Executive Summary

In August 2026, CISA published results from simultaneous red team assessments against two critical infrastructure organizations in the Government Services and Water/Wastewater sectors. Both organizations were fully compromised at the domain level using similar attack techniques including web application exploitation with default credentials, Active Directory Certificate Services misconfigurations, and privilege escalation through cleartext stored credentials. Organization A detected nothing despite thousands of security alerts, while Organization B's SOC detected and isolated affected workstations within 2-20 minutes, demonstrating the critical importance of security operations maturity over tool sophistication.

This assessment highlights the growing focus on defensive capabilities amid increasing nation-state threats against critical infrastructure, particularly following recent campaigns like Salt Typhoon that exposed fundamental gaps in network security and detection capabilities across sectors.

Why This Matters Now

Critical infrastructure remains highly vulnerable to basic attack techniques, with detection capabilities varying dramatically between organizations despite similar security tooling, emphasizing urgent need for SOC maturity improvements.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Both organizations had default Machine Account Quota settings, misconfigured AD CS certificate templates (ESC1), cleartext stored credentials for service accounts, and static cloud access keys with no expiration.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this multi-stage attack by limiting lateral movement between network segments and reducing the blast radius of the domain compromise across cloud and on-premises environments.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Workstation compromise scope would likely have been reduced through microsegmentation policies that limit initial foothold expansion and contain compromised endpoints within isolated network segments.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Domain controller access and DCSync attack reach would likely have been constrained through segmentation policies that limit privileged account movements and restrict certificate authority communications to authorized endpoints only.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Access to sensitive business systems and OT bastion hosts would likely have been significantly restricted through east-west traffic inspection and policy enforcement between network segments and operational technology environments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control channel establishment would likely have been detected faster and contained more effectively through enhanced visibility into cross-cloud communications and automated response capabilities across hybrid infrastructure environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration scope would likely have been reduced through controlled egress policies that limit cloud resource access patterns and restrict the volume and destinations of sensitive data transfers.

Impact (Mitigations)

While domain compromise occurred, the overall business impact would likely have been contained to isolated network segments, reducing the potential for widespread operational technology disruption and limiting exposure of critical business systems.

Impact at a Glance

Affected Business Functions

  • Security Operations Center (SOC) Management
  • Critical Infrastructure Monitoring
  • Incident Response and Detection
  • Network Security Operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

This was a controlled red team assessment where CISA gained access to sensitive business systems, cloud resources, and security team emails. Organization A had complete compromise with no detection, while Organization B successfully detected and contained the initial attack vectors. The exercise exposed significant security gaps including cleartext credentials, misconfigured certificate services, and inadequate SOC procedures.

Recommended Actions

  • Implement Zero Trust segmentation with least privilege policies to prevent lateral movement between workstations and sensitive business systems
  • Deploy egress security controls with FQDN filtering to block unauthorized C2 communications and data exfiltration attempts
  • Enable east-west traffic inspection and anomaly detection to identify suspicious inter-system communications and credential abuse
  • Establish multicloud visibility and centralized policy enforcement to monitor AWS access key usage and Entra ID application permissions
  • Deploy threat detection capabilities with proper SOC procedures, shared visibility between security tools, and clear escalation authority to ensure rapid incident response

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image