惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
宝玉的分享
宝玉的分享
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
V
V2EX
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Engineering at Meta
Engineering at Meta
L
LangChain Blog
Jina AI
Jina AI
博客园 - 叶小钗
B
Blog RSS Feed
Recent Announcements
Recent Announcements
H
Help Net Security
小众软件
小众软件
大猫的无限游戏
大猫的无限游戏
B
Blog
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
D
DataBreaches.Net
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
CISA urges critical infrastructure firms to ‘fortify’ bef...
Eric Geller · 2026-05-05 · via Cybersecurity Dive - Latest News

The Cybersecurity and Infrastructure Security Agency (CISA) wants to help critical infrastructure operators keep their systems running during a major cyberattack or other serious incident.

CISA on Tuesday released guidance as part of an international “CI Fortify” initiative focused on activities that infrastructure operators can take to isolate the effects of a cyber intrusion and recover from them.

“In a geopolitical crisis, the critical infrastructure organizations Americans rely on must be able to continue delivering—at a minimum—crucial services,” acting CISA Director Nick Andersen said in a statement. “They must be able to isolate vital systems from harm, continue operating in that isolated state, and quickly recover any systems that an adversary may successfully compromise.”

The new guidance, modeled on advice that the Australian government published in 2025, comes as intelligence agencies warn that China might sabotage Western critical infrastructure to keep the U.S. and its allies from interfering with Beijing’s long-rumored invasion of Taiwan. China’s Volt Typhoon hacking campaign indicated that Beijing had already begun laying the groundwork for such disruption, prompting U.S. officials to step up warnings about the dangers of interdependencies in operational technology.

“Operators should assume that in a conflict scenario third-party connections — such as telecommunications, internet, vendors, service providers, and upstream dependencies — will be unreliable and that threat actors will have some access to the OT network,” CISA said on its CI Fortify page. “Isolation and Recovery are emergency planning objectives that can mitigate this threat within the next few years.”

The isolation advice includes identifying “critical customers,” such as nearby military bases, establishing service delivery expectations for them, identifying the OT assets necessary to provide that service and maintaining up-to-date “business continuity plans and engineering processes” to facilitate safe isolated operations “for weeks to months.”

The recovery advice covers documenting how systems operate, backing up important files and “practicing the replacement of systems or the transition to manual in case isolation fails and components are rendered inoperable.”

Critical infrastructure operators should discuss CISA’s advice with their vendors, the agency said, “to help understand their communications dependencies and potential workarounds.”

CI Fortify also includes recommendations for how other companies in the critical infrastructure ecosystem can support operators. Equipment vendors should remove barriers to isolation and recovery, CISA said, while managed service providers and integrators should help operators with engineering and planning work.

CISA also offers direct help

In addition to the guidance, which CISA will periodically update, the agency will also perform “targeted assessments” of participating critical infrastructure operators’ resilience measures, including their ability to operate in isolation, Andersen told reporters during a briefing on Tuesday.

“We've already started to kick off the first couple of assessments under a pilot phase of this initiative,” he said.

CISA’s regional offices will play a key role in supporting this assessment work, but they have been hit hard by layoffs, retirements and forced relocations as part of the Trump administration’s efforts to downsize CISA. The administration has approved CISA’s request to hire 329 new employees to fill critical vacancies, and Andersen told reporters that the regional teams “are high on that priority [list]” for the hiring plan.

Each infrastructure facility assessment will prioritize different outcomes depending on the sector and operator in question, Andersen said. Energy utilities and transportation systems can choose to supply or transport one customer versus another in the event of degraded capacity, he noted, while the water sector isn’t designed to work that way.

Editor’s note: This story has been updated with information from a CISA press briefing.