< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 4 sources · 14 days · First seen · Last updated

Critical infrastructure cybersecurity security gaps

Overview

CISA released an advisory following red team engagements that identified significant security gaps within critical infrastructure. A report titled ‘A Tale of Two SOCs’ compared the responses of a Government Services and Facilities Sector entity against a Water and Wastewater Systems Sector entity.

In the first case, red team operators utilized phishing and Active Directory misconfigurations to gain elevated domain privileges and access sensitive cloud resources without detection. The second organization’s Security Operations Center (SOC) successfully isolated compromised workstations within 2 to 20 minutes of the initial attack, preventing the intrusion from spreading.

Industry analysis accompanying these findings suggests that security teams face a ‘data abundance problem.’ Experts indicate that the primary challenge is a lack of operational technology (OT) context, which makes it difficult for teams to distinguish between routine maintenance and malicious activity.

Entities

OMICRON Electronics · CISA

Timeline

  1. 19 days ago

    [TECHNOLOGY] 4 sources
    CISA red team exercises reveal critical infrastructure security gaps

    CISA red team exercises reveal varying levels of detection capabilities in critical infrastructure, while experts warn that a lack of operational technology context hinders effective threat response.

  2. about 1 month ago

    [TECHNOLOGY] 2 sources
    Cybersecurity methodologies: Red teaming vs penetration testing

    Penetration testing identifies technical vulnerabilities and aids compliance, while red teaming simulates targeted adversaries to test an organization's detection and response capabilities.

Sources

businesstechweekly.com · cybernoz.com · dev.to · securityaffairs.co