The Cybersecurity and Infrastructure Security Agency on August 25, 2026, published an advisory detailing red team assessments requested by two critical infrastructure organizations and their sharply different defensive responses. At one organization, the simulated attackers remained undetected after compromising multiple workstations, escalating domain privileges and moving laterally, while the other organization detected and quarantined the initial access and some follow-on activity.

During the assessments, CISA used adversarial tradecraft to simulate malicious cyber operations and evaluate each organization’s ability to detect, investigate and respond to real-world threat activity. The resulting advisory, “A Tale of Two SOCs: Insights From Two Red Team Assessments,” describes the red team’s activity and how the organizations’ security operations centers responded.

At the first organization, the security operations center did not detect the red team after it gained initial access to several workstations, elevated privileges across the domain and reached other systems and resources. At the second organization, detection and quarantine of the initial access forced CISA’s team to shift to an assumed-breach model; the security operations center also detected and quarantined some subsequent activity.

CISA said the assessments show that security outcomes depend on more than defensive tools. Its principal recommendations include establishing robust baselines and improving alert filtering and monitoring, removing organizational silos and bureaucratic barriers that can impede detection and response, and applying appropriate security controls and processes in cloud environments. The agency said network defenders, systems administrators and other technical personnel can use the findings to assess their cybersecurity posture and select mitigations suited to their environments.

The advisory was developed in coordination with the two assessed organizations. After each assessment, CISA provided the relevant organization with findings and recommendations intended to strengthen its cybersecurity posture and resilience to a potential incident. CISA encouraged organizations to review the advisory and implement measures applicable to their specific needs across information technology, cloud and operational technology environments.