CISA Updates Internet Exposure Reduction Guidance

08/25/2026 2:00 PM EST

Logo of the Cybersecurity and Infrastructure Security Agency (CISA) with a digital globe and data connections in the background.

Cybersecurity and Infrastructure Security Agency (CISA) has updated its Internet Exposure Reduction Guidance to help organizations identify internet-accessible systems, remove unnecessary exposure, and secure required remote access.

Many organizations unknowingly expose information technology (IT) and operational technology (OT) assets to the internet, including remote access technologies, industrial control systems (ICS), supervisory control and data acquisition (SCADA) systems, programmable logic controllers (PLCs), and other connected devices. Threat actors can use internet-based search and discovery platforms to identify publicly accessible systems with misconfigurations, default credentials, and outdated software.

CISA encourages organizations to routinely assess their internet-accessible assets, verify third-party remote access, remove unnecessary exposure, and secure required access using strong passwords, multifactor authentication, security patching, traffic monitoring, and a secure gateway, firewall, VPN, or other centrally managed access solution.

For more information, review the updated Internet Exposure Reduction Guidance. CISA also offers Cyber Hygiene Services and regional Cybersecurity Advisors to help organizations reduce exposure and strengthen cybersecurity.


Discover more from #News247WorldPress

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from #News247WorldPress

Subscribe now to keep reading and get access to the full archive.

Continue reading