WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published an advisory about lessons learned from red team assessments performed at the request of two critical infrastructure organizations to help organizations strengthen detection, response and protections in information technology (IT), cloud, and operational technology (OT) environments.
During red team assessments, CISA uses adversarial tradecraft to simulate malicious cyber operations. The objectives are to observe and evaluate an organization’s ability to detect, investigate and respond to real‑world threat activity. The advisory, A Tale of Two SOCs: Insights From Two Red Team Assessments, details red team activity at both organizations and the organizations’ differing defensive responses.
In one organization, the red team remained undetected by the security operations center (SOC) after gaining initial access to multiple workstations, elevating privileges over the domain, and moving laterally to other systems and resources. At the second organization, the red team’s initial access was detected and quarantined by the SOC. This forced the team to shift to an assumed breach model activity, and some of their follow-on activity was also detected and quarantined by the SOC.
CISA is sharing lessons learned from the two assessments that network defenders, systems administrators and other technical staff can use to assess their cybersecurity posture, identify areas to improve and apply appropriate recommended mitigations to their unique environment. The advisory highlights that security outcomes depend on more than tools, and organizations should establish baselines and improve monitoring as well as eliminate silos and bureaucratic hurdles for effective detection and response.
“This advisory demonstrates CISA’s commitment to empowering critical infrastructure organizations with the tools and insights they need to outpace sophisticated cyber threats. By sharpening their detection, response, and threat hunting capabilities, organizations can better defend their networks against evolving attacks. CISA encourages organizations to review this advisory, assess their cybersecurity posture and act on our recommended measures to enhance their security and resilience,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA’s Red Team is among the best in the world and is laser focused on helping our federal and critical infrastructure partners identify and mitigate their most significant vulnerabilities and weaknesses.”
This advisory was developed in coordination with the assessed organizations. At the conclusion of each assessment, CISA provided the organizations with a report of findings and recommendations to strengthen their cybersecurity posture and resilience to a potential incident.
CISA encourages organizations to review the advisory and implement mitigations that apply to their specific needs. For more information on how your organization can strengthen cybersecurity, please visit Cybersecurity Best Practices and Cyber Threats and Response.
###
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
