Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 4 sources · 14 days · First seen · Last updated
Critical infrastructure cybersecurity security gaps
Overview
CISA released an advisory following red team engagements that identified significant security gaps within critical infrastructure. A report titled ‘A Tale of Two SOCs’ compared the responses of a Government Services and Facilities Sector entity against a Water and Wastewater Systems Sector entity.
In the first case, red team operators utilized phishing and Active Directory misconfigurations to gain elevated domain privileges and access sensitive cloud resources without detection. The second organization’s Security Operations Center (SOC) successfully isolated compromised workstations within 2 to 20 minutes of the initial attack, preventing the intrusion from spreading.
Industry analysis accompanying these findings suggests that security teams face a ‘data abundance problem.’ Experts indicate that the primary challenge is a lack of operational technology (OT) context, which makes it difficult for teams to distinguish between routine maintenance and malicious activity.
Entities
Timeline
-
19 days ago
[TECHNOLOGY] 4 sourcesCISA red team exercises reveal critical infrastructure security gapsCISA red team exercises reveal varying levels of detection capabilities in critical infrastructure, while experts warn that a lack of operational technology context hinders effective threat response.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesCybersecurity methodologies: Red teaming vs penetration testingPenetration testing identifies technical vulnerabilities and aids compliance, while red teaming simulates targeted adversaries to test an organization's detection and response capabilities.
Sources
businesstechweekly.com · cybernoz.com · dev.to · securityaffairs.co