Jessica Entwistle
August 26 2026
CISA has published findings from simultaneous red team assessments conducted at two organisations, revealing significant differences in defensive outcomes despite both organisations ultimately suffering full domain compromise. In both environments, the red team achieved complete control of the domain and accessed sensitive business systems and cloud resources. However, Organisation A failed to detect or contain any of the red team's activities throughout the entire assessment period, while Organisation B detected multiple stages of the attack and took containment actions, though not quickly enough to prevent compromise. The assessment found that Organisation A's security operations centre lacked clear processes for triaging alerts, had no defined escalation procedures, and did not conduct proactive threat hunting. Organisation B, by contrast, had established detection and response procedures, conducted regular threat hunting, and maintained clear communication channels between security teams and system owners.
This demonstrates that having security tools deployed is not the same as having effective detection and response capability. Both organisations in the assessment had security monitoring in place, but only one had the operational discipline, clear ownership and practiced procedures needed to actually use that monitoring to detect and respond to attacks. For many UK organisations, particularly those in sectors facing increased regulatory scrutiny around operational resilience, this highlights the gap between technical security controls and the human processes, team structures and organisational habits that determine whether those controls deliver meaningful protection. The findings are particularly relevant for organisations preparing for NIS2 compliance, where incident detection and response capabilities will be subject to regulatory oversight. The assessment also highlights that even organisations with good detection capabilities may not respond quickly enough to prevent compromise, which reinforces the importance of defence in depth, network segmentation and limiting the blast radius of successful attacks.
UK businesses should review whether their security operations teams have documented processes for alert triage and escalation, whether they conduct proactive threat hunting, and whether they regularly test their ability to detect and respond to realistic attack scenarios through exercises or red team assessments. Consider whether your security operations team has clear ownership of specific detection and response responsibilities, whether they have defined escalation procedures that are actually followed, and whether there are established communication channels between security teams and system owners that are used regularly, not just during incidents. It is also worth reviewing whether your security monitoring is tuned to detect the techniques that matter most in your environment, whether alerts are prioritised based on business risk, and whether your team has the time and resources to investigate alerts properly rather than just acknowledging and closing them. For organisations that do not have in-house security operations capability, consider whether your managed security service provider has these processes in place and whether you have tested their ability to detect and respond to attacks in your specific environment. The broader lesson is that mature security comes from clear ownership, practiced procedures and regular testing of detection and response capabilities, not just from deploying security tools.
Source: CISA