By Franklyn C. Adams
Timehri Networks
Detection and response, not tool count, separated the stronger defender
On August 25, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published cybersecurity advisory AA26-237A, “A Tale of Two SOCs: Insights From Two Red Team Assessments.” Two days later, WaterISAC highlighted the findings because one of the assessed organizations was a water and wastewater utility.
The comparison deserves the attention of every water utility manager, SCADA administrator, OT engineer, and cybersecurity leader.
CISA ran comparable red team assessments against two critical infrastructure organizations. One was in the Government Services and Facilities Sector. The other was in the Water and Wastewater Systems Sector.
In both environments, the red team ultimately achieved significant access.
But the defensive outcomes were very different.
The water utility’s security team detected malicious activity early enough to disrupt the red team’s progress, isolate affected systems, and force the attackers to change tactics. The other organization did not recognize the intrusion while it was occurring.
That difference provides an important lesson for critical infrastructure:
Cyber resilience is not measured by whether an attacker can ever get in. It is measured in large part by how quickly defenders recognize abnormal activity, contain it, and protect operations.
Both Organizations Were Tested. Only One Responded Effectively.
Red team assessments are designed to simulate realistic adversary behavior. Their purpose is not simply to prove that vulnerabilities exist, but to determine whether an organization can detect and respond to an attacker operating inside its environment.
In CISA’s assessment, the red team eventually gained substantial access in both organizations, including domain level access and access to sensitive systems and cloud resources.
This is a critical point.
The better performing organization was not successful because the attackers never penetrated its defenses.
It was successful because its defenders noticed what was happening and acted.
For water and wastewater utilities, that distinction matters enormously.
Control environments are built to maintain reliable physical operations. A cyber incident can therefore become more than an information security event. If malicious activity reaches systems supporting treatment, pumping, distribution, collection, telemetry, or remote operations, the consequences can become operational.
Early detection gives the utility more options.
Late detection gives the attacker more options.
Alert Volume Can Become a Security Weakness
One of the most valuable findings from CISA’s advisory was not about malware, firewalls, or a particular vulnerability.
It was about alert overload.
WaterISAC’s summary notes that the organization that performed poorly was burdened by thousands of routine alerts. Its personnel were also hindered by fragmented coordination and uncertainty over who had authority to take action.
This is an important warning for utilities developing or outsourcing Security Operations Center capabilities.
The objective of a SOC should not be:
Collect every possible event and generate as many alerts as possible.
The objective should be:
Identify the events that matter, add enough context to understand them, and ensure someone is empowered to act.
A dashboard displaying 20,000 alerts is not necessarily evidence of strong security.
It may be evidence that analysts are being asked to find a meaningful signal inside an enormous amount of noise.
For utilities with limited cybersecurity staffing, this problem can be especially dangerous. An analyst who spends most of the day dismissing false positives may miss the small number of events that indicate a real compromise.
A Utility SOC Needs Operationally Meaningful Detection
Traditional enterprise monitoring remains necessary. Authentication failures, endpoint detections, suspicious network connections, firewall events, privilege changes, and unusual account activity can all provide valuable evidence.
But water utilities should go further.
Detection should be prioritized according to the systems and actions that could affect operations.
Examples of high value activity may include:
• unusual access to SCADA servers or engineering workstations,
• unexpected administrative privilege changes,
• remote access sessions outside approved maintenance windows,
• new communications between network zones,
• changes to firewall or VPN configurations,
• execution of administrative tools from unusual hosts,
• new devices appearing in sensitive OT segments,
• unauthorized changes to accounts used for SCADA or remote access, and
• security events occurring immediately before or during unusual OT activity.
The purpose is not to turn every process event into a cybersecurity alarm.
The purpose is to make sure the SOC can recognize activity that deserves investigation before an attacker has time to establish persistence, move laterally, or reach critical systems.
Detection Without Authority Still Creates Delay
CISA’s comparison also highlights an organizational issue that is frequently overlooked.
Even when analysts recognize suspicious activity, they must know what they are allowed to do next.
Can the SOC isolate a workstation?
Can it disable an account?
Can it terminate a remote access session?
Can it block communication across a security boundary?
Who must be contacted before action is taken on a system supporting plant operations?
Who decides whether an event requires escalation to utility leadership, operations, engineering, legal counsel, or an incident response partner?
These questions should not be answered for the first time during an intrusion.
Water utilities should establish clear escalation paths and decision authority before an incident occurs. In OT environments, this is particularly important because an action that is routine in enterprise IT, such as isolating a host, may have unintended operational consequences if the system supports a running process.
The SOC, SCADA team, operations personnel, and incident response leadership therefore need predefined procedures for acting together.
The Lesson Is Not “Build a Bigger SOC”
Smaller and midsize water utilities may look at a CISA red team assessment and conclude that the lesson applies only to organizations with large cybersecurity staffs.
That would be the wrong conclusion.
The lesson is not that every utility needs a large, 24 hour internal SOC.
The lesson is that every utility needs a reliable detection and response capability appropriate to its size and risk.
That capability might be provided through an internal team, a managed security provider, a shared service, or a hybrid model.
Regardless of the operating model, several questions remain the same:
• What systems and events are being monitored?
• Which alerts receive the highest priority?
• Who investigates them?
• How quickly are they reviewed?
• What OT context is available to the analyst?
• Who has authority to contain malicious activity?
• How are SCADA and operations personnel brought into the response?
A small utility with focused monitoring, well defined procedures, and clear escalation authority can be more resilient than a larger organization with expensive tools but poorly tuned detections and unclear responsibilities.
Five Actions Water Utilities Should Take From This Advisory
1. Review the alerts your team actually investigates
Utilities should examine their highest-volume detections and determine how many are meaningful. Repeated false positives should be tuned so analysts are not conditioned to ignore alerts.
2. Identify a small set of high consequence security events
Prioritize detections involving privileged access, SCADA administration, remote connectivity, security boundary changes, engineering workstations, and unusual movement toward critical OT assets.
3. Define escalation authority before an incident
Document who can isolate systems, disable accounts, terminate remote sessions, block communications, and contact operations leadership.
4. Connect cybersecurity responders with SCADA and operations personnel
The SOC should not operate as an isolated IT function when protecting operational technology. Analysts need a defined path to personnel who understand the process and can evaluate operational consequences.
5. Exercise detection and response, not only disaster recovery
Tabletop exercises should test whether the organization can recognize an intrusion, escalate it, make containment decisions, communicate with operations, and maintain safe service.
What Should Utility Leadership Ask?
CISA’s assessment gives executives and utility managers a useful way to evaluate cybersecurity without becoming cybersecurity specialists themselves.
Leadership can begin with a few practical questions:
If an attacker entered our environment today, how would we know?
How long would it take someone to investigate the first meaningful alert?
Would that person understand which systems are operationally critical?
Would they know who has authority to contain the activity?
Could our cybersecurity and operations teams make a coordinated decision quickly?
If the answers are unclear, the issue is not simply technical.
It is a resilience gap.
The Water Utility in CISA’s Assessment Offers an Encouraging Example
Cybersecurity reporting about critical infrastructure often focuses on failures.
This CISA assessment provides something equally valuable: evidence that good defensive practices can materially affect an attacker’s progress.
The water utility was not impenetrable.
It was attentive, responsive, and capable of taking action.
That is a more realistic model of cyber resilience.
No organization can reasonably assume that every phishing attempt, stolen credential, vulnerable device, or attacker technique will be stopped at the perimeter.
Utilities should instead build layers of defense that make malicious activity increasingly difficult to hide.
When prevention fails, detection must work.
When detection works, response must follow.
And when response begins, cybersecurity and operations must work together to protect the physical service the community depends upon.
That may be the most important lesson from CISA’s “Tale of Two SOCs.”
About Timehri Networks
Timehri Networks helps utilities and critical infrastructure organizations strengthen OT/ICS cybersecurity through practical assessments, secure architecture reviews, network segmentation, remote access evaluations, continuous monitoring, and cybersecurity roadmaps designed around operational realities.
Securing Operations. Strengthening Communities.