
CISA’S red team successfully penetrated two critical infrastructure organisations during assessments carried out on 25 August 2026, with one target failing to notice any intrusion while the other managed to isolate the compromised systems according to The Hacker News. The operation was conducted without prior notice to the victims, mimicking the tactics of a determined adversary. Both organisations were chosen because they provide essential services that underpin national stability. The results have prompted immediate discussion among defenders about the adequacy of current monitoring.
The assessments are documented in CISA advisory AA26‑237a, which describes how the red team achieved full domain compromise by using legitimate credentials and exploiting misconfigured cloud services as detailed in the advisory. At the first organisation, detection tools produced an overwhelming volume of false alerts, causing genuine malicious activity to be overlooked. This alert fatigue allowed the attackers to move laterally, establish persistence and exfiltrate test data without triggering a timely response. The advisory notes that tuning thresholds and correlating events across logs could have reduced the noise and highlighted the intrusion.
In contrast, the second organisation benefited from tuned monitoring and a clear separation of duties between teams. Analysts there noticed unusual authentication patterns and isolated the affected segment within minutes of detection. The containment effort prevented further lateral movement and gave incident responders time to eradicate the foothold. The report attributes this difference to organisational silos and an underestimation of cloud risks that weakened the first firm’s defensive posture. These findings reinforce guidance from the Nice Framework for systems administration, which stresses the importance of role‑based access and continuous monitoring outlined here.
The exercise forms part of CISA’s routine red team programme designed to test the resilience of sectors that support critical national functions. No known threat actors were linked to the assessments, yet the outcomes echo earlier warnings about alert fatigue and fragmented response structures. Industry observers have pointed out that many organisations still rely on outdated signature‑based tools that generate excessive noise. Addressing these shortcomings requires both technical adjustments and cultural changes that promote shared responsibility for security.
Defenders should start by reviewing detection rules to lower the false positive rate, ensuring that genuine alerts are not buried in noise. Implementing behavioural analytics and integrating cloud workload protection with existing SIEM platforms can improve visibility across hybrid environments. Regular joint exercises that involve IT, security and business units help break down silos and improve communication during an incident. Updating playbooks to include specific cloud‑scenario steps ensures that responders know how to isolate compromised workloads quickly.
Adopting the Nice Framework role for systems administration offers a baseline for skill development, responsibility mapping and career progression. Organisations are encouraged to revisit their incident response plans after each red team engagement, incorporating lessons learned to improve future readiness. By combining technical tuning, staff training and clearer governance, critical infrastructure operators can raise the bar against increasingly sophisticated threats.