CISA Red Team Exercise Offers Ways to Tighten Infrastructure Cybersecurity
Summary
The Cybersecurity and Infrastructure Security Agency has issued an advisory on learnings from a red team cyberattack exercise and recommendations on countermeasures against the malicious activities simulated in the assessment. The exercise was conducted upon the request of a critical infrastructure organization, which also coordinated the release of the assessment, CISA said Thursday. It was heavily dependent on host-based endpoint detection and response and had insufficient network layer protection, the exercise showed. The CISA advisory also lined up mitigation measures that software manufacturers should take to address the cybersecurity risks and challenges facing critical infrastructure owners and operators as demonstrated in the red team exercise. To mitigate vulnerability to cyberattacks, the CISA document also recommends eliminating default passwords and mandating multi-factor authentication for privileged users.