The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published an advisory, "A Tale of Two SOCs" (AA26-237A), detailing the results of two parallel red team exercises against critical infrastructure organizations. The report serves as a powerful case study on the difference between having security tools and having effective security operations. One organization, a water utility, demonstrated a mature defensive posture by rapidly detecting and containing the CISA red team. The other, a government services entity, was completely compromised without generating a single alert, blinded by thousands of false positives from poorly configured tools. The findings provide crucial lessons for all organizations on the importance of security operations maturity.
The advisory details two concurrent but separate red team engagements.
The primary technical gap at Organization A was not a lack of tools, but a failure to properly implement and manage them. The SOC was effectively non-functional due to alert fatigue. Key misconfigurations included:
In contrast, Organization B demonstrated effective use of its security stack, with well-tuned alerts, clear escalation procedures, and an empowered team capable of taking decisive action.
The report emphasizes that effective detection and response is a combination of people, process, and technology:
D3-PA - Process Analysis.Based on the findings, CISA recommends that organizations:
Regularly audit and tune security alerts to reduce false positives and ensure real threats are visible.
Harden Active Directory and AD CS configurations to prevent common privilege escalation techniques.
Implement secrets management solutions to avoid storing credentials in cleartext.
Conduct regular adversary emulation exercises (e.g., red teaming) to test and validate security controls and SOC responsiveness.
CISA releases advisory AA26-237A, 'A Tale of Two SOCs', detailing the red team findings.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.