CISA

A Tale of Two SOCs: Insights From Two Red Team Assessments

From Cybersecurity and Infrastructure Security Agency ↗

Advisory at a Glance

Title

A Tale of Two SOCs: Insights From Two Red Team Assessments

Original Publication 

August 25, 2026

Executive Summary

The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.

This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and oper...