The Cybersecurity Accountability Gap: What a Federal Red Team Test Revealed

The Cybersecurity Accountability Gap: What a Federal Red Team Test Revealed
Jason Lafakis

Jason Lafakis

Senior IT/Cybersecurity Solutions Advisor

5 min read · Sep 15, 2026

Earlier this year, CISA, the Cybersecurity and Infrastructure Security Agency, tried something interesting. They sent one of their own red teams, essentially a group of ethical hackers whose job is to break into an organization the same way a real attacker would, after two different companies at the same time, using the same playbook against both.

Both companies got broken into. Fully. In each case, the attackers reached sensitive business systems and data in the cloud. On paper, both companies were equally exposed.

Here's where it gets interesting. One company caught the attackers within twenty minutes and shut them down before real damage was done. The other company never noticed at all. Not during the test, not after it. The attackers got so deep into the network that at one point they were quietly reading the security team's own email, just to check whether anyone had picked up on what was happening.

Nobody had.

The Real Difference Wasn't Technology

When CISA explained why one company caught it and the other didn't, they didn't point to better antivirus software or a more expensive security tool. They pointed to something much simpler: how the people and the process around those tools were set up. In their own words, “detection tools are only as effective as the people, processes, and procedures supporting them.”

I've sat in on more than a few conversations after something goes wrong, and the real answer almost never turns out to be a missing piece of software. It's almost always a structure problem. Two teams, or two systems, that each assumed somebody else was watching a particular part of the business, and neither one of them was technically wrong. They just weren't right either.

That's basically what happened at the company CISA calls Organization A. Their security setup wasn't one team with one clear picture. It was several different tools and providers running in parallel, none of them talking to each other, and nobody with clear authority to say “this is mine, I'm handling it” when something suspicious showed up. On top of that, they were getting so many low priority alerts every day that the one real warning sign, tied to actual attacker activity, got waved off as noise. Nobody was asleep at the wheel. They were just buried.

What This Means If You Run a Regulated Business

This is pretty common in regulated companies. Over time, different vendors get brought in to solve different problems. One handles the firewall, another monitors security, another supports IT, and the internal team fills in the gaps. It works well enough most days. The real test comes when something goes wrong at 2 a.m. and nobody is quite sure who is supposed to take the lead. That is the accountability gap, and it usually does not become obvious until the moment you need everyone working as one team.

So here's the question worth asking yourself, and it isn't “do we have security tools,” because you almost certainly do. It's this: if someone on your team spotted something suspicious tonight, would they know whose job it is to deal with it, and would they have the authority to act immediately, without needing three phone calls first?

If you had to pause before answering that, you already know where your own blind spot probably is.

Closing the Gap

This is exactly the argument I keep making to clients, because CISA basically proved it with real data. Adding more tools without one team clearly accountable for the whole picture doesn't fix this. It usually just adds more noise. A single accountable operator across your IT, security, and compliance closes that gap, because there's one team that owns the full picture and has the authority to act on it.

The only real way to know where you stand is to test it. Not with a scan you run once a year and file away, but with regular penetration testing and vulnerability assessments on an ongoing basis.

I tell clients this all the time: security is a process, not a product. You can't buy a tool that solves this permanently and then walk away from it. You have to keep testing whether your process actually holds up in practice, not just on paper.

And if something does get through, which eventually it will for almost everyone, the real question is whether your managed detection and response has one clear owner, or whether it's twenty people each quietly assuming somebody else has it covered.

I don’t think the team at Organization A ignored the risk. The problem was that responsibility was spread across too many people, and no one had a clear view of what happened next when something went wrong. That kind of gap can sit unnoticed for a long time, right up until an attacker finds it first.

If you are not sure who owns what in your own environment, we can help you take a closer look before that ambiguity becomes a real problem. Let’s talk.

Because the real question CISA is asking here isn't really about their report. It's about whether you'd know, tonight, which one of these two companies you actually are.

Not sure which company you'd be tonight? Book a short call with RedZone and we'll walk through where your own environment might have this exact gap. Schedule a conversation →

Jason Lafakis is a Senior Cybersecurity Solutions Advisor at RedZone Technologies, where he works directly with credit unions, healthcare organizations, and manufacturers to close the gap between the security tools they've bought and how those tools actually get used day to day.

Source: CISA Advisory AA26-237A, “A Tale of Two SOCs: Insights From Two Red Team Assessments,” released August 25, 2026.

Frequently Asked Questions

What is the cybersecurity accountability gap?

The accountability gap is what happens when a company relies on several disconnected security vendors and tools, none of which is clearly responsible for the environment as a whole. When no single team owns the full picture, real threats get missed or dismissed because nobody is certain whose job it is to act.

What did CISA's red team report actually find?

CISA ran the same red team style attack against two critical infrastructure organizations at the same time. Both were fully compromised during testing, but one company detected and shut down the attack within twenty minutes, while the other never detected it at all.

Why didn't better security tools prevent the breach?

According to CISA, the difference between the two companies wasn't the quality of their security tools. It came down to people, process, and clear ownership: who was watching, who had authority to act, and whether alerts were reaching someone who could actually respond.

How is vendor sprawl connected to security breaches?

Vendor sprawl happens when a company adds security tools and providers one at a time over the years without ever designing how they work together. Each relationship makes sense on its own, but nobody ends up accountable for the whole environment, which is exactly the gap attackers rely on.

What can a business do to close its security accountability gap?

Start by identifying whether one team or provider is accountable for your full security environment, rather than several disconnected vendors. Pair that with ongoing penetration testing and a managed detection and response function with a single clear owner, rather than relying on an annual audit alone.

What is PTaaS and why does it matter more than an annual security audit?

PTaaS, or penetration testing as a service, is ongoing testing rather than a once a year assessment. Security is a process, not a product, so testing on a recurring basis is what actually shows whether your defenses hold up in practice, instead of just looking good on paper once a year.

Confidence across IT, Security, and Compliance

Ready to take control of your IT and security posture?