CISA ran two red team assessments against two critical infrastructure organizations using similar attack methods, and published the results side by side on August 25, 2026, in an advisory titled “A Tale of Two SOCs” (AA26-237A). Both organizations were fully compromised at the domain level, and in both cases the red team reached sensitive business systems and cloud resources. The part worth actually paying attention to is what happened after the initial breach, because that’s where the two organizations diverged completely.
Same Attack, Two Different Outcomes
Organization A, a Government Services and Facilities Sector entity, failed to detect or contain the red team’s activity at all. Organization B, a Water and Wastewater Systems Sector entity, had its security operations center isolate compromised workstations within 2 to 20 minutes of the initial phishing payload executing, cutting off command-and-control communication before the intrusion could spread further. Same style of attack, similar tradecraft, and one organization stopped it in minutes while the other never noticed. CISA’s own conclusion is the useful part: it attributed the gap to the people, processes, and procedures operating the security tools, not to which tools each organization had deployed.
Why “We Have Security Tools” Isn’t the Same as “We’re Protected”
This is the finding that generalizes past critical infrastructure specifically. Buying monitoring software, endpoint detection, or a SIEM platform gives an organization the capability to detect an intrusion; it doesn’t guarantee anyone’s actually watching, or that whoever is watching knows what a real intrusion looks like versus routine noise, or that there’s a defined, practiced process for what happens in the first few minutes after something suspicious shows up. Organization B’s 2-to-20-minute response time reflects a team that had actually rehearsed what to do, not just a better dashboard. Organization A’s total failure to detect activity, despite presumably having some security tooling in place, given that CISA’s advisory frames this as a process gap rather than a total absence of tools, reflects the opposite: tools that existed but weren’t actually operationalized into a working response capability.
What This Means for a Smaller Organization
Critical infrastructure operators run at a scale most small and mid-sized businesses don’t, but the underlying lesson holds regardless of size: detection tooling without a rehearsed response plan is a false sense of security, not real protection. For a smaller business, that doesn’t mean building a 24/7 SOC, it means knowing concretely what actually happens if something suspicious shows up in a server’s access logs or a security alert fires. Who looks at it? How fast? What’s the actual first action, isolate the affected system, change credentials, call the host’s support line? If those questions don’t have a clear, already-decided answer before an incident happens, the honest answer is that detection capability alone isn’t doing much, since the value of noticing something fast is entirely dependent on what happens in the minutes immediately after.
The Practical Takeaway
CISA’s own framing (people and process over tooling) is a useful gut check for anyone about to spend on a new security product rather than on process: a new monitoring tool that nobody reviews promptly, with no defined next step when it fires, adds cost without adding much real protection. A written, even informal, incident response plan, who gets notified, what gets isolated first, who has the authority to make that call, costs nothing but time, and based on what separated these two organizations, that kind of preparation mattered more than anything either one had actually purchased.

