To a great degree the strategic plan builds on the previously published CISA Strategic Intent and formalizes a number of cybersecurity strategy initiatives the agency is already well underway with.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
State-backed Russian hackers are actively exploiting a combination of MFA configuration vulnerabilities and the documented "PrintNightmare" exploit to penetrate networks and exfiltrate files and emails.
A new CVE program roadmap outlines planned enhancements, such as better identification and prioritization of the most immediate software threats and additional participation by an assortment of security researchers and open-source experts from around the globe.
CISA added the Ransomware Readiness Assessment module to the CSET toolset to assist organizations of varying maturity levels to assess their cybersecurity posture against attacks.
CISA has released a roadmap establishing four overarching broad goals, with five more specific lines of effort that appear to indicate concrete immediate priorities. Defensive AI cybersecurity measures and plans for critical infrastructure adoption are repeating themes.
According to a new joint warning published by the CISA, NSA and FBI, exploits by the Chinese hackers have been going on for at least five years in some victim critical infrastructure environments.
CISA stresses that "significant" Log4j breaches have not yet been found in the networks of federal agencies or critical infrastructure, but that it is not yet possible to assess whether the vulnerability is present across all of these disparate systems.
CISA warns about heightened security risks from the alleged Oracle Cloud credential leak affecting about 140,000 tenants and advises organizations to apply recommended mitigations.
A multi-agency cybersecurity advisory warns about unsophisticated hackers compromising U.S. critical infrastructure using basic and elementary intrusion techniques.
CISA is warning high-risk chemical facilities of potential data theft after a threat actor breached the agency's Chemical Security Assessment Tool (CSAT) via Ivanti Connect security flaws.










