CISA’s red-team tests found that a government organization was compromised and failed to respond effectively, while a water-sector organization detected the intrusion and quickly quarantined affected systems. Both organizations still had security gaps, including cloud-risk underestimation, missing Conditional Access for workload identities, and weak token revocation processes. #CISA #OrganizationA #OrganizationB
Keypoints
- CISA tested two organizations in the government and water sectors.
- The government organization was breached and did not respond effectively.
- The water organization detected the attack and quarantined systems quickly.
- Phishing and spearphishing were used to gain initial access.
- Both organizations had cloud security and token-management weaknesses.
Read More: https://cyberscoop.com/cisa-red-team-report-government-water-cybersecurity/