As the Nation’s Cyber Defense Agency, the Cybersecurity and Infrastructure Security Agency (CISA) sees how our nation’s adversaries operate and what tools they use. While some of these adversaries use advanced tools and techniques, most take advantage of unpatched vulnerabilities, poor cyber hygiene or the failure of organizations to implement critical technologies like MFA. Sadly, too few organizations learn how valuable MFA is until they experience a breach.
Since joining CISA, I’ve made it a priority to raise MFA awareness across all sectors to better protect our nation’s critical infrastructure. Importantly, we need more and better data to understand the scope of, and solutions to, the threats we face in cyber, and we’ve called on our industry partners to provide radical transparency to allow our defenders to better see, understand and ultimately protect our citizens, customers and companies. In particular, it’s critical that “high-value targets” like system administrators and Software as a Service (SaaS) staff use phishing-resistant MFA.
But more and better information is just the beginning.
Working collaboratively, I look forward to seeing what we can do to together to make our nation more resilient, more secure, and to show measurable progress … including in next year’s Verizon Data Breach Investigations Report.