New CGCYBER report warns of cybersecurity risks in marine environment due to network-connected OT systems
Govt & Regulations

2023 Cyber Trends and Insights in The Marine Environment (CGCYBER)

This report summarizes U.S. Coast Guard Cyber Command’s (CGCYBER) findings from calendar year 2023 and the associated mitigation recommendations. CGCYBER continues to expand its presence and navigate an increasingly interconnected marine environment. As we witness a surge in technological advancements, the organizations that facilitate the exchange of goods face evolving cyber threats, demanding our unwavering attention and concerted action.
NSA information sheet focuses on enhancing data security and zero trust implementation
Govt & Regulations

Advancing Zero Trust Maturity Throughout the Data Pillar (NSA)

This cybersecurity information sheet (CSI) provides recommendations for maturing data security and enforcing access to data at rest and in transit, ensuring that only those with authorization can access the data. It further discusses how these capabilities integrate into a comprehensive Zero Trust (ZT) framework.
E-ISAC releases report on GridEx VII exercise, highlighting recommendations for grid security and resilience
Govt & Regulations

GridEx VII Lessons Learned Report (NERC & E-ISAC)

This report summarizes the recommendations and observations identified through each exercise. The recommendations are intended to help electric utilities, government partners, the E-ISAC, and other stakeholders prepare for and respond to security incidents that affect the North American electricity system.
US DoD unveils DIB Cybersecurity Strategy 2024 to strengthen national cyber defenses
Govt & Regulations

Defense Industrial Base Cybersecurity Strategy 2024

The DIB Cybersecurity Strategy ensures that we remain on the cutting edge of what it takes to secure our infrastructure. It requires us foremost to coordinate and collaborate across the Department to identify and close gaps in protecting our DIB networks, supply chains, and other critical resources. In it, we have identified opportunities where we can bolster the cybersecurity of the DIB, align the Department's focus on systemic challenges, and provide solutions that deliver the highest return on investment.
Foresight Cybersecurity Threats FOR 2030 – Update (ENISA)
Govt & Regulations

Foresight Cybersecurity Threats FOR 2030 – Update (ENISA)

The "ENISA Foresight Cybersecurity Threats for 2030" study provides an in-depth analysis of potential cybersecurity threats expected in 2030. Using a multidimensional approach, this second iteration, first released in 2022, updates the top ten threats and trends, highlighting significant developments and evolving challenges in cybersecurity.
US agencies release updated guide on defending against DDoS attacks for critical infrastructure organizations
Govt & Regulations

Understanding and Responding to DDoS Attacks (CISA, FBI)

This guide provides an overview of the denial-of-service (DoS) and DDoS landscapes, including attack types, motivations, and potential impacts on government operations, as well as practical steps on implementing preventative measures, and incident response for each of the defined DDoS and DoS technique types.
Transnational security agencies warn of Volt Typhoon cyber threat, emphasize cyber risk as core business risk
Govt & Regulations

PRC State-Sponsored Cyber Activity: Actions for Critical Infrastructure Leaders

This document provides a comprehensive overview of the urgent risk posed by Peoples Republic of China (PRC) state-sponsored cyber actors known as Volt Typhoon. PRC-backed cyber actors targeting critical infrastructure, aiming to disrupt services amid geopolitical tensions. Issued by CISA, NSA, FBI, and partners, it calls for enhanced cybersecurity defenses against these sophisticated threats.
Govt & Regulations

Enhanced Cyber Security Obligations – Incident Response Planning (Australia)

Part 2C Division 2 Security of Critical Infrastructure Act 2018 Guidance. The document outlines essential strategies for crafting incident response plans, emphasizing preparedness for cyber incidents and alignment with overall cyber security strategies. It details the importance of managing incidents effectively, from detection through to post-incident analysis, to strengthen cyber resilience and recovery capabilities.
Govt & Regulations

Enhanced Cyber Security Obligations – Cyber Security Exercise (Australia)

Part 2C Division 3 Security of Critical Infrastructure Act 2018 Guidance. The document outlines guidelines for cyber security exercises under the Enhanced Cyber Security Obligations, highlighting the importance of timeframes for issue resolution, distinct and reasoned recommendations, and alignment between exercise outcomes and the broader security testing and assurance program.