Government Advisory

Two Companies, Two Outcomes: What a CISA Red Team Test Reveals About Cyber Defence

CISA · 25 Aug 2026
Key Takeaway Regularly review and fine-tune your security alerts, and make sure staff know exactly who to notify and what to do the moment something looks suspicious.

The Cybersecurity and Infrastructure Security Agency (CISA) recently ran simulated cyberattacks, known as red team assessments, against two organisations at the same time. In both cases, the testers managed to fully compromise the network and reach sensitive business systems and cloud resources. However, the outcomes differed sharply: one organisation failed to notice the intrusion at all, while the other quickly spotted early warning signs, isolated the affected systems, and forced the attackers to change tactics.

CISA found that the key difference wasn't necessarily the tools each organisation had, but how well those tools were configured and how effectively staff responded. The organisation that missed the attack had detection systems that weren't properly tuned, leading to a flood of false alarms that drowned out real threats. Internal silos and slow decision-making also hampered its ability to respond even when warning signs were present.

The advisory stresses that having security software is not enough — organisations need well-defined alert baselines, clear escalation processes, and coordinated teams ready to act quickly. These lessons apply broadly across IT, cloud, and operational technology environments, not just to large enterprises.

red team incident response detection CISA SMB security

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.