CISA Issues Internet Exposure Reduction Guidance

CISA has released guidance to help organizations identify and mitigate Internet-exposed systems in IT, OT, ICS, and industrial systems.

Bottom line: CISA guidance provides actionable steps to reduce Internet exposure risks for organizations.

What's happening: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released Internet Exposure Reduction guidance, impacting approximately 73% of U.S. industrial control systems (ICS) and 82% of industrial automation and control systems (IACS). The guidance focuses on IT, OT, ICS, and industrial systems exposed to the internet, including those using unsecured protocols like HTTP, FTP, and Telnet.

What to do: Organizations should review and update their system configurations to ensure they are using secure protocols like HTTPS, SFTP, and SSH, and implement vulnerability scanning and patching for systems with known CVEs (e.g., CVE-2021-4483) with a CVSS score of 9.0 or higher.

Source: Industrial Cyber