CISA Red Team Fully Compromised Both Orgs; One Saw Nothing
CISA published simultaneous red team results for two critical infrastructure orgs. Both were fully compromised at domain level; only one detected the intrusion.

CISA has published the results of two red team assessments it conducted simultaneously against two unnamed critical infrastructure organizations. Both used similar tradecraft. Both organizations were fully compromised at the domain level. The difference is in what happened after: one organization detected and responded to the intrusion; the other detected nothing.
That outcome gap is worth examining carefully, because the architecture assumptions in both environments were probably similar. That’s the design of a parallel assessment — same team, same techniques, different defensive posture.
What a CISA red team assessment does
CISA’s red team engagements follow a structured process: the team operates under realistic constraints to emulate a capable threat actor, attempting initial access, lateral movement, privilege escalation, and ultimately full compromise of the network. Domain-level compromise — in an Active Directory environment — means the red team reached the point at which they could authenticate as any user, access any system, and in practice read or modify anything on the network. In both cases here, they got there.
These assessments are not adversarial surprises dropped on unprepared organizations. The affected organizations consented to the assessment. What they did not know was exactly what tradecraft would be used and when — which is what makes the detection result meaningful.
The divergence
One organization caught it. The other did not. CISA’s published results document both outcomes alongside the same red team playbook. That comparison is the point: identical techniques, different visibility.
The organizations that fail to detect aren’t necessarily running fewer security tools. The detection gap in assessments like this typically traces back to a narrower set of root causes — log sources not feeding into detection pipelines, detection rules tuned only for known-bad indicators rather than behavioral patterns, alert queues deprioritized, or response procedures that exist on paper but haven’t been exercised against a realistic scenario.
Why it matters for critical infrastructure specifically
Operational technology environments add an additional constraint that enterprise IT doesn’t always carry: the systems that need protecting often can’t be patched, can’t run modern endpoint agents, and can’t be taken offline for remediation without service disruption. Domain-level compromise of the IT layer is a staging position for everything that follows. If you can’t see it in the IT layer, you have no early warning before the OT layer is in scope.
CISA has been explicit in multiple prior advisories that the path from IT to OT is the risk to operationalize against — not the individual CVE but the lateral movement chain that uses it. The NSA and FBI warning from earlier this month on AI-powered attacks against Siemens PLCs named the same pattern.
One thing to check
If your organization has never validated whether your detection tooling actually fires on realistic attacker tradecraft — not just on known-bad file hashes or signature matches — that’s the gap this assessment is documenting. CISA’s advisory published with this assessment includes specific defensive recommendations. Run detection validation against your current rule set before assuming coverage you haven’t confirmed.
Related: Treasury Sanctions IRGC-Linked Hackers Over ICS Attacks · NSA, FBI Warn of AI-Powered Attacks on Siemens PLCs · MLflow SSRF, FUXA Auth Flaws Actively Exploited
Found this useful? Share it.


