Leadership1 publisher3 min readPublished
Triage and tuning decided which SOC caught CISA's red team
CISA's red team breached two critical-sector organisations, and only the water-sector one contained it, isolating machines in up to 20 minutes. The gap traces to alert tuning and triage, so the first fix most SOCs need is analyst time.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CISA's tests found organisation A's SOC flooded with false-positive and low-value alerts set off by normal business operations.
- One alert the red team triggered at A was closed as a false positive because no one in the SOC could work out who owned the affected server.
- Sysdig strategist Crystal Morin said both organisations faced comparable attacks and triggered similar alerts.
- Bridewell CTO Martin Riley said B also disrupted command and control before the intrusion could move further.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- cost Process fixes are paid for in the SOC's own staff time, so the budget line that decides the outcome is analyst capacity for detection engineering.
- decision A leader weighing a new tool this quarter first has to know whether analysts can name the owner of every server that raises an alert.
- exposure Organisations that answer missed alerts by buying another product add sprawl to the same queue where A lost the red team's signal.
Detection fired at both organisations, so the failure at A happened after the tooling, in what the SOC did once an alert arrived [4]. Sysdig's Crystal Morin said the gap "had nothing to do with tools or maturity" [3]. Her description of B is about knowing the environment: "It knew what good behavior looks like, and what steps are out of line" [21]. Chris Oakley of LRQA called the closed server alert "a common story of technology not being the limiting factor" [12].
The obvious objection is sample size. Two red-team engagements are a thin base for a rule about every SOC. IT Pro's account does not describe either organisation's tool stack, and both operated in critical sectors [17]. The narrower finding holds up anyway: at A, the controls existed and the shortfall was in how they were set. Securonix's Cyrille Badeau said: "Some controls were in place, but they were not configured or tuned well enough to help the SOC at the point of investigation" [14]. He also said tool sprawl adds "another level of complexity" [16].
A SOC leader is choosing between a purchase and analyst hours, and the hours are the scarcer of the two. ExtraHop's figure comes from a separate report, not from CISA's test [8]. Still, if 68% of an analyst's day goes to reactive triage and manual data gathering, about 32% is left for everything else, including the tuning that would bring the 68 down [1]. Oakley said detection engineering is "not glamorous work" and "requires constant iteration" [13]. Debby Briggs, chief information security officer at NETSCOUT, said traditional network monitoring and high alert velocity can "quickly become overwhelming" for analysts [20].
The work available this quarter is small. Oakley's list from the findings: expiry dates on cloud keys, checks on cloud application permissions, and removing passwords from text files [18]. "These things don't necessarily need technology or a sizable budget and are achievable through time and mandate," he said [19].
The cost arrives next quarter, when the baseline starts to drift. I would expect a team that cleans up once and then goes back to the queue to slide back toward A's position. Badeau described how the drift happens: "Environments get larger, new applications are added, people change roles, and service accounts stay in place for years. The security team ends up looking at activity without always knowing what normal behavior should look like for that account or system" [15].
I think the case for sequencing holds for most SOCs: fix triage and baselines before buying more detection. The evidence does not show that tools stop mattering. B's containment began with detecting each phishing payload as it executed [6], and catching a payload at that speed requires the sensors to be in place already. On Morin's account, what set B apart was "the right approach to baselines and triage" [5].
What to watch
- Release of CISA's full advisory detail on each organisation's tooling and alert volumes, which would show whether the two tool stacks were actually comparable.
- Any repeat of the paired red-team comparison across more than two organisations or outside critical sectors.
- Whether SOC budgets move toward detection-engineering headcount; so far the record is practitioner commentary, with no spending data.