CISA red team: water utility foils attack, gov org fails

The latest red-team assessment from the Cybersecurity and Infrastructure Security Agency underscores a widening gap in detection and response between sectors, with a US water utility successfully spotting and containing a simulated intrusion while a government organization failed to detect or stop a comparable attack.[1]

CISA’s newly public report describes two unnamed critical-infrastructure entities that voluntarily invited red-team testing, anonymized as “Organization A” in the government sector and “Organization B” in the water sector.[1] In the government environment, the red team used an internal email account to launch a phishing campaign, gained access to multiple workstations, escalated privileges across the domain and moved laterally into sensitive business and cloud systems without triggering a meaningful defensive response.[1] CISA notes that endpoint detection and response tools did generate low- and medium-severity alerts, but the security operations center appeared overwhelmed by thousands of false positives and organizational silos that obscured the malicious activity.[1]

At the water organization, the red team again relied on spearphishing and convinced three users to click a malicious link that delivered access to their workstations.[1] This time, the security operations center quickly triaged the resulting alerts and quarantined the compromised machines within two, ten and twenty minutes, respectively, cutting off the initial foothold before the attackers could pivot.[1] Because defenders blocked the first wave, CISA shifted the engagement to an “assume breach” model in which trusted internal contacts provided the red team with the level of access they would have had if the attack had gone undetected, allowing testers to escalate privileges and reach cloud resources and a bastion host in the operational technology demilitarized zone.[1] Even under those conditions, the report says, network defenders at the utility identified the anomalous activity in the OT DMZ and again isolated the affected system.[1]

Despite the divergent outcomes, CISA stresses that both organizations share structural weaknesses, particularly around identity and cloud security.[1] The assessment finds that each environment underestimated cloud risks, lacked Microsoft Conditional Access controls for workload identities, and had no formal processes for revoking compromised access or refresh tokens once an account was suspected of being abused.[1] Those themes echo earlier CISA red-team advisories, which have repeatedly highlighted misconfigured identity layers and insufficient logging as root causes of undetected lateral movement in critical infrastructure networks.[2]

The timing of the report adds weight to CISA’s recent warnings about cyber threats to water and wastewater systems, including joint alerts with federal law enforcement about Iranian-affiliated actors targeting programmable logic controllers at US utilities.[8][12] In a late-July alert, the agency urged water-sector operators to harden their operational technology by segmenting IT and OT networks, restricting remote access pathways, enforcing multifactor authentication and promptly reporting suspicious activity to federal responders.[8][12] The new red-team findings suggest that even comparatively mature utilities can still miss cloud-focused attack paths if they treat identity and token management as an afterthought.[1][8]

For defenders across critical infrastructure, CISA’s case study reinforces several practical lessons: detection engineering and alert tuning are as important as deploying new tools; security teams must reduce noise and break down organizational silos so genuine threats are not buried under false positives; and identity controls such as Conditional Access and rigorous token revocation are now baseline requirements, not optional hardening steps.[1][2] The agency continues to promote sector-specific exercises and assessments, including offerings tailored to local governments and water utilities, and encourages organizations to adopt an “assume breach” mindset by validating incident response playbooks through regular red- and purple-team engagements.[2][11]

References

  1. Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
  2. Enhancing Cyber Resilience: Insights from CISA Red Team …
  3. CISA Urges Water and Wastewater Systems Sector to Protect OT …
  4. CISA Exercises
  5. Iranian-Affiliated Cyber Actors Exploit Programmable Logic …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply