by the people who needed to use it.

Cloud and OT: the expanding attack surface

Both assessments included cloud resources and, for Organization B, OT systems. The red team exploited overprivileged cloud workload identities and the absence of Conditional Access policies. Neither organization had comprehensive procedures for detecting, remediating, and revoking access or refresh tokens in a cloud compromise. The advisory flags this gap explicitly.

For Organization B, the red team demonstrated the ability to reach a bastion host in the OT DMZ, though defenders detected and isolated that activity. The advisory notes that organizations often segment IT and OT environments but fail to account for shared administrative pathways and credential stores that bridge the two.

The Monday list: baselines, authority, cloud token procedures

For the state CISO or municipal IT director reading this: CISA's advisory includes specific, actionable mitigations. Establish and continuously maintain a baseline; reduce alert noise by fine-tuning. Break down silos and empower network defenders with clear incident response authority. Implement Conditional Access policies for workload identities and monitor for excessive or unused permissions. And establish procedures for cloud compromise response, including token revocation, remediation, and re-issuance, before you need them.

The advisory also makes implicit what prior CISA red team reports (AA23-059A from February 2023 and AA24-326A from November 2024) suggested separately: detection tools without detection governance are noise generators. The organization that contained the breach didn't have a different SIEM. It had a different chain of command.


Published ·Deep Fathom