Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-26 ยท updated: 2026-08-26 ยท tags: [incident, gov-agency, defense, technique, sector-government, sector-energy] ยท confidence: high ยท severity: high ยท affected_sectors: [government, energy] ยท au_impact: true

AA26-237A โ€” CISA Red Team Assessment Advisory

CISA Cybersecurity Advisory AA26-237A details the findings of two voluntary red team engagements comparing defensive responses between a water utility and a government organisation under simulated spearphishing attacks.

Overview

Attribute Detail
Advisory ID AA26-237A
Publishing Agency Cybersecurity and Infrastructure Security Agency (CISA)
Date 2026-08-25
Entities Assessed Organization A (Government Organisation), Organization B (Water Utility)
Key Findings Water utility contained attacks in minutes; Government organisation missed domain dominance due to alert fatigue

Engagement Analysis

Organization B (Water Utility)

  • Defenders detected and triaged initial spearphishing activity rapidly, quarantining compromised workstations within 2, 10, and 20 minutes.
  • When red team operators attempted lateral movement into the OT DMZ via a bastion host, defenders successfully isolated the path before critical operational technology systems could be impacted.

Organization A (Government Organisation)

  • Red teamers achieved initial foothold through spearphishing and escalated privileges to complete domain dominance and access sensitive business systems undetected.
  • SOC analysts observed EDR telemetry but failed to respond because critical alerts were buried among thousands of unmanaged false positives.

Common Deficiencies

  • Underestimated cloud attack surface and exposure.
  • Absence of Conditional Access policies for workload identities and service principals.
  • Inadequate or missing session token revocation procedures.

Significance & Defensive Recommendations

  1. Combat Alert Fatigue: Implement rigorous alert tuning and triage discipline to ensure high-fidelity EDR detections are promptly investigated.
  2. Workload Identity Protection: Apply Conditional Access, strict scopes, and MFA/device trust to service accounts and cloud workloads.
  3. Token Management: Establish automated token revocation procedures upon suspected credential or endpoint compromise.

Australian Context

The operational breakdown in AA26-237A strongly reinforces the detection engineering requirements under the ACSC Essential Eight and Australian SOCI Act obligations, particularly the risk of unmanaged SOC alert volume obscuring critical adversary movement.

Sources