Skip to main content
ThreatHunt and ThreatContain revealed.See the announcements
Threat Intelligence · August 27, 2026

CISA's 'A Tale of Two SOCs': The Advisory Every MSSP Should Be Reading This Week

CISA's August 2026 advisory pits two red team assessments against each other: same access, same attack chain, two very different outcomes. The gap between them is the exact gap Vijilan's Global SOC is built to close.

Vijilan· 8 min read
CISA's 'A Tale of Two SOCs': The Advisory Every MSSP Should Be Reading This Week

The Advisory: Same Attack, Two Very Different Endings

On August 25, 2026, CISA published Cybersecurity Advisory AA26-237A, titled 'A Tale of Two SOCs: Insights From Two Red Team Assessments' [2]. It documents two separate CISA red team engagements against critical infrastructure organizations. Both used the same attack chain. Both achieved full compromise, reaching Active Directory and cloud systems inside the target environments [13][4]. And that's where the similarities stop.

In one engagement, the target organization's SOC detected the intrusion and moved to contain it. In the other, the SOC never saw it happen [3][12]. Same access, same techniques, same red team. One organization walked away with a documented breach and a red team debrief. The other walked away with an incident response.

CISA didn't publish this to embarrass anyone. It published it because the delta between those two outcomes is measurable, and it isn't the sophistication of the attacker. It's what the defending SOC did in the moments after the first signal appeared [5][4].

If you're an MSSP, this advisory is not background reading. It's a mirror. Every client environment you monitor is one red team exercise away from being SOC A or SOC B in someone else's advisory.

What CISA's Red Team Actually Found

Strip away the narrative framing and the advisory is describing something familiar to anyone who has run a SOC: an attacker gets a foothold, moves laterally, touches identity infrastructure, and eventually reaches cloud-connected systems [13]. None of that is exotic. What CISA is highlighting is that the technical findings, cloud security gaps and Active Directory exposure among them, were present in both environments [4]. The attack path wasn't the differentiator. The organizations shared similar weaknesses going in.

What diverged was the response layer. One SOC had visibility, correlated the activity, and acted. The other had visibility gaps, or had the visibility and didn't act on it in time to matter. CISA's own framing makes the point directly: the advisory exists to show 'which actions make the difference for quickly containing a breach' [7].

That's a very specific claim. Not which tools. Not which vendor. Which actions.

Detection Was Never the Hard Part

Here's the uncomfortable truth this advisory puts on paper: generating an alert is the easy 80% of the job. Security researchers studying SOC operations have been saying this for a while, alert triage is where SOCs actually live or die, and inconsistent triage is one of the most cited failure points in SOC effectiveness [16][17]. Most environments today, especially ones running CrowdStrike Falcon, Microsoft Defender, or Sentinel, are already generating a mountain of telemetry. The tooling is rarely the gap. The gap is what happens to that alert in the sixty seconds after it fires.

Does it land in a queue behind four hundred other alerts, waiting for an analyst to triage it during business hours? Or does something, human or automated, take action on it immediately: isolate the host, disable the account, kill the session?

CISA's red team just proved, with a live comparison, that this single variable is the one that separates a contained incident from a front-page one. That's not a hypothetical anymore. It's documented in a federal advisory with a control number.

Why This Should Sting a Little

There's a dark joke buried in this advisory for anyone who has worked a SOC floor: the losing team in 'A Tale of Two SOCs' almost certainly had a dashboard that looked fine. Green lights, tools deployed, alerts flowing. Nobody fails a red team exercise because they forgot to buy an EDR. They fail because the alert sat there being technically correct and operationally useless, like a smoke detector that emails you a PDF instead of waking up the house.

We're not going to name which SOC vendor or MSSP was on the losing side, CISA didn't, and neither will we. But every MSSP reading this advisory should be running an honest inventory of their own queue right now, not their client's.

What an MSSP Should Actually Do With This

  1. Audit your mean time to action, not just mean time to detect. If your SOC can show a detection timestamp but can't show a containment timestamp within the same incident record, you have the exact gap CISA just publicized.
  2. Check whether containment requires a human in the loop for every case type. Isolation, session kill, and account disable should be automatable for well-defined attack patterns, not a ticket that waits for an analyst to wake up.
  3. Pressure-test identity and cloud coverage specifically. Both red team engagements reached Active Directory and cloud systems [13][4]. If your monitoring stops at the endpoint and doesn't extend into Entra ID, Okta, or cloud control planes, you have the same blind spot CISA's red team walked through twice.
  4. Run your own tabletop against this advisory. Take the two-SOC scenario CISA describes and ask your team, honestly, which SOC you would have been.
  5. If you're white-labeling detection to a downstream SOC, ask them the same questions you'd ask a vendor. A logo on the report doesn't change whether containment happened in minutes or sat in a queue overnight.

Where Vijilan's Global SOC Fits

This advisory is, functionally, a case study for why Vijilan built ThreatRespond™, our Managed XDR service, around automated containment rather than alert generation. When a host shows credible signs of compromise, our Global SOC doesn't just open a ticket and route it into a queue. The action, isolate the endpoint, suspend the session, contain the identity, happens at the moment of detection, with human analysts validating and driving the response around the clock. That's the exact variable CISA's red team just proved matters more than anything else in the chain.

For partners running CrowdStrike Falcon, Microsoft Defender, or SentinelOne as their EDR layer, ThreatRespond and ThreatContain™ sit on top of that telemetry and do the part most stacks stop short of doing on their own: turning a correct alert into a closed loop, fast, without waiting for a human to triage it out of a backlog first. For MSSP and MSP partners specifically, we run this white-label under your brand, and we never compete with our partners for their clients. You keep the relationship. We close the gap CISA just spent an entire advisory describing.

If you want to see how that containment loop is built, or what it would look like layered onto your current stack, talk to our partner team. Pricing questions have a home too: vijilan.com/pricing.

Frequently asked questions

What is CISA's 'A Tale of Two SOCs' advisory about?

It's CISA advisory AA26-237A, published August 25, 2026, describing two red team assessments against critical infrastructure organizations that used the same attack chain and achieved full compromise in both cases. One organization's SOC detected and contained the activity; the other did not detect it at all.

What was the actual difference between the two organizations in the advisory?

Both environments shared similar technical weaknesses, including gaps in cloud security posture and exposure in Active Directory. The deciding factor was the SOC's ability to detect and act on the activity, not the attack technique itself.

Does having an EDR or SIEM tool prevent this kind of outcome?

Not on its own. Alert generation is table stakes for most modern security stacks. The advisory highlights that the gap is usually in triage and response speed, specifically whether containment action happens automatically at detection or waits in a queue.

How does Vijilan's ThreatRespond differ from a standard alerting service?

ThreatRespond is a Managed XDR service built around automated containment, such as endpoint isolation or session suspension, taken at the moment of detection by our Global SOC, rather than generating an alert and leaving containment to a downstream ticket queue.

Can MSSPs white-label this kind of containment capability?

Yes. Vijilan delivers ThreatRespond and related services white-label for MSSP and MSP partners, and we never compete with our partners for their clients.

Found this useful? Send it to someone who needs it.

Talk to a security expert

See what 24/7 looks like when the SOC actually acts.

Book a 20-minute platform walkthrough: no slide deck, just the console.

Book a walkthrough →