Skip to content
← All articles
Top Attack·August 31, 2026·Cybersecurity PSA

A Tale of Two SOCs: Insights From Two Red Team Assessments

Voice options

Voice names come from your browser and device.

CISA Cybersecurity Advisories & Alerts ↗
TL;DR
The fast version

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive…

Detailed briefing
Create a high-quality editorial cybersecurity illustration in a dramatic split-screen composition showing “a tale of two security operations centers.” On the left, a dim, chaotic SOC overwhelmed by dense alert streams, red warning lights, unattended dashboards, and a subtle shadowy intrusion spreading from enterprise servers toward cloud systems and operational technology; analysts appear distracted by false positives and unable to contain the breach. On the right, a calm, well-organized SOC with focused defenders rapidly isolating compromised endpoints, segmented network zones, secured cloud infrastructure, and protected industrial control systems, while a contained red intrusion is stopped at the perimeter. Visually contrast disorder and delayed detection with disciplined monitoring, incident response, network segmentation, multifactor authentication, and resilience. Realistic cinematic lighting, sophisticated blue-and-red color palette, modern critical-infrastructure setting, subtle sense of urgency, professional magazine feature aesthetic, no readable text, no logos, no branding, no gore.

What happened

Advisory at a Glance Title A Tale of Two SOCs: Insights From Two Red Team Assessments Original Publication August 25, 2026 Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations…

In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources.

What is verified

Organization A failed to detect or contain the activity, but Organization B rapidly identified initial compromise attempts, isolated affected systems, and forced the red team into an assume breach model.

This advisory details the red team’s activity and organizations’ defensive actions, offering lessons learned and mitigations to help critical infrastructure organizations strengthen detection, response, and protections in IT, cloud, and operational technology (OT) environments.

Without well-defined baselines and alert filtering, false positives and routine alerts overwhelm network defenders.

Why it matters

A confirmed cyber incident can create secondary risk long after the initial intrusion. Stolen account data, contact information, or business records may be reused for phishing, credential attacks, identity fraud, or targeted social engineering. The source-backed facts above describe the incident; the downstream risk depends on what information was actually exposed.

What you should do

If you are notified that your information or account was affected, follow the organization’s incident instructions first. Change reused passwords, enable multifactor authentication, watch for targeted phishing, review security alerts and account sessions, and monitor financial or identity activity when sensitive personal information may have been involved.