Blue padlock with the text "National Cybersecurity Awareness Month - October" written next to it.

CISA Outlines Steps for Critical Infrastructure During Cybersecurity Awareness Month

Updated resources emphasize account protection, employee training and plans to maintain essential services during cyber incidents.

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Cybersecurity Awareness Month resources to help businesses and government organizations protect critical infrastructure and prepare for disruptions.

Cybersecurity Awareness Month is celebrated every October, and this year’s theme is “Securing the Next 250.” The guidance combines basic safeguards with recommendations for monitoring threats, responding to attacks and restoring operations.

CISA identifies four practices it calls “foundational”: training employees to identify and report phishing attempts, establishing strong password requirements, implementing multifactor authentication and installing software updates.

Beyond those measures, organizations should record system activity to help security teams identify potential unauthorized access. CISA also recommends encrypting information and devices, maintaining backups and establishing recovery plans that account for how much data an organization can tolerate losing.

Incident response plans should address likely threats, including ransomware, and undergo review and exercises at least annually.

The agency also advises organizations to prepare for circumstances in which essential systems or internet connections become unavailable. Continuity plans should identify ways to sustain necessary functions through alternatives such as paper records or radio communication.

Additional recommendations include reporting cyber incidents to CISA and obtaining a .gov domain for eligible government entities.

For critical infrastructure operators, CISA emphasizes what it calls the 3Rs of cybersecurity: reduce, replace and recover. Limit potential points of intrusion; remove equipment that no longer receives vendor support; and develop the ability to restore service after an attack.

The agency’s updated awareness materials include a toolkit and resources tailored to businesses and government organizations.

About the Author

Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products

  • DMP VK™ VMS With XV Plus Gateways

    DMP VK VMS With XV Plus Gateways

    Build flexible video monitoring systems with cloud-based video management, tiered AlarmVision analytics and gateways that need no inbound ports or separate VPN appliance.

  • Theia Technologies building fisheye

    Theia Technologies Linear Optical Technology®

    Learn how ultra-wide, zero-distortion rectilinear lens design improves spatial accuracy and eliminates the need for software de-warping in real-time robotic and automation systems.

  • new product

    Adams Rite 4300 Steel Hawk® Electrified Deadlatch

    Modernize aging storefront doors with a refined electrified deadlatch engineered to overcome sag, misalignment and heavy wear without replacing existing hardware.