Executive Summary
In 2024, CISA conducted red team exercises against two organizations - one government and one water sector entity - with dramatically different outcomes. Both organizations were successfully breached through phishing campaigns, but while the government organization failed to detect or respond to the simulated attack, allowing red teamers to gain elevated privileges and move laterally across systems undetected, the water sector organization quickly identified the intrusion and quarantined affected systems within 2-20 minutes. The exercise revealed critical gaps in detection capabilities, cloud security controls, and incident response procedures across both sectors.
This incident highlights the urgent need for improved cybersecurity defenses in critical infrastructure sectors, particularly as nation-state actors increasingly target water facilities and government systems. The stark contrast in detection and response capabilities demonstrates the growing maturity gap in cybersecurity readiness across different sectors.
Why This Matters Now
Critical infrastructure attacks are surging, with recent targeting of U.S. water facilities by foreign adversaries. This CISA exercise exposes dangerous security gaps in government systems while demonstrating that effective detection and rapid response are achievable with proper security operations.
Attack Path Analysis
CISA red team conducted simulated attacks on government and water organizations through spearphishing campaigns to gain initial access. In Organization A (government), attackers escalated privileges to domain-level access, moved laterally to sensitive business systems and cloud resources undetected, maintained persistent command channels, and demonstrated potential for data exfiltration and operational impact. Organization B (water) detected initial compromise quickly but red team still achieved privilege escalation and lateral movement to OT systems before being detected again.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Red team gained initial access through spearphishing campaigns - internal phishing emails at Organization A and malicious links clicked by three users at Organization B
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Phishing: Spearphishing Attachment
Valid Accounts
Exploitation for Privilege Escalation
Remote Services
Use Alternate Authentication Material: Application Access Token
Account Discovery
Email Collection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
CISA Zero Trust Maturity Model 2.0 – Privileged Identity Management
Control ID: Identity.IM-3
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.05
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
PCI DSS 4.0 – Multi-layered Network Security Controls
Control ID: 11.4.7
Digital Operational Resilience Act (DORA) – Identification and Classification of ICT Risk
Control ID: Article 8
ISO 27001:2022 – Reporting Information Security Events
Control ID: A.16.1.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
CISA red team exercise revealed critical detection failures, excessive false positives obscuring real threats, and inadequate lateral movement prevention in government networks.
Utilities
Water sector demonstrated effective threat detection and quarantine capabilities, but vulnerabilities in cloud security and operational technology DMZ require zero trust segmentation.
Computer/Network Security
Red team exercises expose gaps in east-west traffic monitoring, encrypted communication protection, and multicloud visibility requiring enhanced security fabric implementations.
Information Technology/IT
Phishing campaigns targeting workstations highlight need for egress security, anomaly detection, and Kubernetes security to prevent privilege escalation and lateral movement.
Sources
- Water sector passes, government sector fails attempts to spot and halt simulated CISA attackhttps://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/Verified
- CISA Red Team Exercise Report - Government and Water Sector Cybersecurity Assessmenthttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- CISA Cybersecurity Performance Goalshttps://www.cisa.gov/cross-sector-cybersecurity-performance-goalsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained the red team's ability to move laterally between business systems and cloud resources undetected. The segmented architecture would likely have reduced the blast radius from domain-level compromise to isolated workload boundaries.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native security fabric may have limited the initial foothold scope by constraining compromised workstation access to predefined network segments and reducing reachability to sensitive business applications
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation could have constrained privilege escalation by limiting domain-level access scope to specific application workloads rather than broad network resources, reducing the effective reach of elevated credentials
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have constrained lateral movement between business systems and cloud resources by enforcing segmentation boundaries that limit cross-workload communication pathways
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls may have limited persistent access by constraining communication channels between compromised cloud resources and reducing coordination capability across distributed attack infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained data exfiltration pathways by limiting outbound communication channels from sensitive business systems and reducing unauthorized data transfer capabilities
Remaining exposure would likely be limited to specific application workloads rather than enterprise-wide operational disruption, constraining the scope of potential infrastructure impact to isolated network segments
Impact at a Glance
Affected Business Functions
- Security Operations Center (SOC) Monitoring
- Network Infrastructure Management
- Email Communications Systems
- Cloud Resource Management
Estimated downtime: N/A
Estimated loss: N/A
Red team exercise accessed personnel emails at security operations center and gained access to sensitive business systems, cloud resources, and operational technology demilitarized zone. However, as this was a controlled exercise, no actual data compromise occurred.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust segmentation with least privilege policies to prevent lateral movement between workstations, cloud resources, and OT systems
- • Deploy egress security and policy enforcement to detect and block unauthorized outbound communications and data exfiltration attempts
- • Establish multicloud visibility and control capabilities to monitor anomalous interactions and suspicious automation across hybrid environments
- • Enhance threat detection and anomaly response systems with proper alert prioritization to reduce false positive noise that obscures real attacks
- • Implement Conditional Access controls for workload identities and establish processes for revoking compromised access tokens in cloud environments



