Blue padlock with the text "National Cybersecurity Awareness Month - October" written next to it.

CISA Outlines Steps for Critical Infrastructure During Cybersecurity Awareness Month

Updated resources emphasize account protection, employee training and plans to maintain essential services during cyber incidents.

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Cybersecurity Awareness Month resources to help businesses and government organizations protect critical infrastructure and prepare for disruptions.

Cybersecurity Awareness Month is celebrated every October, and this year’s theme is “Securing the Next 250.” The guidance combines basic safeguards with recommendations for monitoring threats, responding to attacks and restoring operations.

CISA identifies four practices it calls “foundational”: training employees to identify and report phishing attempts, establishing strong password requirements, implementing multifactor authentication and installing software updates.

Beyond those measures, organizations should record system activity to help security teams identify potential unauthorized access. CISA also recommends encrypting information and devices, maintaining backups and establishing recovery plans that account for how much data an organization can tolerate losing.

Incident response plans should address likely threats, including ransomware, and undergo review and exercises at least annually.

The agency also advises organizations to prepare for circumstances in which essential systems or internet connections become unavailable. Continuity plans should identify ways to sustain necessary functions through alternatives such as paper records or radio communication.

Additional recommendations include reporting cyber incidents to CISA and obtaining a .gov domain for eligible government entities.

For critical infrastructure operators, CISA emphasizes what it calls the 3Rs of cybersecurity: reduce, replace and recover. Limit potential points of intrusion; remove equipment that no longer receives vendor support; and develop the ability to restore service after an attack.

The agency’s updated awareness materials include a toolkit and resources tailored to businesses and government organizations.

About the Author

Chelsey Arries is assistant editor of Security Today, Campus Security Today, Occupational Health & Safety and Environmental Protection Online.

Featured

New Products

  • ADI Control4 product image

    ADI Control4® X4 & Control4® Connect

    Drive long-term system value and reduce post-installation friction with a visually redesigned control interface paired with a secure, future-ready smart service framework.

  • NAPCO product image

    StarLink Fire Max2 Dual Cell/IP Communicator

    Streamline commercial fire compliance with dual-carrier cellular connectivity, a dedicated FACP data path, and dual-layer electronic inspection verification.

  • Cover image for IDP ProCare

    IDP ProCare™ Premium Support Program

    Minimize downtime and secure uninterrupted credential production with priority technical support, overnight advanced unit replacements, and proactive system health reviews.