Blue padlock with the text "National Cybersecurity Awareness Month - October" written next to it.

CISA Outlines Steps for Critical Infrastructure During Cybersecurity Awareness Month

Updated resources emphasize account protection, employee training and plans to maintain essential services during cyber incidents.

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Cybersecurity Awareness Month resources to help businesses and government organizations protect critical infrastructure and prepare for disruptions.

Cybersecurity Awareness Month is celebrated every October, and this year’s theme is “Securing the Next 250.” The guidance combines basic safeguards with recommendations for monitoring threats, responding to attacks and restoring operations.

CISA identifies four practices it calls “foundational”: training employees to identify and report phishing attempts, establishing strong password requirements, implementing multifactor authentication and installing software updates.

Beyond those measures, organizations should record system activity to help security teams identify potential unauthorized access. CISA also recommends encrypting information and devices, maintaining backups and establishing recovery plans that account for how much data an organization can tolerate losing.

Incident response plans should address likely threats, including ransomware, and undergo review and exercises at least annually.

The agency also advises organizations to prepare for circumstances in which essential systems or internet connections become unavailable. Continuity plans should identify ways to sustain necessary functions through alternatives such as paper records or radio communication.

Additional recommendations include reporting cyber incidents to CISA and obtaining a .gov domain for eligible government entities.

For critical infrastructure operators, CISA emphasizes what it calls the 3Rs of cybersecurity: reduce, replace and recover. Limit potential points of intrusion; remove equipment that no longer receives vendor support; and develop the ability to restore service after an attack.

The agency’s updated awareness materials include a toolkit and resources tailored to businesses and government organizations.

About the Author

Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products

  • DMP VK™ VMS With XV Plus Gateways

    DMP VK VMS With XV Plus Gateways

    Build flexible video monitoring systems with cloud-based video management, tiered AlarmVision analytics and gateways that need no inbound ports or separate VPN appliance.

  • GroundAware® GA1360LH 2D 360-Degree Radar

    Protect up to 750 acres with a single sensor, delivering extended 1 km+ target detection, all-weather tracking and automated intrusion deterrence for critical infrastructure.

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities