The Hacker News reported on August 26 that CISA published results from two red-team assessments against critical infrastructure organizations. The headline lesson is uncomfortable but useful: both organizations were compromised at the domain level, but their defensive responses were very different. One did not detect the activity, while the other detected and contained important parts of the test.
That matters beyond critical infrastructure. Many smaller organizations pay for endpoint protection, managed security monitoring, cloud logging, backup alerts, identity tools, and incident response retainers. Those services may be valuable, but the business risk is not solved just because the invoice says security is covered.
For New Jersey businesses, schools, nonprofits, healthcare practices, manufacturers, and professional services firms, the practical question is whether the security stack creates usable security detection evidence. Can someone show which alerts were reviewed, who owned the affected system, what action was taken, and when the issue was escalated?
The gap between having tools and using them
CISA's advisory describes issues that business owners can understand without becoming security engineers. The report points to alert noise, disconnected visibility across teams and tools, limited analyst authority, unclear escalation procedures, default identity settings, cleartext credentials, static cloud access keys, and over-permissioned cloud applications.
Those are not just technical defects. They are management and accountability problems. A company can buy strong tools and still miss risk if nobody owns the systems generating alerts, if too many alerts are ignored as background noise, or if the team cannot tell the difference between a false positive and a business-critical system acting strangely.
This is where security monitoring can become a confidence problem. Owners may hear that endpoint detection is installed, logs are collected, or the MSP watches alerts. The more useful question is what evidence the provider can produce after a real incident, a tabletop exercise, or a simulated attack.
The business decision is proof, not product count
The decision for owners is not whether every business needs a red-team assessment. Many do not. The decision is whether the company has enough operational proof that its current security controls can produce action when it matters.
That proof does not have to be fancy. It can include recent alert-review samples, documented escalation paths, ticket histories, named system owners, cloud key rotation records, privileged-access reviews, backup restore evidence, and notes from incident-response exercises.
If a vendor or internal team cannot show that evidence, the next budget discussion should not automatically be about buying another tool. It may be about tuning alerts, reducing noise, assigning ownership, centralizing logs, rotating credentials, tightening cloud permissions, and giving responders authority to act.
Questions to ask your IT provider or security team
- Which alerts are reviewed by a person, and how quickly? Ask for examples from the last 30 to 90 days, not just a feature list.
- Who owns each critical system? If an alert names a server, firewall, cloud app, or database, someone should know who can approve action.
- What happens when an alert looks real? Confirm who can isolate a device, disable an account, revoke a token, or escalate to leadership.
- Are cloud keys and privileged accounts reviewed? Static cloud keys, broad application permissions, and stale admin access deserve regular review.
- Can the team connect endpoint, identity, cloud, and network evidence? A single alert may not tell the full story if the data sits in separate tools.
- When was the last response exercise? Even a short tabletop can reveal whether contact lists, authority, backups, and communication steps are usable.
A practical next step
Ask for a short security monitoring review instead of a broad promise that everything is covered. The review should list the tools in use, the alerts that matter most, who reviews them, how escalation works, which systems lack clear ownership, and what evidence the provider can show.
Then pick one improvement to complete first. For many smaller organizations, the best starting point is a high-value access review: administrators, service accounts, cloud applications, VPN users, shared mailboxes, and any static keys or tokens that could outlive the person who created them.
CISA's red-team results are a reminder that security confidence has to survive contact with real events. Tool names matter, but reviewed alerts, named owners, clean permissions, and rehearsed decisions are what turn monitoring into action.
Sources and further reading