Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
When the Cybersecurity and Infrastructure Security Agency tested defenses for two targets โ one in the government sector and the other in the water sector โ red teamers were able to get into both of their systems, but the water organization discovered the simulated attack and acted to defend itself, whereas the government organization did neither.
CISA published the breakdown Tuesday in a rare public report on its red-team activities, at a time when attacks on the water sector have a higher profile after revelations of targeting of water facilities across the United States over the past month and numerous government warnings.
The agency didnโt name the organizations it tested through a process that is voluntary and by-request.
โIn one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to [sensitive business systems] and cloud resources undetected,โ CISAโs analysis reads. โIn the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.โ
For โOrganization A,โ the government organization, CISA used an internal email address to send phishing emails to gain access to the workstations, probed further to gain elevated privileges, then moved around and compromised targeted sensitive business systems. The red teamers observed that the organization โdid not respond effectively to red team activityโ by accessing personnel emails at its security operations center, where they saw them receive low- and medium-severity endpoint detection and response alerts, but didnโt respond to them.
False positives by the thousands, including some with higher severity, โobscured the alerts triggered by red team activity,โ CISA said. The agency also faulted โorganizational silos.โ
Meanwhile, at โOrganization B,โ the water organization, CISA got access via a spearphishing campaign, convincing three users to click on a malicious link to gain access to workstations. This time, the security operations center triaged the alerts and quarantined the work stations in 2, 10 and 20 minutes, respectively.
The red teamers tried another approach with the help of the organizationโs IT contacts who were aware of the activity, but were foiled in their follow-ups.
โBecause Organization B detected the initial compromise, the red team moved to an โassume breachโ model, where Organization B trusted agents (TAs) provided access to a host that replicated the level of access the red team would have had if defenders had not detected their activity,โ CISA wrote. โFrom there, the red team escalated privileges and moved laterally to [sensitive business systems], cloud resources, and a bastion host in the OT [operational technology] demilitarized zone (DMZ), where defenders again detected activity and isolated the system.โ
Still, CISA said both organizations had flaws in their defenses: They underestimated cloud risks; they lacked Conditional Access โ a Microsoft security tool โ for workload identities; and they didnโt have processes in place to revoke compromised access/refresh tokens.
CISA first published an advisory on its red team activity in 2023, but such advisories have been few and far between since. The agency said last year that it had not โlaid offโ its red team, after stories revealed the exit of contractors that included red-team members.
The post Water sector passes, government sector fails attempts to spot and halt simulated CISA attack appeared first on CyberScoop.


















