CISA Just Ran the Same Attack on Two Organizations. One Caught It in 20 Minutes. The Other Never Knew.
CISA's red team fully compromised two critical infrastructure organizations using identical techniques. The difference in outcome wasn't the sophistication of the attack — it was detection speed. Here's what every business leader needs to understand.
Last week, CISA published one of the most instructive cybersecurity documents I've seen in years. They called it "A Tale of Two SOCs."
Here's the setup: CISA's red team ran simultaneous cyberattack simulations against two critical infrastructure organizations using nearly identical techniques. Same type of phishing. Same lateral movement playbook. Same credential theft methods. Same goal — full domain compromise.
Both organizations got fully compromised. CISA's team accessed sensitive business systems and cloud resources in both environments.
But there was a critical difference in how those stories ended.
Organization B detected the initial intrusion. Their security team isolated the affected systems within 2 to 20 minutes. The red team was stopped in its tracks at the front door.
Organization A? They never knew it happened. Not during the attack. Not while the red team escalated privileges across their entire domain. Not while CISA's team accessed sensitive cloud resources. Organization A found out when CISA told them — after the fact.
Same attack. Completely different outcome. The variable wasn't the sophistication of the attacker. It was detection.
What Actually Went Wrong — At Both Organizations
Here's what makes this report so valuable: CISA found the same underlying vulnerabilities in both organizations. Default credentials left on a web application. Misconfigured Active Directory certificate templates that let any low-privileged user escalate to admin. Passwords stored in cleartext inside configuration files. Static cloud access keys that never expired.
These aren't exotic zero-day exploits. They're the same misconfigurations that show up in penetration tests we run for clients every month.
At Organization A, the red team used a default-credential web application to send internal phishing emails — trusted by everyone on the network because they came from an internal address. Four workstations compromised. Privileges escalated using a misconfigured certificate template. Sensitive business systems reached using credentials stored in a decrypted database file. Then a pivot into cloud resources, where they used an over-permissioned application to read the security team's own email — checking whether anyone had noticed.
No one had.
CISA identified part of the reason: Organization A was drowning in alerts. Thousands of false positives from normal business operations, many rated at higher severity than what the red team was generating. Multiple security operations centers running with no shared visibility between them. The signal was there. The noise buried it.
At Organization B, the security team caught the initial phishing execution. Isolated the affected workstations. Forced the red team into what's called an "assume breach" model — meaning CISA had to simulate what would have happened if they'd gotten through, rather than actually getting through.
Even in that model, the team found the same underlying problems. Cleartext service account credentials in an SCCM configuration file. Those credentials had domain controller rights. The team ran a DCSync attack — essentially stealing every password hash in the organization — and still found a bastion host near the operational technology environment. But there too, defenders detected the activity and isolated the system.
Organization B had problems. But their detection capability turned a potential catastrophe into a contained incident.
The Question Every Business Leader Should Be Asking
I want you to sit with this for a moment: two organizations, same vulnerabilities, same attacker tradecraft. One walked away with a lesson. The other walked away having been fully owned — with their domain, their cloud, and their sensitive business systems all in the hands of an adversary — and they didn't know it until they were told.
Now ask yourself: which organization are you?
Most business leaders I talk to believe their answer is "Organization B." Most of them haven't tested whether that's actually true.
The gap CISA documented isn't primarily a technical gap. It's an operational one. It's the difference between having security tools and actually having detection capability.
Here are the three questions that matter:
1. Can you detect an attacker at the moment of initial access — not days later?
Organization B detected phishing payload execution in real time. Their endpoint telemetry was connected, monitored, and generating actionable alerts. Organization A had tools too — they just weren't generating usable signal. Alert fatigue is a detection failure, not a technology limitation. If your security team spends more time suppressing noise than hunting threats, you have an Organization A problem.
2. Do you know what credentials are stored in cleartext anywhere in your environment?
CISA found cleartext passwords in database configuration files and SCCM configuration files in both organizations. These aren't obscure hiding spots — they're exactly where attackers look first. A credential audit isn't glamorous work. But it's the kind of work that determines whether a compromised endpoint becomes a contained incident or a full domain compromise.
3. What happens when an attacker gets your credentials?
Both organizations had the same cloud security gap: no Conditional Access policies for workload identities, and over-permissioned applications that could read all user email. An attacker with stolen credentials and cloud access can move faster than most organizations can respond. Do you have the controls to limit what a stolen credential can do — and the monitoring to detect when it's being abused?
The Lesson CISA Is Trying to Teach
CISA's advisory is blunt about the takeaway: prevention controls will eventually fail. Misconfigurations exist. Phishing works. Credentials get stolen. The question isn't whether an attacker can find a foothold — they often can. The question is how quickly you find them once they do.
Organization B's detection posture didn't prevent a determined adversary from finding vulnerabilities. It prevented those vulnerabilities from becoming a full compromise. That's a meaningful distinction.
This is what we mean when we talk about building security programs around detection and response, not just prevention. Prevention buys you time. Detection determines the outcome.
If you're reading this and realizing you're not sure which organization you'd be — that's a conversation worth having. TrustPoint Cyber helps organizations build the detection capability to know the answer before an adversary tests it for you.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.