IndustrialCyber

CISA launches ‘Securing the Next 250’ campaign to strengthen critical infrastructure cybersecurity and resilience


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) launched its 2026 Cybersecurity Awareness Month campaign under the theme ‘Securing the Next 250,’ calling on individuals, organizations and communities to strengthen digital defenses as the United States looks toward its next era. CISA said the campaign recognizes the nation’s 250th anniversary and emphasizes the need to build a secure digital future, with a continued focus on organizations supporting critical infrastructure and essential services.

For critical infrastructure owners and operators, CISA is promoting the ‘3Rs of Cybersecurity,’ involving reduce, replace and recover, as part of its awareness effort. The agency also recommends that organizations use logging, back up and encrypt data, report cyber incidents to CISA, maintain and exercise incident response plans, and prepare for system disruptions. The campaign also highlights four core steps for individuals: avoiding and reporting phishing scams, using strong passwords, enabling multifactor authentication and password managers, and keeping software updated. 

“Whenever critical infrastructure is disrupted, so are the businesses and communities that depend on vital services,” said Nick Andersen, CISA’s acting director in a media statement. “That’s why CISA is prioritizing the security and resilience of critical infrastructure, and state, local, tribal, and territorial government (SLTT), whose systems and services sustain us every day. This includes things like clean water, secure transportation, quality healthcare, secure financial transactions, rapid communications, and more. However great or small—every organization that touches critical infrastructure is vital to ensuring uninterrupted services to America’s communities.” 

Four practices are foundational and should be as automatic as buckling a seatbelt. Employees should be taught to avoid phishing scams, since recognizing and reporting suspicious emails and links may prevent cyber intrusions. Strong passwords should be required, because long, random, and unique passwords make accounts harder to breach. Multifactor authentication should also be required, as it adds an extra layer of protection if a password is compromised. Software should be kept updated so that systems remain protected against known vulnerabilities.

Organizations can take further steps to level up their defenses. Logging activity on systems allows teams to monitor signs that threat actors may be trying to gain access, and organizations should learn how to monitor key information to protect the business. Backing up data makes recovery faster and less stressful when incidents happen, so a backup plan should be put in place that aligns with the organization’s recovery point objective. 

Encrypting data and devices strengthens defenses against attacks, because information stays locked and unreadable even if criminals gain access to files, which makes encryption a worthwhile part of any security strategy. Government entities, including SLTT governments, can obtain a [dot]gov domain for additional security. 

Cyber incidents should be reported to CISA at cisa.gov/report.

Organizations should also have an incident response plan and put it to use. They should develop, maintain, update, and regularly exercise response plans for common threat scenarios such as ransomware attacks. Drills should be realistic and include all relevant stakeholders, such as organizational leadership and legal counsel, in addition to technical personnel, and plans should be reviewed and drilled at least once a year. 

Also, organizations should likewise be prepared for system disruptions by developing and executing plans to recover and restore service to critical assets or systems that a cybersecurity incident might affect. These plans should consider the ability to carry out mission-essential functions without access to critical assets or even the internet, for example by shifting to paper-based operations or radio communications.

Owners and operators of critical infrastructure are further encouraged to practice the 3Rs of Cybersecurity: Reduce, Replace, and Recover. The first is to reduce attack surfaces, the second is to replace end-of-support devices, and the third is to recover quickly to sustain operations.

Commenting on Cybersecurity Awareness Month, Rafael Narezzi, co-founder and CEO at Centrii, wrote in an emailed statement that for years, cybersecurity awareness has largely been framed around what employees should do differently – recognise phishing attempts, strengthen passwords and avoid suspicious links. Those habits still matter, but today’s threat environment requires a much broader definition of awareness.

“In critical infrastructure, cyber risk is operational risk. A compromised battery storage system, renewable energy site or remote-access connection may not produce the warning signs of a conventional data breach,” Narezzi identified. “Instead, the consequences can appear as lost generation, unstable operations, reduced availability and direct financial loss. As energy infrastructure becomes more distributed and interconnected, organisations need visibility not only into their own environments, but also into the vendors and technologies on which their operations depend.”

He added that organisations have too many alerts and too little context. Leaders must be able to determine which exposures could disrupt operations, how much capacity or revenue is at risk and which action will reduce that risk first.

“This Cybersecurity Awareness Month, we should move beyond treating awareness as an annual training exercise,” Narezzi said. “True cyber resilience requires continuous asset visibility, carefully controlled access, clear supply-chain accountability and incident-response plans that are regularly tested. People should not simply be labelled the weakest link; they should be equipped to become an active layer of defence. Cybersecurity becomes meaningful when everyone – from operators and engineers to executives and boards – understands both their role and the real-world consequences of inaction.”

Ram Varadarajan, CEO at Acalvio, wrote in an emailed statement that “Cybersecurity Awareness Month tends to focus on the moment of compromise – the phishing email, the weak password, the unpatched system. But less attention is given to what happens after an attacker is already inside, which is where the real damage is done.” 

He added that “Reconnaissance is a search for confidence. A configuration file may point to a database, a directory query turns up a server that looks worth examining, and gradually an attacker pieces together a route toward systems that matter. From even a limited foothold, an attacker can assemble a working map of the environment: which systems appear connected, where credentials might work, and which path seems worth testing next. AI is changing the pace of that work. It can help an attacker interpret query results, select another system to probe, and continue with less human direction, shortening the time between each discovery and the next action.”

“Cybersecurity Awareness Month 2026 comes with a long-term challenge,” Agnidipta Sarkar, chief evangelist at ColorTokens, wrote in an emailed statement. “CISA’s theme, ‘Securing the Next 250,’ asks how we secure the digital systems and critical infrastructure the next era will depend on. For boards, that goes beyond awareness to whether the enterprise is built to withstand an attack. AI now finds weaknesses, writes the exploit, and moves through a network faster than most security teams can open a ticket.”



Source link