Operational silos, technological sprawl and cloud-platform blind spots are serious issues preventing organizations from spotting and repelling cyberattacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a new report.
Those were three of the main factors that allowed CISA’s red team to break into the networks of two unnamed partner organizations — one a government agency, the other a water utility — during recent simulated attacks. But although the red team was successful in both intrusions, it had a much harder time with one attack than with the other, a fact that CISA attributed to important differences in the targets’ operating procedures and use of technology.
“In one organization (Organization A), the team gained initial access to multiple workstations, gained elevated privileges over the domain, and moved laterally to [sensitive business systems] and cloud resources undetected,” CISA said in a report released Tuesday. “In the second organization (Organization B), network defenders quickly detected the initial compromise and quarantined the affected systems.”
Organization A could have stopped CISA’s red team. Analysts in its various security operations centers (SOCs) received alerts from their endpoint detection and response (EDR) software about suspicious activity. But because the alerts were classified as low and medium severity, the SOC analysts — overwhelmed by false-positive alerts, some classified as high severity — didn’t act on the warnings.
The fact that the organization had multiple SOCs and EDR programs also hampered its response, CISA said. “Staff did not communicate with staff from other SOCs or have visibility on their detection tools. SOC staff and system owners also did not communicate with each other.”
Things were different at Organization B. The CISA red team’s intrusion generated multiple alerts that defenders responded to quickly. In one case, that response prevented the red team from receiving data from a command-and-control server that it had set up on a hacked computer. In another case, the defenders blocked a compromised Microsoft Azure account that the red team was using.
“These actions demonstrated a mature, proactive security posture and helped prevent wider compromise,” CISA said.
Still, Organization B’s Microsoft cloud services left the organization vulnerable. CISA’s red team eventually breached the organization’s Microsoft Entra ID platform by logging in with an overly permissioned account that lacked multifactor authentication (MFA) requirements. In its report, CISA said that oversight highlighted “the need for more mature cloud security processes.”
Organization B also failed to limit the permissions on some of its Microsoft Active Directory accounts, which helped the red team increase its ability to access data and make changes.
CISA summarized its findings by warning organizations about six key shortcomings: poorly tuned intrusion-detection tools that led to ignored warnings; bureaucratic barriers and communication gaps that prevented collaboration; overlooked cloud identity risks that created invisible openings; user credentials that were set to never expire; excessive, untailored permissions for applications; and a lack of procedures for replacing compromised cloud access tokens.