CISA Red Team Gains Full Domain Control of Two Critical Infrastructure Organizations, Exposing Detection Gaps
What Happened – CISA’s own red‑team exercises revealed that two critical‑infrastructure entities—one in the Government Services sector and another in the Water & Wastewater sector—lost complete domain control and had their cloud environments compromised. Organization A never detected the intrusion, while Organization B isolated the hosts within minutes.
Why It Matters for Compliance & Audit Readiness
- Full‑domain compromise and undetected activity illustrate a failure of the SOC 2 Security principle to “detect, prevent, and respond to system‑intrusion attempts.”
- The reliance on default credentials and a mis‑configured AD Certificate Services template highlights gaps in Access Control (CC6.1) and Change Management (CC7.1) that must be documented and continuously monitored.
- Continuous evidence of alert‑tuning, incident‑response playbooks, and credential‑hygiene controls is essential to provide a defensible audit trail—exactly what Verisq’s Control Mapping capability helps organizations capture.
Who Is Affected – Government Services & Facilities sector; Water and Wastewater Systems sector.
Recommended Actions –
- Map the compromised AD Certificate Services template to SOC 2 CC6.1 (Access Control) and CC7.1 (Change Management).
- Implement credential‑hygiene policies (no default passwords) and enforce MFA for privileged accounts.
- Tune SIEM/alerting rules to reduce false positives and ensure high‑severity alerts are triaged promptly.
- Capture continuous evidence of alert‑tuning, incident‑response drills, and remediation steps for audit readiness.
Source: Security Affairs – CISA Red Team Fully Compromised Two Critical Infrastructure Orgs
Technical Notes – Attack vector combined default‑credential exploitation, phishing from a trusted internal address, and a mis‑configured Active Directory Certificate Services (ESC1) template that allowed low‑privilege users to request high‑privilege certificates. No specific CVE was cited, but the flaw is a known misconfiguration in AD CS. Cloud resources were later accessed, and SOC staff emails were read to confirm the breach went unnoticed.