
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Internet Exposure Reduction Guidance to help organizations identify internet-accessible systems, remove unnecessary exposure, and secure required remote access.
Many organizations unknowingly expose information technology (IT) and operational technology (OT) assets to the internet, including remote access technologies, industrial control systems (ICS), supervisory control and data acquisition (SCADA) systems, programmable logic controllers (PLCs), and other connected devices. Threat actors can use internet-based search and discovery platforms to identify publicly accessible systems with misconfigurations, default credentials, and outdated software.
CISA encourages organizations to routinely assess their internet-accessible assets, verify third-party remote access, remove unnecessary exposure, and secure required access using strong passwords, multifactor authentication, security patching, traffic monitoring, and a secure gateway, firewall, VPN, or other centrally managed access solution.
CISA also offers Cyber Hygiene Services and regional Cybersecurity Advisors to help organizations reduce exposure and strengthen cybersecurity.






















