Critical Infrastructure Security Doesn’t Have Time for False Alarms as the Airspace Gets Busier with Drones

Drones have emerged as the tool of choice for bad actors at critical infrastructure sites. The confusion and damage caused by drone activity is very real, and awareness is growing, thanks to a spate of serious recent incidents that have drawn attention to the threat. Reports in December of unknown drone activity in New Jersey  sparked headlines around the world, and drone incidents also paused air traffic in two states, at an Air Force base in Ohio  and an airport in New York . These, unfortunately, are not isolated incidents.
At Sweden’s Stockholm Arlanda Airport , UAS sightings forced the suspension of air traffic, disrupting operations and endangering travelers. In Nashville, a man reportedly attempted to weaponize a drone with explosives  to collapse the U.S. power grid. It’s clear that drones are no longer a toy and are not restricted to causing annoyances such as disrupting air travel. They present a tangible risk to CI sites and reinforce the necessity for operators to be thoroughly prepared. And along with the uptick in drone sightings, a high volume of false alarms has proven a strain to security infrastructure and response teams.
The issue of false alarms is highlighted by an FBI report into drone sightings in December 2024 , concluding that many had been false alarms, with helicopters, hobbyist drones and even stars mistaken for drone threats. The FBI wrote, “Having closely examined the technical data and tips from concerned citizens, we assess that the sightings to date include a combination of lawful commercial drones, hobbyist drones, and law enforcement drones, as well as manned fixed-wing aircraft, helicopters, and stars mistakenly reported as drones. We have not identified anything anomalous and do not assess the activity to date to present a national security or public safety risk over the civilian airspace in New Jersey or other states in the northeast.”
At the same time, aviation and drone flights are growing rapidly, with the FAA dealing with 45,000 flights per day, and a million drones now registered in the U.S. The skies are a busy place, and traditional ‘2D’ security systems at critical infrastructure sites are struggling to keep up.
Recent Executive Orders, such as ‘Restoring American Airspace Sovereignty’  have highlighted the urgency of dealing with this issue, with the President’s Executive Order noting that, “Critical infrastructure, including military bases, is subject to frequent — and often unidentified — UAS incursions.  Immediate action is needed to ensure American sovereignty over its skies and that its airspace remains safe and secure.”
However, all too often, security teams are expected to deal with these new threats on top of their existing tasks, with teams simply asked to ‘look up’ rather than being augmented with specialist officers with the skills to deal with drone threats. That means already-stretched teams are stretched even further.
As demands for airspace monitoring, deconfliction, and threat management rapidly intensify, technology is becoming the essential bridge between strained security resources and evolving operational needs. Advanced sensor systems are now capable of discerning a broad range of airborne objects—not just aircraft—enabling more accurate identification and prioritization. This capability is vital in reducing false alarms and alleviating the burden on overstretched teams. Traditional perimeter intrusion detection systems (PIDS), while useful, often struggle to differentiate between drones posing real threats to critical infrastructure and benign objects like birds, debris, or weather phenomena. Emerging technologies offer a path forward, enhancing situational awareness and supporting more effective, efficient airspace security.
Cameras and radio frequency (RF) sensors have long played a valuable role in monitoring and securing critical infrastructure—from substations to dams—by providing early detection and situational awareness. However, as airborne threats grow in scale and sophistication, these traditional tools face challenges in reliability, often generating false alarms that burden security teams. Relying solely on optical or RF sensors, or ground-based guards focused on 2D perimeters, is no longer sufficient for addressing the complex dynamics of modern airspace threats. Closing this capability gap requires new technologies purpose-built for the evolving landscape.
The Good, Bad, and Ugly: The Airspace is Getting Busier
Drones are filling the skies at an unprecedented pace, driven by surging adoption in agriculture, infrastructure, and the rapid rise of commercial delivery fleets. Commercial delivery drones are expected to grow at 42.7% CAGR per year from 2025 to 2032, for example .
The FAA has registered 420,825 commercial drones and 383,007 recreational drones in the U.S., with drones used to inspect infrastructure sites sharing the skies with everything from electric vertical takeoff and landing vehicles (eVTOLs) and hobbyist UAVs. Hobbyist drone pilots may operate with good intentions, but their presence near airports, for example, can unintentionally disrupt critical airspace operations. With the FAA recording over 100 drone sightings near U.S. airports each month, the agency is focusing education efforts on recreational users to reduce these incidents and help ensure the safety and reliability of the national airspace system.
Critical infrastructure sites also face the possibility of drones being used for malicious purposes, ranging from espionage to direct attacks. To take one example, Greenpeace flew a Superman-shaped drone  into a nuclear plant in 2018 to show its vulnerability. In such situations, radar sensors can play an important role in providing time-stamped and geo-located evidence for later prosecutions.
Drones can also be a powerful tool for espionage, being able to land unobserved in remote locations, even if there is human security on the ground. From that position, they can probe wireless networks for vulnerabilities. Many locations that have previously been considered ‘secure’, because the idea of a cheap drone with cyber capabilities was science fiction 10 years ago, are now no longer ironclad.
And it is not just remote sites that are vulnerable. Any building that houses computer systems, be that a regional bank or a datacenter hosting cloud-based resources, could potentially be vulnerable to UAV attacks. With many of the services the world relies on, from email to food delivery to internet banking, hosted in server farms, there is vulnerability to small UAVs landing on the roof to tap into networks and breach security systems, or unleashing software to steal trade secrets or simply attack and damage resources.
There are many possible motivations for attackers to target CI locations, from criminal enterprises aiming to steal intellectual property, to state-sponsored espionage and terrorism, to those who seek to cause chaos for its own sake. For such attackers, drones are particularly attractive. They are low-cost, easily and legally accessible, and easy to modify to use as weapons.
In some cases, drones are purpose-built for offensive operations. One illustrative example is the Kalashnikov KUB-UAV, a loitering munition unveiled in 2019. Roughly the size of a coffee table, the drone can fly at speeds up to 80 mph for 30 minutes while carrying a six-pound payload—typically explosives—up to 40 miles. Described by its manufacturer as offering “hidden launch, high accuracy, noiselessness, and ease of handling,” it reflects the increasing sophistication of drone-based weapon systems.
In addition to individual drones, swarming tactics—in which dozens or even hundreds of smaller drones operate in coordination—represent another growing area of concern. These swarms could overwhelm traditional defenses and sensors through sheer volume and maneuverability. A RAND Corporation report  identifies drone swarms as a “current and growing threat,” particularly due to their potential to be used against complex and distributed infrastructure.
What Constitutes a “False Alarm” and Why
In the context of drones operating in shared airspace—whether the pilot is clueless, careless, or criminal—the term “false alarm” is often misunderstood. Many assume that if a detected drone isn’t a direct threat, it must be a false alarm. But that’s not the case.
A robust perimeter intrusion detection system—especially one that covers both ground and air domains—is expected to detect and identify all drones in its vicinity. That includes hobbyist drones, commercial platforms, and potential threats. The goal isn’t to ignore non-threatening drones, but to accurately classify and assess them.
This is why advanced detection, tracking, and classification technology is essential. With the growing diversity of drone makes, models, sizes, and flight behaviors, the ability to distinguish between benign and potentially malicious drones has become increasingly complex—and increasingly critical. Effective classification enables informed decision-making, reduces unnecessary escalations, and ensures that security teams can focus their attention where it matters most.
Why False Alarms Create a Vulnerability for CI Security Teams
True false alarms create vulnerabilities for CI security teams, ranging from wasted man-hours to increased operational costs. The most serious of these problems is incident fatigue: if false alarms sound constantly, there is a risk that operators will begin to think, ‘Nothing to worry about, it’s just another false alarm.’ This can lead to delayed response times and, more critically, a gradual desensitization among operators. When genuine threats do arise, the urgency to act may be diminished—resulting in missed opportunities to intervene and exposing the organization to significant financial and reputational risk.
Rising Attention from Authorities Signals a New Era of Airspace Security
As the operational implications of drone activity become clearer, federal agencies and national security leaders are responding with increased urgency. The FAA, for example, has been testing drone detection systems at airports for several years, and is now expanding these efforts to off-airport locations in New Mexico, North Dakota, and Mississippi. These trials involve hundreds of drones—both commercial and recreational—operating in real-world scenarios, highlighting a shift toward scalable, field-tested solutions for airspace awareness.
This growing investment in detection capabilities reflects mounting concern at the highest levels of government. Former FBI Director Christopher Wray, speaking before a U.S. Senate panel, called the drone threat “steadily escalating,” noting it had intensified following the publicity surrounding the attempted assassination of Venezuelan President Maduro using explosive-laden drones.
Meanwhile, former CISA Assistant Director Brian Harrell offered a blunt assessment as early as 2019: “This is not an emerging threat. This was emerging five years ago. This is here. It is now… The overhead threat for attack is absolutely real today.”
For operators of critical infrastructure, these signals point toward a clear trajectory: drone detection is no longer optional. In the wake of high-profile airport incidents and increasing visibility into the potential for airspace misuse, regulatory expectations are rising, and CI sites should prepare for a future where drone detection and classification are standard components of perimeter security.
Is Your Site More Susceptible to False Alarms? 
While airports have received much of the public and regulatory attention around drone-related false alarms—largely due to high-profile incidents and the obvious risks associated with dense air traffic—they are far from the only critical infrastructure sites affected. In fact, what makes a site vulnerable to false alarms is not just traffic volume, it is proximity to “drone-like” airborne objects, such as birds, balloons, or weather phenomena.
Utilities, energy producers, oil and gas facilities, and nuclear plants have all reported concerns:
• Nuclear Facilities: The U.S. Nuclear Regulatory Commission has acknowledged the potential threats drones pose to nuclear power plants, emphasizing the need for vigilance and reporting of unauthorized drone sightings.
• Energy Infrastructure: In July 2020, a modified drone was discovered near a Pennsylvania power substation , equipped in a manner suggesting an intent to disrupt operations. This incident marked the first known attempt to target U.S. energy infrastructure using a drone.
• Oil and Gas Platforms: Norway’s Petroleum Safety Authority  has urged increased vigilance after unidentified drones were observed near offshore oil and gas installations, warning of potential risks to safety and operations.
These examples demonstrate that the threat—and the potential for false alarms—extends well beyond airports, especially as the skies become increasingly crowded with commercial, recreational, and potentially hostile drones. Addressing this challenge requires precision detection technologies capable of distinguishing real threats from harmless objects across a wide range of environments and operational contexts.
Addressing the Limitations of Conventional PIDS in the Drone Era
How can critical infrastructure sites respond to the growing challenge of drones? Traditional security systems—designed for ground-level threats—are increasingly outmatched in the face of airborne risks. Most rely on thermal sensors, RF detectors, and human patrols, which are not only vulnerable to false alarms but can also miss or misclassify fast-moving, low-signature aerial objects. Cameras, for instance, often struggle to distinguish between drones and similarly sized objects like birds or debris.
Addressing this modern threat landscape requires a layered approach, combining detection, tracking, and classification with high-performance technology layers that support future-state mitigation. In this framework, advanced drone detection radar systems play a central role—bringing the precision and persistence needed to identify, classify, and respond to airborne intrusions in real time. Unlike conventional radar designed for ground-based movement, modern airspace-focused radar systems are built for high transmit and receive density, allowing them to continuously and precisely interrogate the entire field of view—even in cluttered or obstructed environments.
This enhanced radar capability provides far more than just detection. By analyzing size, speed, altitude, and flight behavior in real time, and when combined with optical and classification capabilities, radar helps operators distinguish between benign activity and true threats—minimizing false alarms and enhancing situational awareness. Crucially, radar performs reliably day or night, in all weather conditions, and does not depend on visible signatures or RF emissions. This makes it especially effective against so-called ‘dark drones’—unmanned systems designed to evade detection by flying silently and without emitting RF signals. These drones are increasingly favored by criminal actors for their ability to bypass traditional surveillance tools such as cameras, RF sensors, and optical systems.
Modern radar systems can track multiple airborne targets at once and leverage micro-Doppler capabilities to detect subtle flight behaviors—such as drones flying in tight formation, loitering in place, or slowly approaching with potential payloads. Additionally, today’s advanced drone detection radar is more compact, affordable, and easily deployable than ever before. Facilities like airports, substations, and water treatment plants can install multiple radar units to create overlapping coverage zones, even in complex layouts.
Other technologies play a valuable supporting role alongside radar, depending on the specific needs and layout of a given site. Optical sensors, such as pan-tilt-zoom (PTZ) cameras, are especially effective complements to radar, providing visual confirmation and enabling continuous monitoring once a target is detected. Additional sensors—such as thermal imaging systems and RF detection technologies for identifying drones that emit radio signals—can further strengthen the detection stack. When RF signals are catalogued and analyzed, they can also add meaningful value by helping to triangulate or trace the location of a drone’s pilot, offering an additional layer of operational intelligence. Together, these tools provide layered coverage and enhance overall situational awareness.
To move beyond the limitations of conventional perimeter systems, critical infrastructure sites must adopt purpose-built technologies for today’s airspace threats. Advanced radar designed specifically for drone detection is foundational to this shift, offering the precision, speed, and data richness required to manage a modern threat environment.
This level of precision becomes even more important in jurisdictions where mitigation is legal, as safely intercepting or neutralizing a drone demands real-time data on its size, velocity, flight path, and behavior. Only high-performance radar offers the responsiveness and fidelity necessary to inform proportionate, accurate, and legally defensible mitigation tactics.
Reducing False Alarms is Foundational for Modern Critical Infrastructure Protection and Resilience
For critical infrastructure security operators, the urgency to address false alarms—across personnel, systems, and overall security strategy—has never been greater. Every false positive consumes time, depletes resources, and reduces the impact of active site security efforts. It’s no longer enough to ask whether your PIDS is functioning—it’s time to ask whether it’s keeping up with the reality of today’s threats.
The threat has taken to the skies. Drones have rapidly evolved from hobbyist gadgets into instruments of espionage, disruption, and potential destruction. Site operators, policymakers, and security stakeholders must adapt to this new operational environment—one that demands new rules, new technologies, and new urgency.
A layered perimeter intrusion detection system, anchored with advanced radar that detects, tracks and classifies drones with precision delivers the situational awareness required to cut through the noise, drastically reduce false alarms, and free operators to focus on real threats. In doing so, they not only enhance site security, but also help protect the essential systems our modern world depends on. The path forward is clear: to defend what matters most, we must rise above outdated approaches—and start protecting the airspace as vigorously as we do the ground.
By Curtis Walters, Echodyne VP Sales, Government and Critical Infrastructure

UK arrest following aerospace cyber incident

A man has been arrested in the UK by the National Crime Agency as part of an investigation into a cyber incident impacting Collins Aerospace.
The incident, which was reported on 19 September, affected flights at Heathrow and other European airports over the weekend.
NCA officers, supported by the South East ROCU, arrested a man in his forties in West Sussex yesterday evening on suspicion of Computer Misuse Act offences. He has been released on conditional bail.
Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, said:
“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing.”
“Cybercrime is a persistent global threat that continues to cause significant disruption to the UK. Alongside our partners here and overseas, the NCA is committed to reducing that threat in order to protect the British public.”

Unidentified Drone Incursions Temporarily Shut Down Copenhagen and Oslo Airports

Authorities in Denmark and Norway are investigating a series of unauthorized drone sightings that forced the temporary closure of airspace over two major international airports—Copenhagen's Kastrup Airport and Oslo's Gardermoen Airport, and are being treated as serious threats to national and regional security.
In Copenhagen, multiple drones were detected near the airport perimeter, leading to a near four-hour shutdown that disrupted over 50 flights and affected approximately 20,000 passengers. Danish police say the drones demonstrated flight behavior consistent with advanced operation, and officials have described the incursion as one of the most significant threats to Denmark’s critical infrastructure in recent memory.
Shortly after the Copenhagen incident, Oslo’s main airport reported similar drone activity, prompting Norwegian authorities to temporarily close airspace. Though the disruption lasted just under three hours, it led to delays and diversions and raised concerns about a coordinated effort.
While Danish and Norwegian officials are cooperating closely, no definitive link between the two incidents has been established. Authorities in both countries are analyzing radar data, visual reports, and drone signatures as part of a joint investigation. Danish leadership has confirmed the threat level to critical infrastructure remains elevated.
Security experts across Europe have expressed growing alarm over the vulnerability of critical national infrastructure and entities to drone-related threats. Discussions are now underway among Nordic and EU partners regarding the implementation of a regional drone defense strategy.

CISA Releases Advisory on Lessons Learned from an Incident Response Engagement

CISA released a cybersecurity advisory detailing lessons learned from an incident response engagement following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response tool.
This advisory, CISA Shares Lessons Learned from an Incident Response Engagement, highlights takeaways that illuminate the urgent need for timely patching, comprehensive incident response planning, and proactive threat monitoring to mitigate risks from similar vulnerabilities.
The advisory also outlines the tactics, techniques, and procedures (TTPs) employed by cyber threat actors, including exploitation of GeoServer Vulnerability CVE-2024-36401 for initial access. By understanding these TTPs, organizations can enhance their defenses against similar threats.
CISA recommends organizations take the following actions:
- Prioritize Patch Management: Expedite patching of critical vulnerabilities, particularly those listed in CISA’s Known Exploited Vulnerabilities catalog, with a focus on public-facing systems.
- Strengthen Incident Response Plans: Regularly update, test, and maintain incident response plans, ensuring they include procedures for engaging third-party responders and deploying security tools without delay.
- Enhance Threat Monitoring: Implement centralized, out-of-band logging and ensure security operations centers continuously monitor and investigate abnormal network activity to detect and respond to malicious activity effectively.
CISA urges organizations to apply these lessons learned to bolster their security posture, improve preparedness, and reduce the risk of future compromises. For additional details, review the full cybersecurity advisory.

Commission Communication to strengthen the resilience of critical entities across the EU adopted

On 11 September 2025, a Commission Communication to strengthen the resilience of critical entities across the EU was adopted. It provides non-binding guidance to EU countries to identify their critical entities and a risk assessment reporting template.

Directive (EU) 2022/2557 on the resilience of critical entities1 (‘the Directive’) aims to ensure that services essential for the maintenance of vital societal functions or economic activities are provided in an unobstructed manner in the internal market. The Directive enhances the resilience of the critical entities providing such services and creates an overarching framework of resilience of critical entities in respect of all hazards (natural and man-made, accidental or intentional).
To achieve a high level of resilience, Member States have obligations under the Directive. The Commission was mandated to develop recommendations, non-binding guidelines and a voluntary common reporting template to support them in fulfilling some of these obligations. Specifically, this Communication gives effect to Article 5(5) of the Directive regarding the development of a template for the provision of certain information to the Commission, to Article 6(6) of the Directive regarding the development of recommendations and guidelines to support Member States in identifying critical entities, and to Article 7(3) of the Directive regarding the adoption of guidelines to facilitate the application of the criteria for determining the significance of a disruptive effect, taking into account the information that Member States must submit in accordance with Article 7(2) of the Directive.
Before the adoption of this Communication, in accordance with the aforementioned provisions, Member States were consulted in a workshop that took place on 3-4 October 2024 and the Critical Entities Resilience Group (CERG) was consulted on 12 February 2025. Further bilateral consultations of CERG delegates took place in writing in March 2025 and an updated version was shared with the CERG on 7 April 2025.
The present Communication is not legally binding and does not affect the interpretation of EU law by the Court of Justice of the European Union.
The voluntary common reporting template for Member States to provide certain information related to the risk assessment to the Commission, as provided for in Article 5(5) of the Directive, is set out in the Annex.
Although this reporting template is voluntary in nature, Member States are encouraged to use it when providing information pursuant to Article 5(4) of the Directive.
Further details can be found in the 'Commission Guidelines and reporting template developed pursuant to Articles 5(5), 6(6) and 7(3) of Directive (EU) 2022/2557 on the resilience of critical entities'.

The latest issue of Critical Infrastructure Protection & Resilience News has arrived

Download your copy now at www.cip-association.org/CIPRNews
Please find here your downloadable copy of the Summer 2025 issue of Critical Infrastructure Protection & Resilience News, the official magazine of the International Association of CIP Professionals (IACIPP), for the latest views, features and news, including a Preview of the forthcoming Critical Infrastructure Protection & Resilience Europe conference, taking place in Brindisi, Italy next month as part of CIP Week in Europe, and co-hosted with The International Emergency Management Society (TIEMS) conference.
Critical Infrastructure Protection & Resilience News in this issue:
- Building Ukraine’s Shield: The Bold New Effort to Train Critical Infrastructure Security Professionals
- Critical Infrastructure Security Doesn’t Have Time for False Alarms as the Airspace Gets Busier with Drones
- The Drones Revolution and Its Implications for Modern Ground Warfare with Special Focus on Critical Infrastructure Protection & Resilience
- E-GIANTS Project Concludes Study on GNSS Authentication and Security Improvements
- Digital twins: The new pillar of critical infrastructure security
- Legal and Regulatory aspects relating to the physical security of the telecommunications infrastructure used for critical communication services
- Celebrating 10 years of IACIPP
- Preview of Critical Infrastructure Protection & Resilience Europe
- Securing the Backbone of Society: How to Protect Critical Network Infrastructure
- Closing the Gaps in Insider Threat Mitigation
- Zero Trust IEEE Standard: In Progress
- Expert interview with the European Utilities Telecom Council (EUTC)
- Agency News
- Industry News
Download your copy at www.cip-association.org/CIPRNews
#criticalinfrastructureprotection #criticalinfrastructure #resilience #cybersecurity #emergencymanagement #riskmitigation #portsecurity #homelandsecurity #firstresponder #riskmanagement #ai #artificalintelligence #energysecurity #gridresilience

Standards Australia adopts world’s foremost standard for operational technology

Australia has officially adopted the AS IEC 62443 series as national standards for protecting Operational Technology (OT) in critical infrastructure from cyber threats. This decision comes as cyberattacks grow more frequent and sophisticated, increasingly targeting the systems that support our daily lives.
OT systems are the backbone of essential services such as energy, water, transport, medical devices, and building automation. A successful cyberattack on these systems could disrupt communities, threaten public safety, and harm the environment. The AS IEC 62443 standards help prevent this by offering a clear, structured approach to cybersecurity that supports safety, reliability, and resilience throughout the life of these systems.
A Practical Framework for Securing OT Systems
OT environments face unique cybersecurity challenges that differ from traditional IT systems. To address these, specialised standards were developed for Industrial Automation and Control Systems (IACS). In response, the IEC/Technical Committee 65 Industrial-process measurement, control and automation developed the IEC 62443 series – Security for industrial automation and control systems. These standards are now recognised in Australia as AS IEC 62443, with the support and contributions from our national committee IT-006.
These standards are modular and role-based, allowing users to select only the parts relevant to their responsibilities or the stage of the system lifecycle they’re working in. They are designed for asset owners, service providers, and product suppliers, and they align with local regulatory requirements—making implementation practical and effective across sectors.
The benefits of adopting AS IEC 62443 are wide-reaching:
- Protects public health by helping to reduce the risk of system failures caused by cyberattacks
- Supports social stability by safeguarding the essential services communities rely on
- Boosts economic opportunities by allowing consumers to safely participate in energy markets, such as selling power back to the grid
- Reduces reputational risk by minimising the chance of prolonged outages and public fallout for organisations managing critical infrastructure
The IEC continues to evolve these standards to meet the needs of emerging technologies and smart systems. A new addition – Part 1-6 – will address the application of the series to the Industrial Internet of Things, further supporting the safety, reliability, and performance of smart energy, smart manufacturing, and smart cities.
By adopting AS IEC 62443, Australia is taking a proactive step to ensure its critical infrastructure is secure, resilient, and ready for the future.

Thorium Platform Public Availability

CISA, in partnership with Sandia National Laboratories, announced the public availability of Thorium, a scalable and distributed platform for automated file analysis and result aggregation. Thorium enhances cybersecurity teams' capabilities by automating analysis workflows through seamless integration of commercial, open-source, and custom tools. It supports various mission functions, including software analysis, digital forensics, and incident response, allowing analysts to efficiently assess complex malware threats.
Thorium enables teams that frequently analyze files to achieve scalable automation and results indexing within a unified platform. Analysts can integrate command-line tools as Docker images, filter results using tags and full-text search, and manage access with strict group-based permissions.
Designed to scale with hardware using Kubernetes and ScyllaDB, Thorium can ingest over 10 million files per hour per permission group while maintaining rapid query performance. It also allows users to define event triggers and tool execution sequences, control the platform via RESTful API, and aggregate outputs for further analysis or integration with downstream processes.
CISA encourages cybersecurity teams to use Thorium and provide feedback to enhance its capabilities. For more information on Thorium and how it can improve your cybersecurity operations, see CISA’s Thorium resource webpage.

CISA and USCG Issue Joint Advisory to Strengthen Cyber Hygiene in Critical Infrastructure

CISA, in partnership with the U.S. Coast Guard (USCG), released a joint Cybersecurity Advisory aimed at helping critical infrastructure organizations improve their cyber hygiene. This follows a proactive threat hunt engagement conducted at a U.S. critical infrastructure facility.
During this engagement, CISA and USCG did not find evidence of malicious cyber activity or actor presence on the organization’s network but did identify several cybersecurity risks. CISA and USCG are sharing their findings and associated mitigations to assist other critical infrastructure organizations identify potential similar issues and take proactive measures to improve their cybersecurity posture. The mitigations include best practices such as not storing passwords or credentials in plaintext, avoiding sharing local administrator account credentials, and implementing comprehensive logging.
In coordination with the organization where the hunt was conducted, CISA and USCG are sharing cybersecurity risk findings and associated mitigations to assist other critical infrastructure organizations with improving their cybersecurity posture. Recommendations are listed for each of CISA’s findings, as well as general practices to strengthen cybersecurity for OT environments. These mitigations align with CISA and the National Institute for Standards and Technology’s (NIST) Cross-Sector Cybersecurity Performance Goals (CPGs), and with mitigations provided in the USCG Cyber Command’s (CGCYBER) 2024 Cyber Trends and Insights in the Marine Environment (CTIME) Report.
Although no malicious activity was identified during this engagement, critical infrastructure organizations are advised to review and implement the mitigations listed in this advisory to prevent potential compromises and better protect our national infrastructure. These mitigations include the following (listed in order of importance):
- Do not store passwords or credentials in plaintext. Instead, use secure password and credential management solutions such as encrypted password vaults, managed service accounts, or built-in secure features of deployment tools.
- Ensure that all credentials are encrypted both at rest and in transit. Implement strict access controls and regular audits to securely manage scripts or tools accessing credentials.
- Use code reviews and automated scanning tools to detect and eliminate any instances of plaintext credentials on hosts or workstations.
- Enforce the principle of least privilege, only granting users and processes the access necessary to perform their functions.
- Avoid sharing local administrator account credentials. Instead, provision unique, complex passwords for each account using tools like Microsoft’s Local Administrator Password Solution (LAPS) that automate password management and rotation.
- Enforce multifactor authentication (MFA) for all administrative access, including local and domain accounts, and for remote access methods such as Remote Desktop Protocol (RDP) and virtual private network (VPN) connections.
- Implement and enforce strict policies to only use hardened bastion hosts isolated from IT networks equipped with phishing-resistant MFA to access industrial control systems (ICS)/OT networks, and ensure regular workstations (i.e., workstations used for accessing IT networks and applications) cannot be used to access ICS/OT networks.
- Implement comprehensive (i.e., large coverage) and detailed logging across all systems, including workstations, servers, network devices, and security appliances.
- Ensure logs capture information such as authentication attempts, command-line executions with arguments, and network connections.
- Retain logs for an appropriate period to enable thorough historical analysis (adhering to organizational policies and compliance requirements) and aggregate logs in an out-of-band, centralized location, such as a security information event management (SIEM) tool, to protect them from tampering and facilitate efficient analysis.

CISA and Partners Release Updated Advisory on Scattered Spider Group

CISA, along with the Federal Bureau of Investigation, Canadian Centre for Cyber Security, Royal Canadian Mounted Police, the Australian Cyber Security Centre’s Australian Signals Directorate, and the Australian Federal Police and National Cyber Security Centre, released an updated joint Cybersecurity Advisory on Scattered Spider—a cybercriminal group targeting commercial facilities sectors and subsectors. This advisory provides updated tactics, techniques, and procedures (TTPs) obtained through FBI investigations conducted through June 2025.
Scattered Spider threat actors have been known to use various ransomware variants in data extortion attacks, most recently including DragonForce ransomware. While Scattered Spider often changes TTPs to remain undetected, some TTPs remain consistent. These actors frequently use social engineering techniques such as phishing, push bombing, and subscriber identity module swap attacks to obtain credentials, install remote access tools, and bypass multi-factor authentication.
The Mitigations section of the Scattered Spider joint Cybersecurity Advisory offers critical infrastructure organizations and commercial facilities recommendations to fortify their defenses.
1 4 5 6 7 8 63