Fact Sheet: Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems

Internet-Exposed HMIs Pose Cybersecurity Risks to Water and Wastewater Systems

Threat actors have demonstrated the capability to easily find and exploit internet-exposed human machine interfaces (HMIs) with cybersecurity weaknesses. 

Recognize, Assess, De-Escalate, Report

De-escalation Action Guide

Remaining vigilant and taking proactive measures to secure critical infrastructure and public gathering locations requires implementing various security measures to mitigate potential threats. 

Enhanced Visibility and Hardening Guidance for Communications Infrastructure

Enhanced Visibility and Hardening Guidance for Communications Infrastructure

This  joint guide provides best practices to protect against a People’s Republic of China (PRC)-affiliated threat actor that has compromised networks of major global telecommunications providers.

Blog: Updated: Trusted Internet Connection Secure Capabilities Catalog

Updated TIC 3.0 Security Capabilities Catalog

CISA published the updated version of the TIC 3.0 Security Capabilities Catalog version 3.2. The SCC was recently updated based on the new National Institute of Standards and Technology Cyber Security Framework Version 2.0 mapping updates.

Secure Our World. 12 Days of SAFE Holiday Online Shopping. Check these tips before you shop!

Shop Safely This Holiday Season

'Tis the season to stay safe online. Check out our 12 tips to keep your information and accounts secure. 

Secure by Design Progress Reports banner

Secure by Design Progress Reports

By taking the pledge, companies committed to making a good-faith effort towards seven key goals related to Secure by Design. Learn about their progress!

JCDC unifies cyber defenders from organizations worldwide. This diverse team proactively gathers, analyzes, and shares actionable cyber risk information to enable synchronized, holistic cybersecurity planning, cyber defense, and response.

StopRansomware.gov is the U.S. Government's official one-stop location for resources to tackle ransomware more effectively.

SAFECOM works to improve emergency communications interoperability across local, regional, tribal, state, territorial, international borders, and with federal government entities.

Additional CISA Resources

Abstract image of a PCB overlayed with cyber design elements

CISA’s Federal Cyber Defense Skilling Academy

CISA’s Federal Cyber Defense Skilling Academy provides full-time federal employees an opportunity to focus on professional growth through an intense, full-time, three-month accelerated training program.

Image of an event with speaker and participants

CISA Events

CISA hosts and participates in events throughout the year to engage stakeholders, seek research partners, and communicate with the public to help protect the homeland.

CISA Services Catalog

A single resource that provides you with access to information on services across CISA’s mission areas.

Employees pictured during training session

CISA Training

As part of our continuing mission to reduce cybersecurity and physical security risk, CISA provides a robust offering of cybersecurity and critical infrastructure training opportunities.