惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
Vercel News
Vercel News
Microsoft Azure Blog
Microsoft Azure Blog
爱范儿
爱范儿
N
Netflix TechBlog - Medium
Google DeepMind News
Google DeepMind News
H
Help Net Security
罗磊的独立博客
The Cloudflare Blog
J
Java Code Geeks
博客园 - 叶小钗
I
InfoQ
B
Blog
Blog — PlanetScale
Blog — PlanetScale
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
月光博客
月光博客
博客园_首页
雷峰网
雷峰网
M
MIT News - Artificial intelligence
博客园 - 【当耐特】
美团技术团队
T
The Blog of Author Tim Ferriss
博客园 - 司徒正美

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY Frontier AI models reap rapid discovery of security vulnerabilities
Major critical infrastructure disruptions are inevitable,...
Eric Geller · 2026-06-18 · via Cybersecurity Dive - Latest News

An article from site logo

In recent years, the U.S. government has reoriented its cybersecurity strategy away from prevention and toward resilience.

Published June 17, 2026

Two men and a woman sit on an event stage in front of a blue backdrop that displays the name of the event and its organizer

Nick Andersen, the executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, speaks at an Information Technology Industry Council event in Washington, D.C., on Feb. 3, 2026. Andersen discussed cybersecurity resilience at a conference on Wednesday. Eric Geller/Cybersecurity Dive

WASHINGTON — U.S. cybersecurity resilience in the face of sophisticated threats from China and other adversaries will increasingly depend on critical infrastructure’s ability to weather major disruptions, a top U.S. cyber official said Wednesday.

“Each and every one of us is operating right now on the front lines of a war that is never going to be cleared,” Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA), said at the Institute for Security and Technology’s Critical Effect conference.

“We are going to see an adversarial disruption of our critical infrastructure,” Andersen said. “It's going to have significant not just technical impact, it's going to have a significant psychological impact on the safety of the American people. … We need to start operating like that's the reality of where we're at — that we're not going to be able to keep everything persistently online and available as much as we would like.”

CISA’s emphasis on resilience marks a shift from earlier government cybersecurity doctrines that focused on preventing intrusions. In recent years, advanced nation-state hacking campaigns — especially Beijing’s Volt Typhoon espionage operation — have increasingly convinced government and industry strategists that their primary goal should be ensuring that infrastructure can continue operating during an attack.

“We have to start making some assumptions, like [that our] telecommunications infrastructure may be disrupted,” Andersen said at the Critical Effect conference, which focused on operational technology cybersecurity issues. “Why? Because the telecommunications infrastructure is going to be disrupted.”

To support national resilience efforts, the federal government has spent years trying to make a list of the most important infrastructure assets that accounts for complex interdependencies and supply-chain relationships. But successive administrations’ programs to identify those assets — referred to as Section 9 entities and systemically important entities — have borne little fruit.

Cybersecurity mandates or money?

During a question-and-answer session, Andersen addressed whether it was time for the government to require water utilities to participate in their sector’s information sharing and analysis center, the WaterISAC, which has one of the lowest participation rates of any ISAC. Andersen acknowledged that water was “a real mess of a sector for us” because of how localized it is, but he expressed skepticism that government mandates were part of the solution.

“I don’t know yet that we will see a moment where we start to move from the voluntary to the mandatory,” he said. “The bigger part for me is, how do we apply things like state and local grant dollars in the smartest way possible?”

CISA is working with lawmakers to reauthorize and reappropriate funds for the Department of Homeland Security’s State and Local Cybersecurity Grant Program, said Andersen, who described the program as a critical support mechanism for cash-strapped municipalities.

Grant funding and asset prioritization are better approaches than “making things mandatory on a sector that … doesn’t have the resources to be able to adapt to all these changing norms,” Andersen argued.

CISA’s goal, he said, was to “identify the entities, in a prioritized way, that we need to start doing that outreach to, and then, in a very deliberate way, making sure they've got … the right level of resources to help secure themselves and hit that higher standard and that higher burden that we're foisting upon them.”