Executive Summary

In 2024, CISA conducted red team exercises against two organizations - one government and one water sector entity - with dramatically different outcomes. Both organizations were successfully breached through phishing campaigns, but while the government organization failed to detect or respond to the simulated attack, allowing red teamers to gain elevated privileges and move laterally across systems undetected, the water sector organization quickly identified the intrusion and quarantined affected systems within 2-20 minutes. The exercise revealed critical gaps in detection capabilities, cloud security controls, and incident response procedures across both sectors.

This incident highlights the urgent need for improved cybersecurity defenses in critical infrastructure sectors, particularly as nation-state actors increasingly target water facilities and government systems. The stark contrast in detection and response capabilities demonstrates the growing maturity gap in cybersecurity readiness across different sectors.

Why This Matters Now

Critical infrastructure attacks are surging, with recent targeting of U.S. water facilities by foreign adversaries. This CISA exercise exposes dangerous security gaps in government systems while demonstrating that effective detection and rapid response are achievable with proper security operations.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The water organization detected the initial compromise and quarantined systems within 2-20 minutes, while the government organization failed to detect or respond to the attack despite receiving security alerts.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained the red team's ability to move laterally between business systems and cloud resources undetected. The segmented architecture would likely have reduced the blast radius from domain-level compromise to isolated workload boundaries.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native security fabric may have limited the initial foothold scope by constraining compromised workstation access to predefined network segments and reducing reachability to sensitive business applications

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation could have constrained privilege escalation by limiting domain-level access scope to specific application workloads rather than broad network resources, reducing the effective reach of elevated credentials

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have constrained lateral movement between business systems and cloud resources by enforcing segmentation boundaries that limit cross-workload communication pathways

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls may have limited persistent access by constraining communication channels between compromised cloud resources and reducing coordination capability across distributed attack infrastructure

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely have constrained data exfiltration pathways by limiting outbound communication channels from sensitive business systems and reducing unauthorized data transfer capabilities

Impact (Mitigations)

Remaining exposure would likely be limited to specific application workloads rather than enterprise-wide operational disruption, constraining the scope of potential infrastructure impact to isolated network segments

Impact at a Glance

Affected Business Functions

  • Security Operations Center (SOC) Monitoring
  • Network Infrastructure Management
  • Email Communications Systems
  • Cloud Resource Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Red team exercise accessed personnel emails at security operations center and gained access to sensitive business systems, cloud resources, and operational technology demilitarized zone. However, as this was a controlled exercise, no actual data compromise occurred.

Recommended Actions

  • Implement Zero Trust segmentation with least privilege policies to prevent lateral movement between workstations, cloud resources, and OT systems
  • Deploy egress security and policy enforcement to detect and block unauthorized outbound communications and data exfiltration attempts
  • Establish multicloud visibility and control capabilities to monitor anomalous interactions and suspicious automation across hybrid environments
  • Enhance threat detection and anomaly response systems with proper alert prioritization to reduce false positive noise that obscures real attacks
  • Implement Conditional Access controls for workload identities and establish processes for revoking compromised access tokens in cloud environments

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image