WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships (TLP:CLEAR) CISA and USCG Identify Areas for Cyber Hygiene Improvement
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) CISA and USCG Identify Areas for Cyber Hygiene Improvement

TLP:CLEAR

Author: Chase Snow

Created: Wednesday, August 6, 2025 - 14:40

Categories: Cybersecurity, Federal & State Resources, OT-ICS Security

Summary: CISA led a proactive threat hunt engagement at a U.S. critical infrastructure organization with the support of U.S. Coast Guard (USCG) analysts. This advisory highlights areas of potential cyber hygiene improvement for other critical infrastructure organizations. During the engagement, CISA did not identify evidence of malicious cyber activity or threat actor presence on the organization’s network but did identify several areas of cybersecurity risk.

Analyst Note: Many of the risks identified are what WaterISAC considers “low hanging fruit”, or areas that can significantly impact a utility’s security posture despite requiring less resources for a utility to remediate. WaterISAC encourages members to review this advisory and the identified risks, which can help you prioritize areas of risk that may be present at your utility.  The identified areas of risk include:

  • Insufficient logging.
  • Insecurely stored credentials.
  • Shared local administrator (admin) credentials across many workstations.
  • Unrestricted remote access for local admin accounts.
  • Insufficient network segmentation configuration between IT and operational technology (OT) assets.
  • Several device misconfigurations.

Original Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-212a

Related WaterISAC PIRs: 6, 12

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar