www.cisa.gov 8/25/2026, 3:49:26 PM · external

CISA Report Shows How Two Red Team Exams Reveal Critical SOC Gaps

CyberSIXT Evidence Panel Source marked as original reporting
Primary Source niccs.cisa.gov

THE CISA cybersecurity advisory titled "A Tale of Two SOCs: Insights From Two Red Team Assessments" (August 25, 2026) outlines lessons learned from simultaneous red team assessments of two organizations, highlighting diverse defensive outcomes. Key points include:

1. **Assessment Overview**: Both organizations faced full domain compromises, but responses differed significantly. Organisation A failed to detect initial breaches while Organization B successfully isolated affected systems.

2. **Lessons Learned**:

3. **Key Actions Recommended**:

4. **Intended Audience**: Aimed at federal agencies, state and local governments, and critical infrastructure systems defenders, including system and vulnerability analysts, incident responders, and security managers.

5. **Mitigations and Best Practices**: Recommendations include enhancing cloud security, improving Active Directory configurations, and regularly auditing security practices to minimize risks.

These insights serve to strengthen the cybersecurity posture of critical infrastructure organizations.

View full article

Article by CyberSIXT