OFICIAL CISA News

CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response

What happened
Based on CISA News · Aug 25, 2026

CISA released an advisory detailing red team assessments at two critical infrastructure organizations, highlighting differences in detection and response capabilities to inform cybersecurity improvements across sectors.

CISA Advisory Highlights Red Team Findings to Help Organizations Assess Risk, Identify Threats and Enable Effective Incident Response
CISA News — CISA
Key points
·
During red team assessments, CISA uses adversarial tradecraft to simulate malicious cyber operations.
·
The objectives are to observe and evaluate an organization’s ability to detect, investigate and respond to real‑world threat activity.
·
The advisory, A Tale of Two SOCs: Insights From Two Red Team Assessments, details red team activity at both organizations and the organizations’ differing defensive responses.
·
In one organization, the red team remained undetected by the security operations center (SOC) after gaining initial access to multiple workstations, elevating privileges over the domain, and moving laterally to other systems and resources.

The Cybersecurity and Infrastructure Security Agency (CISA) published an advisory summarizing red team assessments conducted for two critical infrastructure organizations to evaluate their ability to detect and respond to cyber threats. Using adversarial techniques, CISA simulated real-world attack scenarios to test security operations center (SOC) effectiveness. The advisory contrasts two outcomes: one where the red team evaded detection entirely and another where the SOC identified and contained the intrusion, demonstrating the impact of monitoring and response practices.

The advisory, titled 'A Tale of Two SOCs: Insights From Two Red Team Assessments,' provides actionable insights for network defenders and administrators to assess their cybersecurity posture. CISA emphasizes that effective security depends on continuous monitoring, eliminating operational silos, and removing bureaucratic barriers to enable rapid detection and response. Organizations are encouraged to review the findings and apply recommended mitigations tailored to their environments.

CISA Acting Executive Assistant Director for Cybersecurity Chris Butera stated that the advisory reflects the agency’s commitment to equipping critical infrastructure with tools to counter sophisticated threats. He highlighted the role of detection, response, and threat hunting in strengthening cybersecurity resilience. The advisory was developed in collaboration with the assessed organizations, which received detailed reports of findings and recommendations to address vulnerabilities.

CISA urges organizations to review the advisory and implement applicable mitigations to enhance their security posture. The agency provides additional resources, including cybersecurity best practices and threat response guidance, to support organizations in reducing risk. As the national cyber defense agency, CISA leads efforts to secure digital and physical infrastructure critical to national resilience.

Original source → Deals on Clipraptor.com →