WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships White House, CISA Recommend Cyber Best Practices
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

White House, CISA Recommend Cyber Best Practices

Author: Charles Egli

Created: Thursday, December 16, 2021 - 19:54

Categories: Cybersecurity, OT-ICS Security

In light of increased malicious cyber activity and the common tactic of actors deploying attacks when staffing is thin, the White House and CISA are offering tips for critical infrastructure and other businesses during the holiday season.

A December 16, 2021 White House memo to the business community offered several recommendations:

  • Update patching,
  • Know your network and quickly investigate possible intrusions,
  • Change passwords and mandate multi-factor authentication,
  • Manage schedules to ensure holiday coverage,
  • Educate employees about phishing,
  • Conduct exercises, and
  • Back up your data offline.

See more from the White House.

A December 15, 2021 CISA alert recommended:

  • Increased organizational vigilance by ensuring no gaps in IT or OT coverage,
  • Prepare your organization for rapid response by updating incident response plans,
  • Ensure your network defenders implement cybersecurity best practices,
  • Stay informed about current cybersecurity threats and malicious techniques, such as those provided by WaterISAC and other sector’s ISACs, and
  • Immediately report threats incidents to federal partners. Confidentially share the same with WaterISAC to inform sector-wide awareness.

See more from CISA.

These best practices are among those listed in WaterISAC’s 15 Cybersecurity Fundamentals for Water and Wastewater Utilities.

WaterISAC encourages members to confidentially share incident and attempted compromises with its analysts, to identify trends, and provide assistance. WaterISAC can share your incident information with CISA and FBI if you request this option.

Report incidents online or by email an*****@*******ac.org, or call 866-H2O-ISAC.

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar