Full Report
Learn about the current state of cyber threats to critical infrastructure and find out how state and local governments can protect against devastating breaches.
Analysis Summary
# Best Practices: Defending Critical Infrastructure
## Overview
These practices address the escalating cyber threats against state and local government infrastructure. They are designed to mitigate risks from state-sponsored actors (such as Volt Typhoon) and ransomware syndicates that target essential services including power grids, water treatment, transportation, and emergency services.
## Key Recommendations
### Immediate Actions
1. **Deploy Managed Detection and Response (MDR):** Implement 24/7 monitoring to identify "living off the land" techniques where attackers use legitimate admin tools for malicious purposes.
2. **Enforce Multi-Factor Authentication (MFA):** Mandate MFA across all remote access points, email accounts, and administrative interfaces to neutralize credential theft.
3. **Patch Critical Vulnerabilities:** Prioritize patching for all internet-facing systems, particularly VPNs and edge routers which are frequent entry points for infrastructure attacks.
4. **Audit Credential Use:** Monitor for "Unwanted Access" or session hijacking, specifically looking for anomalous logins from unusual geographic locations.
### Short-term Improvements (1-3 months)
1. **Enhance Email Security:** Implement advanced phishing protection and conduct staff training to recognize sophisticated social engineering and "fake IT worker" impersonation attempts.
2. **Incident Response Planning:** Develop and test a specific IR plan for critical systems (e.g., SCADA/ICS environments) to ensure rapid containment of breaches.
3. **Secure Backups:** Implement immutable, off-site backups that are logically separated from the primary network to ensure recovery after ransomware attacks.
### Long-term Strategy (3+ months)
1. **Adopt a Zero Trust Architecture:** Transition to a model where no user or device is trusted by default, regardless of their location relative to the network perimeter.
2. **Supply Chain Risk Management:** Establish security requirements for third-party vendors (similar to the SolarWinds scenario) and conduct regular audits of software dependencies.
3. **Cyber Insurance Integration:** Align security controls with cyber insurance requirements to ensure financial protection and technical compliance.
## Implementation Guidance
### For Small Organizations
- **Focus:** Maximize limited resources by using managed service providers (MSPs).
- **Action:** Outsource 24/7 monitoring to an MDR provider and focus internal efforts on basic "cyber hygiene" (patching and MFA).
### For Medium Organizations
- **Focus:** Formalize security operations.
- **Action:** Conduct quarterly vulnerability scans and implement a formal identity management system to control access to sensitive infrastructure controls.
### For Large Enterprises
- **Focus:** Defense-in-depth and resilience.
- **Action:** Establish a dedicated Security Operations Center (SOC), implement network segmentation between IT and OT (Operational Technology) networks, and run regular Red Team exercises.
## Configuration Examples
- **MFA Configuration:** Set "Conditional Access" policies to block logins from non-compliant devices or countries where the organization has no operations.
- **Endpoint Protection:** Configure EDR/MDR agents to alert on the execution of dual-use tools (e.g., PowerShell, AnyDesk, or ScreenConnect) when initiated by non-admin accounts.
## Compliance Alignment
- **NIST Cybersecurity Framework (CSF):** Aligning Identify, Protect, Detect, Respond, and Recover functions.
- **CISA Performance Goals:** Meeting the Cybersecurity Performance Goals (CPGs) specifically designed for critical infrastructure.
- **CIS Controls:** Implementing the top 18 critical security controls.
## Common Pitfalls to Avoid
- **"Set it and Forget it" Security:** Assuming that a firewall or antivirus is sufficient without active monitoring.
- **Ignoring "Living off the Land":** Failing to monitor legitimate administrative tools that attackers use to bypass traditional antivirus.
- **Neglecting OT Security:** Focusing only on office computers (IT) while leaving the controllers for water/power (OT) unprotected.
## Resources
- **CISA Shields Up:** hxxps[://]www[.]cisa[.]gov/shields-up
- **Huntress Blog (Tradecraft):** hxxps[://]www[.]huntress[.]com/blog
- **NIST Infrastructure Security:** hxxps[://]www[.]nist[.]gov/cyberframework
- **FBI IC3 Reporting:** hxxps[://]www[.]ic3[.]gov/