Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Making sense of federal cybersecurity critical infrastructure guidance

Four steps to take now to establish a minimum level of cybersecurity posture

By Derek Kernus
compliance-freepik1170x658.jpg
February 2, 2022

The breaches continue despite heightened cybersecurity awareness. To help establish standards, the Cybersecurity and Infrastructure Security Agency (CISA) has issued best practices around nine cybersecurity goals for control systems in response to a July 2021 Presidential Memorandum. 


The CISA guidelines establish a minimum level of cybersecurity posture across 16 sectors, many of which include private businesses, whose critical infrastructure supports national defense; critical lifeline sectors (i.e., energy, communications, transportation, and water); or where the failure of control systems could have impacts to safety. 


Let’s unpack what’s involved in the CISA guidelines, who should be paying attention, and the steps your company may need to take now.


Setting a cybersecurity baseline

The CISA guidelines are baseline objectives — the minimum cybersecurity practices that should reasonably be in place for all businesses connected to the government. The requirements were developed from standards and controls already released by CISA and the National Institute of Standards (NIST). They are not as thorough as those controls required by other new government cybersecurity frameworks like the Cybersecurity Maturity Model Certification (CMMC) and the finalized CISA controls that will be released later this year. Instead, companies should view them as the compliance framework that any client would want to see in a SOC2 Type 2 report. 


CISA’s goals and objectives will become controls in the future. There’s nothing new or surprising in the list of best practices, and it’s certainly not an exhaustive list or the only cybersecurity measures that US companies should have in place. That said, setting a cybersecurity baseline is an important step. Just like the requirements for public health and safety that keep the public safe, these guidelines task critical infrastructure owners and operators to protect national and economic security.


Sage advice for small and mid-sized businesses

While the CISA guidelines are intended for organizations that potentially impact critical U.S. infrastructure, they are also a prescription for all small and mid-sized U.S. businesses. Meeting cybersecurity standards help protect the businesses’ data and ability to operate, the U.S. economy, as well as personal investments.


The guidelines define what must be done while leaving flexibility for how businesses achieve it. They offer best practice advice, like using hybrid cloud tools while hosting data locally to boost security cost-effectively. For the technical aspects, an IT consultant can suggest different options based on a company’s existing structure and systems, allowing them to plan and budget. Importantly, nearly half of the guidelines are not technical, so businesses can begin implementing them independently or use the guidelines as a checklist to see what more they need to be doing. 


This is the moment: Four steps to take now

Arguably there’s never been a time when cybersecurity is more important to U.S. businesses. Prioritizing and starting now is important for several business-minded reasons:


  1. Cybersecurity is a change management process. It takes time to turn a ship, especially onboarding people and devices. Implementing tougher cybersecurity is often easier in brand new companies where policies are established from the very start. Asking people to change — even for tasks as simple as how they log in to email or shared folders — requires communication, training, and a period of adjustment. 
  2. Sooner equals better. The security best practices outlined by CISA reduce the risk of a ransomware attack. Many small business owners think they are too small to be a target, but they are wrong. Bad actors hack into a small business because they are often less protected. They aren’t looking to make money or steal data, rather they use the small business as a testbed to work out the kinks in ransomware and plan for larger, more sophisticated attacks. This exact scenario led to the ransomware attack on the City of Atlanta. Investigators traced the roots of the attack back to small businesses in New Jersey, then a small town in Arizona, then the Colorado Department of Transportation, and then eventually to Atlanta. 
  3. Sooner equals cheaper. The cost of ever-evolving cyber protection will continue to increase, so meeting minimum standards now means many companies will be able to update rather than overhaul. It’s also important when technical controls and license costs are based on company headcount or the number of devices. It’s less costly to get compliant before you grow. If technical controls and operational processes are established when smaller, it becomes the way when you grow. New user accounts and new hardware assets will be configured with the security protocols at the start, and the processes will be the only ones employees have known. This will result in less time and money spent modifying existing assets and going through the change management process with staff.
  4. Future-proofing. In time, customers and clients will start looking at cybersecurity like they do a company’s credit score — writing requirements into RFPs and contracts. Meeting standards, like the CISA guidelines, ahead of the pack can be a competitive advantage and sets companies up to make more strategic investments and decisions about cybersecurity rather than being reactionary.


Looking at the CISA guidelines from an implementation perspective, there isn’t anything too challenging or scary for most businesses. Training and awareness, and incident response and recovery, are goals that might require time. The planning, testing and integration to support these goals will undoubtedly be more consuming for businesses than implementing the technical configurations and logical controls, which can be completed by a consultant in a few weeks or months. 


Importantly, business owners need to understand that meeting cybersecurity standards doesn’t mean a huge financial outlay or hiring experts. Many options exist for tools and as-needed consultant expertise that keep costs down for policies and procedures, remediation, automation technologies and more.  


The CISA guidelines signal that the Federal government, traditionally behind the industry, is serious about cybersecurity standards. Now is the time for businesses to get primed and ready to respond and pull their weight to contribute to a more secure environment for all.

KEYWORDS: CISA compliance tools cyber security risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Derek Kernus is the director of cybersecurity operations at DTS and holds CISSP, CCSP and CMMC RP certifications. 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Photograph of apartment complex patios

Enhancing Residential Building Security

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Patient in bed

When Cyberattacks Hit Medical Devices, Patients Pay the Price

Events

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • cyberattack-ddos-freepik1170x658.jpg

    Making sense of the muddled mess of cybersecurity terms

    See More
  • Making Sense of Data Privacy CLAUSES

    See More
  • network-scan

    Making Sense of Security Testing: Scanning and Penetrating Networks and Applications

    See More

Related Products

See More Products
  • 9780367259044.jpg

    Understanding Homeland Security: Foundations of Security Policy

  • 9780128147948.jpg

    Effective Security Management, 7th Edition

  • 9780367221942.jpg

    From Visual Surveillance to Internet of Things: Technology and Applications

See More Products

Events

View AllSubmit An Event
  • August 25, 2026

    Critical Infrastructure Security Is National Security: Protecting Essential Operations in an Era of Escalating Risk

    ON DEMAND: Learn why critical infrastructure security has become a national security imperative, and the strategies organizations can adopt to improve visibility, collaboration, and response across their security operations.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing