What happened
'A Tale of Two SOCs,' a CISA advisory, compares two simultaneous red team assessments run against a government services and facilities organization and a water and wastewater utility, both compromised using similar tradecraft: initial access through a web application with default credentials, phishing emails sent from a now-compromised internal address, privilege escalation via default Machine Account Quota settings and misconfigured Active Directory Certificate Services templates, then use of cleartext credentials and static AWS keys to reach cloud environments. The first organization detected none of it, it ran multiple SOCs and endpoint tools with no shared visibility between them, and thousands of routine false-positive alerts buried the signals the red team actually generated. The second organization's SOC isolated the compromised workstations and cut command-and-control communications within 2 to 20 minutes of the phishing payload executing.
Why it matters for your business
Both organizations had security tooling in place; the outcome came down to whether alerts had a clear owner and an escalation path, not whether the tools themselves were good enough. If your security stack spans multiple SOCs, MSSPs, or point tools that don't share visibility, you likely have the same blind spot the first organization did, regardless of budget.
What to watch next
CISA's fixes are concrete and apply well beyond the two organizations tested: remove default Machine Account Quota settings, audit AD Certificate Services templates for misconfiguration, eliminate cleartext credentials, rotate and scope static cloud access keys, and limit application permissions in Entra ID.
