CISA compared two simultaneous red team assessments and saw the same tradecraft produce two very different outcomes. In one organization, the team reached multiple workstations, gained domain-level privileges, and moved laterally into sensitive business systems and cloud resources without being detected. In the other, defenders spotted the initial compromise quickly and quarantined the affected systems.
The difference was not attacker skill. Once the second organization caught the first foothold, the red team had to operate under an assume-breach model; even then, defenders later detected activity again when the team reached a bastion host in the OT demilitarized zone, or OT DMZ, and isolated it. That makes telemetry coverage and triage speed the deciding factors, not the initial access technique.
For organizations that rely on SOC alerts and quarantine workflows, the exposure sits in the gap between first compromise and containment. If that gap is invisible or slow, ordinary user-like access can turn into reach across business systems, cloud environments, and OT-adjacent infrastructure before anyone notices.