# Two Red Teams, Two Outcomes: Inside CISA Advisory

> CISA's latest advisory contrasts two critical infrastructure red team assessments: one SOC blind, one catching attackers at initial access.

**URL:** https://www.ciptadusa.com/blog/cisa-red-team-advisory-20260826  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-08-26  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-08/daily-appsec-20260826-014612.jpg  

## Article

Two critical infrastructure organizations. The same red team methodology from CISA. Two opposite outcomes. At the first organization, the simulated attackers roamed freely: they gained access to multiple workstations, escalated privileges across the domain, and moved laterally without ever tripping a SOC alert. At the second, their initial access was detected and quarantined — forcing the team into an assumed breach scenario, where some follow-on activity was caught as well.

## Summary
CISA has published an advisory distilling lessons from those two red team assessments: security outcomes are decided less by tooling than by the maturity of detection and response processes.

## Background
During red team assessments, CISA uses adversarial tradecraft to simulate real malicious cyber operations. The goal is not disruption but observation: evaluating how well an organization detects, investigates, and responds to threat activity across IT, cloud, and OT environments. The advisory was developed in coordination with both assessed organizations, each of which received a report of findings and recommendations at the conclusion of the assessment.

## The Challenge
The first organization is a study in stacked blind spots. The red team obtained initial access to multiple workstations, elevated privileges over the domain, and moved laterally to other systems and resources — none of it detected by the security operations center (SOC). Not a single stage of the attack chain triggered a detection.

The second organization showed the reverse. Early detection and quarantine forced the red team off its original plan and into activity that assumed the network was already compromised. Even parts of that follow-on activity were detected and quarantined.

The difference between the two was not budget for tools. It was baselines: the second organization knew what normal traffic and behavior looked like, so small deviations stood out immediately. The assumed breach model deserves attention here too — it was not a consolation prize for the red team, but evidence that layered defenses turn a penetration test into a far more realistic incident response exercise.

## Implications
CISA stresses that security outcomes depend on more than tools: organizations should establish baselines, improve monitoring, and eliminate silos and bureaucratic hurdles that slow detection and response. For teams running critical infrastructure SOCs in energy, water, or finance, the advice translates directly:

1. Measure detection time per stage of the attack chain, not only at the perimeter.
2. Test SOC assumptions regularly through purple team exercises.
3. Make sure quarantine decisions are not stuck behind layered approvals.

Chris Butera, Acting Executive Assistant Director for Cybersecurity at CISA, frames the mission plainly: the CISA Red Team is among the best in the world, laser focused on helping federal and critical infrastructure partners find their most significant vulnerabilities — before real adversaries do.

## References
- [CISA Advisory Highlights Red Team Findings](https://www.cisa.gov/news-events/news/cisa-advisory-highlights-red-team-findings-help-organizations-assess-risk-identify-threats-and) — CISA
- [NIST SP 800-115: Technical Guide to Information Security Testing and Assessment](https://csrc.nist.gov/publications/detail/sp/800-115/final)
- [MITRE ATT&CK](https://attack.mitre.org/)

---

*Markdown version of https://www.ciptadusa.com/blog/cisa-red-team-advisory-20260826 — generated for AI agents and LLM crawlers.*
