{"id":20473,"date":"2024-05-16T10:19:31","date_gmt":"2024-05-16T17:19:31","guid":{"rendered":"https:\/\/webdev.securin.xyz\/?p=20473"},"modified":"2024-05-16T10:21:18","modified_gmt":"2024-05-16T17:21:18","slug":"protecting-u-s-critical-national-infrastructure-a-guide-to-shields-up-and-shields-ready","status":"publish","type":"post","link":"https:\/\/webdev.securin.xyz\/articles\/protecting-us-critical-national-infrastructure-a-guide-to-shields-up-and-shields-ready","title":{"rendered":"Protecting U.S. Critical National Infrastructure: A Guide to Shields Up and Shields Ready"},"content":{"rendered":"\t\t
When cyberattacks on US entities began to escalate at an unprecedented rate in 2023, the US Cybersecurity and Infrastructure Security Agency (CISA) took proactive measures to safeguard US information assets. Two highly successful security campaigns, <\/span>Shields Up<\/b><\/a> and <\/span>Shields Ready<\/b><\/a>,<\/b> were consecutively established in the aftermath of the Russian invasion of Ukraine to help U.S. organizations defend against and respond to cyber threats.<\/span><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t The first initiative, Shields Up, remains one of CISA\u2019s most successful defense campaigns, providing free assistance and information on cybersecurity to individuals and organizations to help them enhance their defenses and deal with attacks. The second campaign,<\/span> Shields Ready, was launched following the success of Shields Up. It took a broader reach and put out stronger protocols geared at moving Critical National Infrastructure (CNI) entities towards protecting themselves against cyberattacks. The campaign also aligns with the <\/span>Federal Emergency Management Agency\u2019s (FEMA) <\/span>Ready<\/span><\/a> campaign, facilitating collaboration and resource-sharing across emergency management communities.<\/span><\/p> While each campaign is designed to help US organizations improve their cybersecurity defenses, they cater to different target audiences, offer curated resources and tools, and vetted best practices varying in scale and focus to assist CNI entities. Concerned organizations in the education, healthcare, finance, energy, public service, and other critical sectors should not remain complacent by ignoring these valuable resources, which are provided by CISA at no cost. Instead, they should promptly make use of them, treating them as checklists to ensure they’ve covered all the required protocols.<\/span><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t Shields Up encourages proactive participation to increase organizational vigilance in protecting against cyber threats to critical infrastructure. In this campaign, CISA offers\u00a0 several security resources and tools for free, such as cybersecurity evaluations, technical support after a breach, complimentary training, exercises, and a ransomware checklist. With a focus on encouraging cyber breach reporting, CISA has also extended round-the-clock support for users to reach out in case of suspicious cyber activity.<\/span><\/p> Some of the best free resources that the Shields Up campaign has made available are:<\/span><\/p> Note: While these resources are certainly helpful they cannot be mistaken for thorough vulnerability scanning measures. They are meant to provide basic levels of security for organizations that do not already have it. For instance, CISA\u2019s vulnerability scanning tool specifically looks for 10 common causes of breaches in Microsoft Active Directory passwords; however, there are many more vulnerabilities out there.<\/span><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t Shields Ready was designed to protect all critical sector organizations in the United States. <\/b>Established in collaboration with the Department of Homeland Security (DHS), CISA, and FEMA, this campaign aims to equip and motivate CNI entities to prepare for potential retaliatory cyberattacks.\u00a0<\/span><\/p> It emphasizes strategic preparedness with a focus on building resilience into the systems, supply chains, facilities, and processes of CNI organizations.\u00a0<\/span><\/p> According to <\/span>IBM<\/span><\/a>, the five critical infrastructure sectors most affected by cyber attacks in the last two years (based on the overall data breach costs) are: healthcare, finance, pharmaceuticals, energy, and industrial.<\/span><\/p> Other critical sectors such as Transport, Education, Professional Services, and Communication are not far behind and also fall in the top target range of nation-state actors.<\/span><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t Securin’s recent <\/span>report <\/span><\/a>conducted a thorough analysis of these attacks, specifically focusing on ransomware incidents. The findings revealed that ransomware groups target entities with vulnerable defenses, high-value data, and substantial user bases. This often includes sectors like healthcare (with confidential patient records), education (containing sensitive information on minors), and finance (such as bank accounts and social security data). Additionally, there is a high likelihood of organizations in these sectors resorting to payouts to mitigate consequences and preserve reputation, especially if they lack the resources to effectively and promptly remediate the breach.<\/span><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t It is this deficit in protection, stemming from lack of knowledge and skilled resources, that CISA aims to address with <\/span>Shields Ready<\/a>. <\/b>The campaign offers all CNI enterprises access to more than 870 custom sector-specific security guides and best practice instructional manuals that they can use to fortify their defenses. These guides offer easy-to-understand and critical-to-implement measures that will help organizations withstand an array of risks from cyberattacks to national disasters. <\/span><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t T<\/span>here are custom guides, including several for the K-12 sector such as:<\/span><\/p> In addition to the above, CISA also oversees <\/span>SchoolSafety.gov<\/span><\/a>, a comprehensive federal website offering a centralized hub for school safety resources, information, and basic tools.\u00a0<\/span><\/p> Using these resources, the education sector has <\/span>successfully and proactively adopted CISA\u2019s cybersecurity resources in almost all US states. For instance, more than 10 schools in Maine joined together to form the Shields Up Maine cohort, while several other prominent organizations like Miami University, the University of Utah, and El Monte Union High School District have implemented cybersecurity measures recommended by CISA, enhancing their resilience against cyber threats and ensuring the protection of sensitive data. <\/span><\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t In healthcare, renowned organizations like the American Hospital Association and the American Optometric Association have embraced Shields Up. <\/span>Other healthcare organizations can also benefit from this goldmine of resources, including:<\/span><\/p>What Does Shields Up Bring to the Table?<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
How Does Shields Ready Help Critical Sector Infrastructure?\n<\/h2>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
For Banks and Financial Organizations<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
For Educational Institutions<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t
For Healthcare Providers<\/h3>\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t