CISA ran the same attack twice last quarter. A water utility’s security team beat it. A government organization did not. That result, published this week in a CISA advisory rather than buried in an internal after-action report, is the most honest accountability document this agency has released in months, and I think it deserves to be read as a warning rather than a curiosity.

The experiment CISA ran on itself

In advisory AA26-237A, “A Tale of Two SOCs,” CISA describes two concurrent, request-based red team assessments run with nearly identical attack tradecraft: phishing for initial access, then privilege escalation toward sensitive business systems and cloud resources. One target was a Government Services and Facilities Sector organization. The other was a Water and Wastewater Systems Sector organization. Both environments were fully compromised by CISA’s red team, full domain takeover, cloud access, the works. The difference was what happened next.

The water sector organization’s SOC quarantined the compromised workstations within roughly two, ten, and twenty minutes of separate intrusion attempts, cutting off the red team’s command and control each time. CISA’s own advisory calls this “a mature, proactive security posture.” The government organization’s SOC received alerts tied to the same activity and did not act on them. CISA’s language is blunt: “the organization did not respond effectively to red team activity.” The advisory attributes this to alert fatigue from thousands of unfiltered false positives and to organizational silos between multiple SOCs that did not share visibility or communicate with system owners.

Media Partner

Web3 x AI Fusion — Media Partner

The counter-argument, and why it does not hold up

The obvious objection is that this proves nothing about government cybersecurity generally, just that one unnamed organization has messy internal processes, the same failure mode private-sector SOCs post about on a weekly basis. Alert fatigue and organizational silos are not government-specific pathologies. I take that seriously; CISA does not name Organization A, does not say it is a federal civilian agency specifically, and does not claim staffing levels caused its failure. Drawing a straight causal line from CISA’s own headcount to this SOC’s performance would be exactly the kind of unsupported claim this publication does not make.

But the objection misses what makes the timing notable rather than incidental. Five days before this advisory published, five members of Congress asked the Government Accountability Office to examine what CISA’s own staffing losses have done to its ability to carry out its mission. “Yet, little is known about the impact of these workforce reductions on CISA’s programs and services or what processes and plans the agency has in place to ensure the agency is hiring the right people to address lost skill sets and meet mission demands,” Rep. James Walkinshaw and Rep. Bennie Thompson wrote to the GAO’s acting comptroller general, citing reporting that the agency has lost nearly a third of its workforce. That letter is about CISA’s capacity to support other organizations, not about Organization A’s own staffing. I am not claiming the two documents describe the same cause. I am pointing out that Congress is asking whether the agency running these assessments still has the bench strength to do so, in the same week the agency published proof that at least one government-sector SOC failed a test a water utility passed.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

What it means for the security leader

Read past the headline pairing and the lessons CISA drew are the ones every SOC leader already knows and few fully act on. Untuned detection tools that bury real alerts under thousands of false positives are not a government problem, they are a maturity problem, and this publication has covered enough critical-infrastructure intrusion campaigns this year to say plainly that the water utility’s twenty-minute detection window is closer to the standard the sector needs than the exception. Organizational silos that leave SOC staff without clear authority to isolate a system without escalating through layers of approval will keep producing an Organization A somewhere, in government or out of it.

What should change is how seriously boards and agency leadership treat a red team failure once it is public. CISA published this advisory voluntarily, in coordination with both assessed organizations, specifically so other critical infrastructure operators could learn from it. That is the system working as intended. Whether the organizations that most need the lesson, particularly government entities operating with fewer resources than the water utility in this comparison, actually have the headcount and authority structure to act on it is the question the GAO probe should answer, and the one this advisory makes impossible to dismiss as hypothetical.

Source: CISA Advisory AA26-237A, “A Tale of Two SOCs”