From 207 items, 1 important content pieces were selected


Critical Infrastructure

  1. CISA withdraws six free cybersecurity assessments for critical infrastructure ⭐️ 7.0/10

Critical Infrastructure

CISA withdraws six free cybersecurity assessments for critical infrastructure ⭐️ 7.0/10

The Cybersecurity and Infrastructure Security Agency (CISA) has eliminated six free cybersecurity assessment services that critical infrastructure operators relied on, citing budget cuts. Tatyana Bolton, executive director of the OT Cyber Coalition, said the cuts have forced CISA into a position where it can no longer provide the level of hands-on, operational support to critical infrastructure operators that it previously offered. The article does not specify which six assessments were cut or provide a timeline for the change, but frames it as a reduction in federal capacity affecting operational technology (OT) security support across sectors.

rss · Utility Dive · Sep 3, 15:35

CISA’s role in critical infrastructure cybersecurity The Cybersecurity and Infrastructure Security Agency (CISA), part of the US Department of Homeland Security, has served as the primary federal body offering critical infrastructure operators no-cost cybersecurity assessments, including services tailored to operational technology (OT) environments in sectors such as energy, water, and rail. These voluntary programs have historically filled a gap for operators, particularly smaller utilities, that lack in-house resources to commission equivalent commercial penetration testing or vulnerability assessments. Federal budget reductions have now curtailed this hands-on support, shifting more of the assurance burden onto operators and private vendors.

What an operator should do Security and risk teams at utilities, water systems, pipeline operators, and other regulated critical infrastructure entities should inventory which CISA assessments (such as vulnerability scanning, penetration testing, or architecture reviews) their organization has used or planned to use, and confirm current availability before budgeting cycles close. Chief information security officers and OT security leads should evaluate commercial or sector-specific alternatives (such as Information Sharing and Analysis Center resources or private OT assessment vendors) to fill the gap, since self-funding these assessments has direct budget and procurement implications. Compliance and regulatory affairs functions should also track whether sector regulators adjust assessment expectations given reduced federal support.

Constraints The source does not specify which assessments were cut, an effective date, or whether reduced or fee-based alternatives will be offered, so operators cannot yet size the exact gap in coverage or cost.

Tags: #OT cybersecurity, #CISA, #critical infrastructure policy, #federal budget cuts, #regulatory capacity