Clicky

mobile btn
Saturday, August 29th, 2026

CISA issues advisory helping organizations identify threats, enable effective response

© Shutterstock

A new advisory from the Cybersecurity and Infrastructure Security Agency outlines how organizations can strengthen detection, response and protections in information technology (IT), cloud and operational technology (OT) environments.

The advisory, A Tale of Two SOCs: Insights From Two Red Team Assessments, highlights lessons learned from red team assessments of the security operations center (SOC) performed at the request of two critical infrastructure organizations. During those assessments, CISA uses adversarial tradecraft to simulate malicious cyber operations to observe and evaluate the organization’s ability to detect, investigate and respond to real-world threat activity. The advisory details red team activity at both organizations and their differing defensive responses.

According to the advisory, the best defenses are to ensure robust baselines and alert filtering; while eliminating organizational silos and bureaucratic hurdles, and applying proper security controls and processes for cloud environments.

“This advisory demonstrates CISA’s commitment to empowering critical infrastructure organizations with the tools and insights they need to outpace sophisticated cyber threats. By sharpening their detection, response, and threat hunting capabilities, organizations can better defend their networks against evolving attacks. CISA encourages organizations to review this advisory, assess their cybersecurity posture and act on our recommended measures to enhance their security and resilience,” CISA Acting Executive Assistant Director for Cybersecurity Chris Butera said. “CISA’s Red Team is among the best in the world and is laser focused on helping our federal and critical infrastructure partners identify and mitigate their most significant vulnerabilities and weaknesses.”

CISA said in one organization, the red team remained undetected by the security operations center (SOC) after gaining initial access to multiple workstations, elevating privileges over the domain, and moving laterally to other systems and resources. At the second organization, the red team’s initial access was detected and quarantined by the SOC. This forced the team to shift to an assumed breach model activity, and some of their follow-on activity was also detected and quarantined by the SOC.

The lessons learned from these two assessments can help network defenders, systems administrators and other technical staff assess their cybersecurity posture, identify areas to improve and apply appropriate recommended mitigations to their environments.