< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

CISA red team exercises reveal critical infrastructure security gaps

CISA has released an advisory following red team engagements that highlight significant security gaps in critical infrastructure. The report, titled ‘A Tale of Two SOCs’, compared two different organizations: a Government Services and Facilities Sector entity and a Water and Wastewater Systems Sector entity.

In one instance, red team operators used phishing and Active Directory misconfigurations to gain elevated domain privileges and access sensitive cloud resources without being detected. In contrast, the second organization’s Security Operations Center (SOC) successfully isolated compromised workstations within 2 to 20 minutes of the initial attack, preventing the intrusion from spreading.

Complementing these findings, industry analysis suggests that critical infrastructure security teams face a ‘data abundance problem.’ Experts argue that the primary challenge is not a lack of threat intelligence, but a lack of operational technology (OT) context. Without understanding how specific threats interact with unique hardware, firmware, and physical processes, security teams struggle to distinguish between routine maintenance and malicious activity.

Entities

CISA · OMICRON Electronics