You are here

Cybersecurity

CISA Launches StopRansomware Initiative

CISA launched a StopRansomware initiative to bring greater awareness to this global cyber threat epidemic. The newly refreshed page has been rebranded and reorganized, and offers consolidated ransomware resources from all federal government agencies. While CISA did register a separate domain (stopransomware.gov) – presumably so they control it and so it’s not taken over by miscreants – the new domain redirects to a cisa.gov root domain (at least for the moment).

OT Cybersecurity – Thoughts on Industrial Sensor Monitoring to Make Critical Infrastructure a Less Attractive Target for Cyber Attacks

Many know Joe Weiss as a passionate proponent of ICS cybersecurity for control system process/sensor (level 0,1) devices. In this recent post he offers several points worthy of consideration on the importance of technology to monitor sensors. The discussion includes multiple water system examples. Read more at Control Global.

OT Cybersecurity – OT-based Credentials Observed Across Public Sources

While some water and wastewater utilities are able to maintain strict separation between OT and IT networks and the internet, that is not the reality for all. Credential leaks, credential reuse across sites, services, and systems, along with the ability to discover internet accessible and insecure control systems through open source search engines such as Shodan and Censys provide threat actors with plenty of opportunity to gain remote access to OT systems.

CISA’s Analysis of FY20 Risk and Vulnerability Assessments

The U.S. Department of Homeland Security Cybersecurity and Information Security Agency (CISA) released its Analysis of FY20 Risk and Vulnerability Assessments along with an infographic mapping from 37 of its Risk and Vulnerability Assessments (RVAs) conducted in Fiscal Year 2020 to the MITRE ATT&CK® Framework. The report identifies routinely successful attack paths CISA observed during RVAs conducted across multiple sectors.

Pages

Subscribe to Cybersecurity