CISA Red Team Report: Water Sector Passes, Government Sector Fails
CISA's red team got initial access to both a water utility and a government organization using nearly identical tradecraft. The water sector isolated and shut it down in minutes. The government sector never detected it. Detection and isolation, not prevention, decided the outcome.
When CISA sent its red team against two critical-infrastructure organizations using nearly identical tradecraft, the water utility caught the intrusion and shut it down within minutes, while the government organization never noticed it at all. That contrast, the same attack run twice with opposite results, is the entire lesson of a rare public report the agency released this week.
The Cybersecurity and Infrastructure Security Agency (CISA) published the breakdown on Tuesday, August 25, 2026, in an advisory titled "A Tale of Two SOCs: Insights From Two Red Team Assessments" (AA26-237A). CyberScoop's Tim Starks first reported the findings: agency red-teamers got initial access to both organizations they tested, "but the water organization discovered the simulated attack and acted to defend itself, whereas the government organization did neither."
This piece does one thing the advisory itself leaves implicit: it pulls out the single defensive lesson that decided both outcomes. Both organizations were breached. What separated the pass from the fail was not a better firewall or a cleverer prevention control. It was detection and isolation, the part of security that only works if a human acts on an alert. We do not reconstruct how CISA got in, because that is not what defenders need from this report.
Same Attack, Two Outcomes
CISA ran two parallel red-team assessments, a process it describes as voluntary and by request, and did not name either target. One was a government-sector organization the advisory calls Organization A. The other was a water-sector organization it calls Organization B. In both, the red team gained initial access through phishing, the oldest doorway in the book.
From there the two stories diverge completely. "In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to [sensitive business systems] and cloud resources undetected," CISA's analysis reads, per CyberScoop. "In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems." Same playbook, two security operations centers, and only one of them was watching.
What the Water Sector Got Right
At the water organization, CISA got in by convincing three users to click a malicious link. Then the defense worked exactly as it is supposed to. The security operations center triaged the alerts and quarantined the three affected workstations in 2, 10, and 20 minutes respectively, which severed the red team's command-and-control connection to those machines. The intrusion was over almost as soon as it began.
It did not stop there. Because the water sector detected the initial compromise, CISA switched to an "assume breach" model, in which the organization's own trusted agents handed the red team a foothold equivalent to what it would have had if defenders had missed the first move. Even then, when the operators escalated and reached a bastion host in the operational-technology (OT) demilitarized zone, "defenders again detected activity and isolated the system," CISA wrote. Twice given a chance to catch the attackers, the water SOC caught them twice.
The lesson is not that the water utility had exotic tooling. It is that alerts reached people who investigated them and had the authority to pull a machine off the network in minutes. That is a workflow, not a product.
|
● What the Water Sector SOC Did Right
The detection-and-isolation moves that shut an intrusion down in minutes.
|
|
1. Triaged the Alert, Fast
SOC analysts investigated the endpoint alerts instead of letting them sit in a queue. Someone owned the alarm.
|
|
2. Isolated the Hosts in Minutes
Quarantined the three affected workstations in 2, 10, and 20 minutes, cutting the red team’s command-and-control.
|
|
3. Kept Watching After First Contact
When the operators pivoted toward the OT demilitarized zone, defenders detected the activity again and isolated the system.
|
|
● The Government SOC’s Failure Mode
Same initial access, but the alerts went unactioned and thousands of false positives buried the real ones. Detection tooling without a response is not a defense.
|
|
Source: CISA advisory AA26-237A, "A Tale of Two SOCs" (August 2026). Defender view only; no exploitation detail shown.
|
How the water-sector security operations center detected and contained an intrusion the government sector never saw, drawn from CISA advisory AA26-237A. Defensive actions only. Illustration: The CyberSignal.
How the Government Sector Missed It
The government organization had the same tooling firing and simply did not act on it. CISA used an internal email address to phish its way onto workstations, escalated privileges, and moved to targeted sensitive business systems and cloud resources, all undetected. The red team then did something that reads like a stress dream for any SOC manager: it read personnel emails inside the organization's own security operations center and watched analysts receive low- and medium-severity endpoint detection and response alerts triggered by the intrusion, and do nothing with them.
Why nothing? Two reasons CISA names, both organizational rather than technical. First, false positives by the thousands, some at higher severities, "obscured the alerts triggered by red team activity," the agency said, per CyberScoop. When every day brings a flood of noise, the one real alarm looks like all the others. Second, CISA faulted "organizational silos," the gaps between teams where an alert becomes someone else's problem and therefore no one's.
This matters because it undercuts the easy read. Both organizations, CISA noted, actually shared the same underlying weaknesses: they underestimated cloud risk, lacked Microsoft Conditional Access for workload identities, and had no process to revoke compromised access or refresh tokens. The government sector did not fail because it was worse equipped. It failed because detection without response is just expensive logging.
What CISA Did Not Say
A few things are worth flagging as not established, so no one over-reads the report. CISA did not name the water utility or the government organization, and said so deliberately: the assessments are voluntary and by request, and anonymity is part of the deal. Anyone claiming to know which specific utility or agency was tested is guessing. We also deliberately leave out the operational detail of how the red team escalated once inside, because that is attacker tradecraft, not defender guidance, and the useful part of this story lives entirely on the detection-and-response side.
This is also not a one-off data point floating free of context. It lands in the middle of a bruising stretch for the water sector, from a multi-agency warning about AI-assisted attacks on internet-exposed Siemens S7 PLCs to a suspected Iran-linked intrusion that knocked a UK power plant offline for four days. Against that backdrop, a water utility that catches and contains a live intrusion in minutes is not a footnote. It is proof the discipline works.
My read: this is the clearest public evidence I have seen that detection and isolation, not prevention, is what actually decides a breach. Both organizations got popped. Prevention failed in both. The only variable that changed the outcome was whether someone in the SOC saw the alert and had the authority to pull the plug, and the water sector did that three times faster than most tabletop exercises assume is possible. If your security program is graded mostly on how well it keeps attackers out, this report is an argument to re-weight it toward how fast you notice and how fast you contain. That is an assessment, not a fact CISA stated, but the two-SOC comparison points hard in that direction.
What Both Sectors Should Do Now
None of the following requires knowing how CISA got in. Each maps directly to what separated Organization B from Organization A, and to the pillar principle that containment speed defines breach impact.
- Exercise your isolation and containment playbook. The water SOC pulled hosts off the network in 2, 10, and 20 minutes because it had rehearsed doing so. Time your own host-quarantine process, and make sure an analyst has the standing authority to isolate a machine without waiting for a change-approval meeting.
- Invest in detection and response, not just prevention. Both organizations shared the same preventive gaps. Alerts that no one triages are the government sector's failure mode. Fund the people and the workflow that turn an alert into an action.
- Run tabletop and red-team exercises. This entire lesson exists only because both organizations invited an assessment. A red-team or purple-team engagement is the cheapest way to find out whether your SOC is Organization A or Organization B before a real adversary does.
- Enforce IT and OT segmentation. The water sector's second catch came at the boundary of its operational-technology zone. Segment OT from IT so that reaching a control-system host requires crossing a monitored boundary, which is exactly where a second detection opportunity lives.
- Tune out the noise. Thousands of false positives buried the real alerts in the government SOC. Alert tuning is not housekeeping, it is the difference between a signal that gets acted on and one that drowns.
The uncomfortable takeaway for critical-infrastructure operators is that the smaller, less-resourced water sector outperformed a government organization on the single metric that mattered. Budget did not save Organization A. A functioning detect-and-isolate loop saved Organization B. That loop is buildable, and this report is the receipt.