Tag: Security Operations Centers

  • CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    CISA Red-Team Assessments Show Why One SOC Detected an Intrusion and Another Did Not

    The US Cybersecurity and Infrastructure Security Agency published A Tale of Two SOCs: Insights From Two Red Team Assessments on August 25, 2026. The advisory compares assessments conducted at two critical-infrastructure organizations and shows how similar adversary techniques produced very different defensive outcomes.

    Two assessments, two outcomes

    At the first organization, CISA’s red team gained access to multiple workstations, elevated privileges across the domain and moved laterally without being detected by the security operations center. The assessment identified gaps in monitoring, cloud visibility, identity protection and communication between separate security teams.

    At the second organization, the SOC detected and quarantined the red team’s initial access. That response forced the assessors to move to an assumed-breach scenario. Defenders also detected and contained portions of the follow-on activity, limiting the red team’s freedom of movement.

    What made the difference

    CISA’s comparison emphasizes operational fundamentals rather than a single security product. Tuned alerts, established network and identity baselines, documented escalation procedures, communication between SOC teams and system owners, and visibility across IT, cloud and operational-technology environments all affected the result.

    The advisory also highlights the risk created by fragmented tooling. Multiple SOCs or endpoint-detection platforms do not automatically improve security when teams cannot see one another’s alerts or coordinate investigations. Cloud identity and application controls require the same operational ownership as traditional endpoint and network monitoring.

    Why it matters for critical infrastructure

    Critical-infrastructure operators increasingly manage connected IT, cloud and OT environments. An attacker who begins on a workstation may use identity systems, remote administration paths or cloud services to move toward operationally important resources. Detection quality therefore depends on whether defenders can correlate events across those boundaries before activity becomes a domain-wide compromise.

    Red-team assessments do not predict every real intrusion, but they provide controlled evidence of how existing people, procedures and technology perform against realistic adversary behavior. CISA’s findings support a practical priority: organizations should test whether their SOC can detect and coordinate a response across the complete environment, rather than assuming that deployed tools are functioning as an integrated defense.

    Sources

    Follow additional developments on Technology News.