CISA Red Team Report: Water Utility Detected Simulated Attack in Minutes, Government Organisation Missed Domain-Wide Compromise
CISA published advisory AA26-237A detailing comparative defensive performance across two real-world red team assessments, contrasting high-discipline detection workflows at a municipal water utility with extensive detection failures at a federal government body.
Overview
| Attribute | Detail |
|---|---|
| Advisory | CISA Advisory AA26-237A |
| Participants | Organization A (Large Government Agency), Organization B (Water & Wastewater Utility) |
| Simulated Vectors | Multi-stage spearphishing, privilege escalation, lateral movement to OT DMZ |
| Outcome | Water utility contained breaches in under 20 minutes; Government agency missed full domain dominance |
| Date | 2026-08-25 |
Detailed Findings
Organization B: Disciplined Containment (Water Utility)
- Defenders processed initial spearphishing alerts with rapid triage, quarantining compromised endpoints in 2, 10, and 20 minutes respectively.
- When red team operators attempted pivot operations into the operational technology (OT) demilitarised zone via a jump host/bastion, defenders quickly isolated the target system and cut ingress paths before critical physical control systems could be surveyed.
Organization A: SOC Alert Fatigue (Government Entity)
- Red teamers gained an initial foothold via spearphishing and methodically escalated privileges until achieving domain-wide administrative control without detection.
- Security Operations Center (SOC) personnel received multiple EDR detection events but failed to initiate investigations because alerts were lost inside backlogs of thousands of unmanaged false positives.
Systematic Architecture Gaps (Both Organisations)
- Underestimated enterprise cloud exposure and misconfigured identity planes.
- Omission of Conditional Access policies applied to non-human workload identities.
- Lack of robust session token invalidation workflows following suspected endpoint breaches.
Significance & Recommendations
The assessment demonstrates that defensive efficacy relies far more on SOC alert triage discipline and rapid containment playbooks than on tooling budget. CISA urges organisations to aggressively tune SIEM/EDR rules, institute workload identity policies, and enforce automated token revocation mechanisms.
Australian Context
The failure modes identified in AA26-237A map directly to ACSC Essential Eight maturity priorities and SOCI Act critical infrastructure requirements. Australian SOC managers should utilise the report's metrics to assess alert fatigue levels and validate incident containment velocity across IT and OT environments.
Sources
- CISA โ Cybersecurity Advisory AA26-237A (Archived: web.archive.org save submitted 26 August 2026)