CISA Red Team Exposes Alert Noise and Siloed Response
CISA published a rare red-team report Tuesday showing two test targets take opposite paths: a government organization was phished, lost elevated access, and was later found in cloud and sensitive business systems without a response, while a water utility detected the same style of attack and contained it quickly.
The government case failed not because alerts were absent, but because thousands of low- and medium-severity endpoint alerts, plus some higher-severity ones, were buried in noise and split across organizational silos. The water utility triaged the alerts, quarantined the affected workstations within minutes, and stopped the intrusion before it could spread.
For government and water-sector shops that depend on endpoint detection, Conditional Access, and token-revocation workflows, the exposure is the handoff between detection and authority. If alerts do not reach someone who can act, identity compromise can keep moving across workstations, domain privileges, and cloud resources even after the first phish is spotted.