A Tale of Two SOCs: Insights F... Note

A Tale of Two SOCs: Insights From Two Red Team Assessments

CISA conducted two red team assessments at different organizations to evaluate their cybersecurity defenses. Organization A failed to detect or stop the red team's activities, leading to full domain compromise. Organization B, however, quickly identified initial compromise attempts and isolated affected systems. This allowed the red team to operate under an "assume breach" model for part of the assessment. The advisory highlights lessons learned from these contrasting outcomes. One key lesson is that untuned detection tools generate too much noise, hindering threat identification. Organizational silos and bureaucratic processes also impede effective incident response. Furthermore, cloud environments are often underestimated security risks with inadequate controls. To improve security, organizations should tune detection tools and reduce noisy alerts. Breaking down silos and empowering defenders is crucial for effective response. Implementing Conditional Access policies for workload identities and monitoring permissions is also recommended. Finally, organizations must establish clear procedures for detecting, remediating, and revoking access in cloud environments.