Same Attack. Two Different Endings.
Same attack, same tools, two different endings. In CISA’s latest red team advisory, one critical infrastructure SOC never noticed a full domain compromise, while the other contained the same phishing attack in as little as two minutes. The difference wasn’t the threat. It was the response.
CISA ran the two assessments at the same time: one against a government services and facilities organization, one against a water and wastewater systems operator. The lessons learned can apply to any organization with identity, endpoint, network, and cloud infrastructure that likely have the same seams these testers walked through.

At the first organization, the compromise went undetected and uncontained for the full engagement. The organization ran multiple SOCs and multiple endpoint detection platforms with no shared visibility between them, and thousands of low-priority alerts from routine business activity buried the handful that mattered. One of those buried alerts had fired correctly. It flagged genuine red team activity on an SCCM server. The SOC discussed it, could not determine who owned the system, and closed it as a false positive. That is not a detection problem. It is an asset ownership question sitting on the seam between IT operations and security, and in this case it helped cost the organization its domain. The testers moved from a public-facing web app to domain admin, then into cloud resources, without a response that stuck.
At the second organization, analysts caught the initial phishing payload within 2 to 20 minutes and isolated the affected workstations before the testers could move laterally, cutting off command and control early. That is real defense, and it deserves to be named as one. But it was not prevention. Once the engagement shifted to an assume breach posture, the same testers found other paths into the same cloud resources. A faster, better coordinated response bought time and reduced the blast radius. It did not make the organization unbreachable, but it did keep the game from ending before the defense even took the field.
That is the honest reading of this advisory, and it is a more useful one than the tidy version. Tools alone do not produce detection. Detection and containment are what an organization’s people and processes do with those tools under real pressure, and the only way to know whether that combination actually works is to test it against realistic adversary behavior, not a checklist. That is the connective tissue between red teaming and managed detection and response (MDR): a penetration test that never informs a detection rule is a report. A SOC that has never been tested against real tradecraft is a hypothesis.
This is also why Neovera treats penetration testing and managed security operations as one conversation instead of two. All too often, a checkbox penetration test is not designed to do any more than find and exploit vulnerabilities. A red team assessment does that as well, but more importantly, simulates a real attacker and their tactics, (hopefully) generating alerts in your detection systems. This exercise can be crucial to identifying gaps in your blue-team’s response. A SOC that receives those findings and is measured on how fast it acts on them, is what turns that engagement into something durable. Split the two and you get exactly what CISA described: a well-intentioned team defending against yesterday’s threat model with today’s alert volume.
A few questions worth asking before the next audit asks them for you.
- Can you demonstrate which attack behaviors your SOC will actually detect?
- How quickly can your team move from alert to containment?
- Do your penetration test findings get converted into new detection logic, or filed?
- When did you last test escalation across identity, endpoint, network, and cloud teams together?
- Can every analyst on shift identify who owns any system that generates an alert?
CISA’s advisory is good, independent evidence for something we see in nearly every environment we assess: the gap between alerting and defense is where breaches live. Testing that gap on purpose, before someone else finds it for you, is the only way to close it.