Here's the finished article:


---


# One Organization Saw Nothing. The Other Saw Everything. CISA's Latest Red Team Exercise Exposes the Brutal Reality of Critical Infrastructure Defense


A CISA red team walked into two critical infrastructure organizations simultaneously. Both networks fell completely. Both saw identical attacker behavior. One organization's security operations center remained silent the entire time. The other caught the intrusion.


This isn't a hypothetical. CISA just published the results, and the findings should terrify anyone responsible for defending essential services.


The assessment, conducted under CISA's ongoing red team evaluation program, deployed the same assault techniques against two separate critical infrastructure entities. The attackers achieved full domain compromise at both targets. They moved laterally. They established persistence. They exfiltrated data. By every measure of an offensive engagement, both red teams won decisively.


But only one organization knew it was under attack.


That chasm between compromise and detection represents the actual state of critical infrastructure security in America. Not the state we claim. Not the state we're funding toward. The state we're living with right now. One organization had the tools, the processes, the visibility, and the will to see an attacker moving through their network. The other might still not know how long the red team was there.


## The Identical Playbook


Both red teams followed remarkably similar attack chains. This consistency matters because it reflects actual adversary tradecraft — the techniques that work repeatedly in the wild. They didn't use zero-days. They didn't deploy exotic malware. They exploited the same weaknesses CISA has been documenting for seven years: default credentials, unpatched systems, trust-based network architecture, and catastrophically poor identity controls.


The initial access vectors were mundane. Weak credentials. Phishing. An unpatched application. Once inside, the red teams moved with purpose. They enumerated the network. They escalated privileges. They compromised domain controllers. They established command and control channels. The activity was noisy enough that defensive tools — if actively deployed and actively monitored — should have registered alerts.


One security team registered nothing. No alerts. No incidents. No anomalies. The red team's entire campaign unfolded in a vacuum.


The defending organization that *did* detect the intrusion caught it through behavioral analytics and network monitoring. They saw authentication patterns that didn't match normal activity. They observed lateral movement traffic that violated their segmentation expectations. They caught beaconing activity that indicated an external controller. Were their defenses perfect? No. But they were *present*. More importantly, someone was actively watching.


That difference — between a deployed security program and a paper one — might be the widest chasm in infrastructure defense.


## This Isn't New. It's Gotten Worse.


CISA has been running these assessments long enough to establish a pattern. The detection gap isn't a sudden revelation. It's a persistent structural problem that organizations acknowledge, budget for, fail to implement, and continue ignoring.


The Colonial Pipeline ransomware attack in 2021 demonstrated this exact weakness at scale. Attackers maintained access for weeks — possibly longer — before the intrusion became visible. They moved through the network. They executed their payload. Defenders were operating blind until the damage became impossible to hide.


The SolarWinds supply chain attack in 2020 infected thousands of organizations globally. Attackers maintained persistent access across enterprise networks for months in many cases. Some organizations were breached for so long that the time-to-detection became a punchline in the security community. The vulnerability wasn't the most sophisticated element of the attack. Lack of visibility was.


CISA's prior red team assessments consistently documented the same gaps: overly permissive network architecture, weak segmentation between critical operational technology and corporate IT, insufficient logging, and an overwhelming reliance on perimeter security as the primary defense strategy. The assumption that the network boundary equals security is now responsible for more infrastructure breaches than any specific vulnerability.


Organizations still operate under an outdated security model: keep the bad guys out, and everything inside the perimeter is trustworthy. It's a framework designed for 1995. Defenders with real maturity understand this explicitly — the network is compromised. Design every system assuming attackers are already inside.


## Why One Org Detected and One Didn't


The difference wasn't sophistication of tools. It was maturity of posture.


The organization that detected the red team had invested in behavioral analytics and continuous network monitoring. They weren't waiting for signature matches. They were watching for deviation from baseline. They understood that credential compromise is inevitable, so they didn't build their entire detection strategy around the assumption that their identity system would remain healthy.


They segment their network. They log heavily. They correlate events across multiple sources. They hunt proactively rather than waiting for alerts to fire. That's not cutting-edge technology. That's defensive discipline.


The organization that saw nothing operated under different assumptions — assumptions that turned out to be fatal. They likely had a security operations center. They probably had signature-based detection tools. But if they're not actively hunting, if they're waiting for alerts to tell them something bad happened, they're operating in reactive mode against an opponent who has already won.


Critical infrastructure compounds this problem because much of it runs legacy systems. Operational technology networks were never designed with cybersecurity in mind. They were designed to run for decades with minimal downtime. EDR deployment is patchy. Log aggregation is absent. Network segmentation is a luxury many OT environments can't afford because it disrupts production. Defenders are essentially operating with medieval armor in a modern war.


## The Unspoken Message


CISA published these results because the detection gap is unacceptable. The organization that saw nothing is emblematic of a much larger population of defenders who will face actual adversaries — not red teams, but nation-state actors and ransomware groups — and will have no idea they're under attack until critical operations stop or data appears on the dark web.


The infrastructure that Americans depend on — power grids, water systems, transportation networks, communications — is defended by organizations operating with visibility that CISA has just proven insufficient. This isn't a hypothetical threat. This is the measured reality of how vulnerable critical systems actually are.


What should happen next is obvious. Organizations need to move away from detection strategies that depend on the health and integrity of their own identity systems. They need to assume the attacker owns domain credentials. Build detection that works in that context. Segment networks so that compromise in one zone doesn't automatically grant access to everything. Implement logging that captures behavioral anomalies, not just signature matches. Run purple team exercises — collaboration between red and blue teams — to ensure defensive tools actually work against real attacker tradecraft.


Organizations also need to accept that perfect prevention isn't achievable. The goal is speed of detection and response. Every day an attacker remains undetected is exponentially more dangerous than an attacker detected on day one.


## HackWire Analysis


The CISA findings hit hardest because they document the gap between what critical infrastructure organizations claim they can defend and what they actually can defend. One organization had tools, processes, and monitoring that worked. The other didn't. Both faced identical assaults. Both failed to prevent compromise.


What's critical to understand is that this isn't a tool problem. The defending organization didn't use some exotic detection platform. Behavioral analytics and network monitoring are mature, commercially available, and proven effective. The problem is that detection requires operational investment that many organizations treat as optional.


Compare this to prior CISA assessments and publicly disclosed breaches. The patterns are consistent: detection gaps correlate directly with dwell time. Colonial Pipeline. SolarWinds. OPM breach. Target breach. In every case, attackers maintained access significantly longer than they should have because defenders couldn't see them.


The implicit message from CISA is also becoming explicit: if critical infrastructure organizations can't detect sophisticated red team operations, they won't detect actual adversaries until after irreversible damage occurs. That's an unacceptable risk profile for systems that millions of Americans depend on.


What's missing from the broader security narrative is accountability. Organizations that have this visibility gap aren't failures — they're standard. The detecting organization is the anomaly. That's backwards. Detection should be the baseline. Until critical infrastructure defenders operate under that assumption, similar breaches remain inevitable.


— HackWire Editorial


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)