When Security Controls Aren’t Enough: Lessons From CISA’s Red Team

BLUF;

  • CISA’s red teams uncovered major gaps in detection, response, and network visibility across two critical infrastructure organizations
  • Strong security tools aren’t enough. Effective monitoring, communication and streamlined response processes are critical to stopping attacks
  • CISA recommends three priorities: strengthen monitoring and alerting, reduce internal silos, and tailor security controls to cloud and IT environments.

The Cybersecurity and Infrastructure Security Agency (CISA) issued new guidance drawn from two of its own red team engagements, offering organizations a roadmap for tightening detection and response capabilities across IT, cloud and operational technology networks.

“This advisory demonstrates CISA’s commitment to empowering critical infrastructure organizations with the tools and insights they need to outpace sophisticated cyber threats. By sharpening their detection, response, and threat hunting capabilities, organizations can better defend their networks against evolving attacks. CISA encourages organizations to review this advisory, assess their cybersecurity posture and act on our recommended measures to enhance their security and resilience,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera.

CISA’s Findings in Its Red Team Assessments – Security Controls

The advisory walks through how CISA’s red team operators, acting as simulated adversaries, tested the defenses of two critical infrastructure organizations that had requested the assessments.

The two assessments produced starkly different results. At the first organization, CISA’s team was able to breach several workstations, escalate its privileges across the domain and pivot to additional systems without ever being flagged by the security operations center. At the second organization, the SOC caught and isolated the initial intrusion attempt, pushing the red team to pivot to an assumed-breach approach. Even then, the SOC intercepted a portion of the follow-on activity.

What Are the Core Lessons Cited by the CISA From the Assessments?

CISA distilled three main lessons from the two engagements for network defenders, IT administrators and other technical personnel looking to gauge and improve their own security posture:

  • Build strong monitoring baselines and refine alert filtering
  • Break down internal silos and administrative friction that slow detection and response
  • Apply the right security controls and operational practices tailored to cloud environments

The agency emphasized that strong cybersecurity outcomes hinge on more than the tools an organization deploys. Effective processes, communication and organizational structure play just as large a role in whether a breach is caught early or missed entirely.

CISA worked directly with both assessed organizations in producing the advisory. Following each engagement, the agency delivered a detailed findings report to help the organization shore up its defenses and improve its readiness for a future incident.

Key questions this article answers

  • What did CISA’s red team assessments reveal about the cybersecurity defenses of critical infrastructure organizations?
  • What security gaps can leave critical infrastructure networks vulnerable to undetected attacks?
  • Why are monitoring, network visibility, and response processes especially important for critical infrastructure?
  • What three priorities does CISA recommend for strengthening critical infrastructure cybersecurity?

The original article was written by Jamie Bennett and can be found here.

For more information about best practices for your critical infrastructure, contact us today.

SecureStrux

SecureStrux

As a cybersecurity firm with deep roots in the Department of War (DoW) cybersecurity community, we provide specialized services in the areas of compliance, vulnerability management, cybersecurity strategies, and engineering solutions. Since 2013, we’ve partnered with hundreds of organizations within and outside the DoW to understand and proactively manage their risk. Our strength within the DoW has allowed us to easily translate best practices to our clients in other industries including Energy, Manufacturing, Architecture, Education, and Aerospace.

The latest in Cybersecurity

Enter your email to get the latest news, updates,
and content on cybersecurity.

"*" indicates required fields

How Did You Hear About SecureStrux?