Validated Containment Architectures are here. →Explore

Executive Summary

CISA conducted simultaneous red team assessments at two organizations in August 2026, revealing stark differences in defensive capabilities. Both organizations suffered full domain compromise and sensitive business system access, but Organization A failed to detect any malicious activity while Organization B rapidly identified and contained threats within 2-20 minutes. The assessments exposed critical gaps in cloud security, Active Directory configurations, and incident response processes across both critical infrastructure entities.

This incident highlights the growing sophistication of identity-based attacks and the urgent need for organizations to mature their cloud security postures as threat actors increasingly target hybrid environments and exploit authentication mechanisms like Entra ID and AWS IAM.

Why This Matters Now

With ransomware groups like Salt Typhoon and Medusa increasingly targeting cloud identities and hybrid environments, organizations must urgently address detection gaps and cloud security misconfigurations before attackers exploit these same techniques in real-world scenarios.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Organization A failed to detect any red team activity due to overwhelming false positive alerts and organizational silos, while Organization B rapidly detected and contained threats within 2-20 minutes through well-tuned detection systems and empowered defenders.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF would have significantly reduced the blast radius of this multi-stage red team operation by implementing microsegmentation and controlling east-west traffic flows. The segmented architecture would likely have constrained lateral movement between compromised systems and limited the scope of privilege escalation across both organizations.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial workstation compromises would likely have been contained within isolated network segments, reducing the attacker's ability to enumerate and access additional systems across the infrastructure

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have constrained the scope of privilege escalation by limiting service account access to specific network segments and reducing the reach of compromised credentials

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have blocked or restricted unauthorized communication paths between SCCM servers, virtual desktops, and workstations, significantly limiting the attacker's lateral movement capabilities

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected and constrained unauthorized cloud application access patterns and suspicious SSO authentication flows across hybrid environments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely have detected and blocked large-scale data transfers from email systems and database servers, reducing the volume of sensitive information successfully exfiltrated

Impact (Mitigations)

The overall organizational impact would likely have been significantly reduced, with attackers constrained to specific network segments rather than achieving full domain compromise and OT environment access

Impact at a Glance

Affected Business Functions

  • IT Security Operations
  • Critical Infrastructure Operations
  • Sensitive Business Systems
  • Cloud-based Services
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Red team demonstrated ability to access sensitive business systems including databases, automated processing systems, email communications of security operations center staff, Microsoft Teams messages, and cloud resources. In Organization B, access to operational technology network visibility was achieved through bastion hosts.

Recommended Actions

  • Implement Zero Trust Segmentation with least privilege policies to prevent lateral movement between workstations and critical systems like SCCM
  • Deploy Egress Security & Policy Enforcement to block unauthorized outbound traffic and detect data exfiltration attempts to external destinations
  • Enable Multicloud Visibility & Control with centralized policy management to detect anomalous cloud application activities and excessive permission usage
  • Establish East-West Traffic Security monitoring to identify and block lateral movement patterns between internal network segments
  • Implement Encrypted Traffic (HPE) controls for data in transit protection and deploy Threat Detection & Anomaly Response capabilities for real-time monitoring of credential abuse and privilege escalation attempts

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image