CISA red team reveals why some SOCs fail and others succeed | TechTarget
"It was the best of times, it was the worst of times…"
Charles Dickens didn't write this in regard to red team testing, but the paradox illustrating how people experience the same event in different ways could relate to how various organizations' systems might fare differently when faced with the same red team simulation.
CISA this week published the results of simultaneous assessments its red team conducted against two critical infrastructure organizations. In both tests, the red team gained initial access to the victim's environment -- but one victim fared worse than the other.
Advisory AA26-237A, "A Tale of Two SOCs: Insights from Two Red Team Assessments," details how CISA penetrated both networks, resulting in "Organization A," from the government services and facilities sector, not detecting the intrusion, while "Organization B," from the water and wastewater systems sector, did. Both exercises reveal important lessons for CISOs.
"This alert raises...
Copyright of this story solely belongs to techtarget.com. To see the full text click HERE