October is Cybersecurity Awareness Month, a global effort to promote online safety and digital security. Launched in 2024 by the National Cybersecurity Alliance and the Cybersecurity and Infrastructure Security Agency (CISA), the aim is to teach individuals and organizations practical steps to improve resilience to cyber threats. The general theme this year is Don’t Make It Easy for Them , which focuses on everyday digital safety habits that everyone should adopt to improve online safety and security, such as using strong, unique passwords, implementing multifactor authentication (MFA), learning to recognize and avoid phishing, and keeping operating systems, software, applications, and devices up to date.
A dual theme of this year’s Cybersecurity Awareness Month is strengthening critical infrastructure cybersecurity. Securing the nation’s critical infrastructure is a top national security priority under the White House March 2026 Cyber Strategy for America. As the United States celebrates the semiquincentennial anniversary of the nation’s founding, a rallying cry has been issued to future-proof the nation’s critical infrastructure and secure it for the next 250 years.
Critical infrastructure relies heavily on internet-connected systems and devices. Internet access improves efficiency, but it also introduces risks, as Internet-exposed systems, software, and devices can potentially be remotely attacked by cybercriminal actors, hacktivists, and hostile nation-states. Financially motivated criminal threat actors attack vulnerable systems and hold systems and data to ransom; hacktivists may target critical infrastructure in response to governmental policies; and nation-state actors steal intellectual property to accelerate their own economic growth and technological dominance, and conduct destructive attacks to further their nations’ political priorities.
Critical infrastructure owners and operators need to defend against these attacks and ensure they can recover quickly should an attack succeed. The 3Rs of Cybersecurity – Reduce, Replace, Recover This Cybersecurity Awareness Month, critical infrastructure owners and operators have been requested to practice the 3Rs of cybersecurity – Reduce, Replace, Recover – to improve cyber resilience.
Critical infrastructure should improve their efforts to reduce the attack surface by ensuring that systems are kept up to date, patches are applied promptly, and obsolete software and devices are upgraded or replaced before they reach end of life. Plans also need to be developed, implemented, maintained, and practiced to ensure operations can be sustained in the event of a cyber incident and that they can recover quickly from a successful attack.
Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy While the threat landscape is constantly evolving, CISA points out that it isn’t fundamentally changing; rather, it is scaling.
Threat actors constantly search for vulnerabilities to exploit, as has been the case for many years; however, vulnerabilities are being discovered in record numbers. Total published Common Vulnerabilities and Exposures (CVE) this year exceeded last year’s total by the end of August 2026. Artificial intelligence is accelerating the discovery of software vulnerabilities and is helping threat actors to exploit vulnerabilities far more quickly, including mass exploitation through automation.
Since defenders can easily get overwhelmed with the sheer number of vulnerabilities that require remediation, the key approach is to patch smarter, not harder . Vulnerabilities need to be assessed, and remediation efforts prioritized, ensuring that the most critical vulnerabilities are addressed first, such as those listed in the Known Exploited Vulnerability (KEV) Catalog.
When software and devices reach end-of-life, security updates and patches come to an end. Continued use of end-of-life software and devices presents threat actors with opportunities to exploit unaddressed vulnerabilities to gain access to networks and sensitive data. Critical infrastructure owners and operators need to know when support will end for their software and devices and plan to upgrade or replace software, firmware, and hardware devices before support comes to an end.
This is especially important for any technology devices or software on the boundary of the network that are accessible from the public internet. Guidance on mitigating risk for end-of-life software and devices is available in BOD 26-02 . It is essential that operations can be sustained in the event of a cyber incident and that a rapid and full recovery is possible.
Critical infrastructure owners and operators need to fortify their systems and invest in isolation and recovery capabilities. Vital systems must be isolated from harm and must be capable of continuing to operate in an isolated state, while compromised systems are recovered. CI Fortify is an allied initiative designed to ensure that critical infrastructure entities can continue to operate in the event of geopolitical cyber conflict, through the implementation of resilient OT environments capable of surviving extended isolation and cyber compromise.
All Businesses Should Take Steps to Improve Their Security Posture Critical infrastructure is supported by a diverse range of businesses, and vendors in the supply chain that are directly or indirectly involved with critical infrastructure are often targeted by threat actors, as they are often a weak link in the security chain.
Originally published at hipaajournal.com


