What's happening: CISA assessed over 100,000 critical infrastructure entities in 2022, including 1,200 high-risk organizations, such as those in the energy and healthcare sectors. The agency is retiring six free assessments, impacting 32 states and 3,600 organizations, which face increasing threats from nation-state actors and ransomware attacks. Nation-state actors launched 10,300 cyberattacks against US critical infrastructure in 2022, with 60% of these attacks targeting the energy sector. CISA is also reducing funding for its Cybersecurity Framework, which provides a voluntary framework for managing cybersecurity risks. The agency's Cybersecurity Framework received over 3,000 comments from stakeholders in 2022, with 70% of respondents expressing support for the framework's continued use. Security leaders must prioritize patching vulnerabilities in unpatched systems, leveraging tools like SolarWinds Patch Manager and Fortinet FortiGate. Organizations must also implement robust incident response plans, using tools like IBM QRadar and Splunk, to quickly respond to and contain security incidents. CISA is urging organizations to review their supply chain security practices and implement robust third-party risk management controls.
CISA Retires Free Cybersecurity Assessments for Critical Infrastructure
CISA is ending six free cybersecurity assessments for critical infrastructure, impacting 32 states and 3,600 organizations.
Source: Industrial Cyber