WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships CISA Releases Analysis of FY23 Risk and Vulnerability Assessments
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

CISA Releases Analysis of FY23 Risk and Vulnerability Assessments

Author: Chase Snow

Created: Tuesday, September 17, 2024 - 17:40

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

CISA has published an analysis and infographic outlining the results from 143 Risk and Vulnerability Assessments (RVAs) conducted by both CISA and the US Coast Guard across various critical infrastructure sectors during fiscal year 2023 (FY23). These documents provide several detailed mitigations and remediation measures to help protect against the most commonly observed threat actor tactics.

The analysis presents a sample attack path, outlining the strategies and procedures a cyber threat actor might use to infiltrate an organization that exhibits vulnerabilities similar to those identified in the FY23 RVAs. The accompanying infographic showcases the most effective techniques for each tactic documented in the RVAs. Together, both the analysis and the infographic align threat actor behavior with the MITRE ATT&CK® framework.

Many of these threat actor tactics are highly prevalent to the water sector, particularly Lateral Movement which has been observed being used by Volt Typhoon to breach a water utility and is mentioned in the analysis (page 17). Members are encouraged to review both the analysis and infographic, and to apply the recommended mitigations. For more information, access CISA.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated April 30, 2026)

Apr 30, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar