The FBI has launched a two-month campaign, Operation Winter SHIELD (Securing Homeland Infrastructure by Enhancing Layered Defense), highlighting 10 actions organizations can use to protect against cyberattacks. The recommendations were developed with domestic and international partners and based on recent cyber investigations to reflect adversary behavior and defensive gaps. The recommendations include adopting phish-resistant authentication, implementing a risk-based vulnerability management program, tracking and retiring end-of-life technology on a defined schedule, and managing third-party risk, among others.

“Operation Winter SHIELD is based on lessons learned from the most significant nation state and criminal cyber investigations,” said John Riggi, AHA national advisor for cybersecurity and risk. “In sum, agencies involved focused on the most common methodologies threat actors are using to ‘beat us,’ and what cyber defensive measures are the most effective at reducing cyber risk and increasing resiliency and recovery. There is nothing surprising on the list, but the landmark campaign serves as an excellent validation and a concise summary of cybersecurity best practices. Operation Winter SHIELD also acknowledges the private sector’s crucial role in defending the nation’s critical infrastructure against the very real and very serious cyber threats we face as a nation.”

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

Related News Articles

Headline
Two AHA guides offer strategies for hospitals and health systems in preparing for public health emergencies and disasters and managing cybersecurity incidents…
Headline
Larry Pierce, director of cybersecurity and information security officer for Atlantic Health, unpacks how the growth of artificial intelligence is reshaping…
Headline
U.S. and international agencies Jan. 14 released guidance on secure connectivity for operational technology environments. Examples of OT environments in health…
Headline
The AHA Jan. 14 expressed support for the Rural Hospital Cybersecurity Enhancement Act (S. 2169), legislation that would direct the Department of Health and…
Headline
The FBI Jan. 8 released an alert on evolving threat tactics by Kimsuky, a North Korean state-sponsored cyber threat group. As of last year, the group…
Headline
The Cybersecurity and Infrastructure Security Agency Dec. 11 released an update to its voluntary Cybersecurity Performance Goals, which includes measurable…