3 Key Takeaways for your Business from the CISA Cross-Sector Cybersecurity Performance Goals

August 22, 2024

3 Key Takeaways for your Business from the CISA Cross-Sector Cybersecurity Performance Goals

 The CISA (Cybersecurity and Infrastructure Security Agency) has released its cross-sector Cybersecurity Performance Goals (CPGs), outlining the key areas that small and medium businesses need to focus on in order to secure their networks and data from hostile actors. These goals are intended to provide guidance for businesses looking to protect themselves from cyber threats and should be taken into consideration when developing and implementing cybersecurity strategies. Cyberattacks have been ramping up in scale and frequency, making defense more important than ever before.

One of the key goals outlined by CISA is the need for businesses to implement strong and effective identity and access management controls. This includes using multi-factor authentication to protect against unauthorized access and implementing strict policies for password management. A password manager is a good option if you have a lot of passwords, (we all do) but make sure you pick one with a good historical record. LastPass recently experienced a breach which we outlined in our last cybersecurity wrap up, so our current recommendation is 1Password. 

Another important goal is the need for businesses to regularly assess and prioritize their cybersecurity risks. This includes identifying and addressing vulnerabilities in systems and networks and implementing robust incident response plans to ensure that any potential breaches are quickly and effectively dealt with. A Security Operations Center is a good fit for running penetration tests and vulnerability scans, which our team can provide you with if your current IT team is overloaded.

CISA also emphasizes the importance of training and educating employees on cybersecurity best practices. This includes providing regular training on how to identify and avoid potential threats, as well as promoting a culture of security within the organization. In addition to cybersecurity training, iTecs can run phishing simulation tests to teach your staff the importance of email security. 

The CPGs provide a valuable roadmap for businesses looking to secure their networks and data from hostile actors. By implementing strong identity and access management controls, regularly assessing and prioritizing risks, and educating employees on cybersecurity best practices, businesses can significantly reduce their exposure to cyber threats and ensure the protection of their critical assets. These guidelines are meant to serve as a baseline and are therefore not comprehensive; a sophisticated attacker can work their way around them. That's where Managed Service Providers like iTecs can help. The CPGs are a wonderful foundation for your cybersecurity but without a dedicated team of professionals that keep up to date on the latest threats, you're still vulnerable to a breach.

iTecs offers customized solutions for your business that are tailored around the best practices for your industry. We have a large roster of clients from a variety of different trades that all agree we have given them the highest level of IT support and cybersecurity possible. Talk to one of our professionals today and secure your network tomorrow.

Latest posts

How to Deploy Self-Hosting DeepSeek-R1 Using Ollama Implementation Guide
April 19, 2025

How to Deploy Self-Hosting DeepSeek-R1 Using Ollama Implementation Guide

Our Self-Hosting DeepSeek-R1 Using Ollama guide provides organizations with a comprehensive technical roadmap for deploying AI models within their own infrastructure. From hardware selection and installation to performance optimization and security hardening, this guide covers the complete implementation process with expert insights at each critical phase. Learn how to select appropriate model sizes based on your hardware capabilities, implement web interfaces for user access, and properly secure your AI deployment. This guide demonstrates how organizations can leverage powerful AI capabilities while maintaining complete data privacy and control.
Shutup10 Privacy Settings Tool
April 14, 2025

Shutup10 Privacy Settings Tool

Anyone who has configured a new installation of Windows 10 has seen there are a large amount of privacy, location and performance settings in the operating system. The sheer amount of selections available to adjust can be discouraging to even an experienced IT professional. Considering the multitude of options available it can be difficult, if almost impossible, to find them again later on - much less to remember them all! Enter O&O Software’s humorously named O&O ShutUp10.
Scam robocalls pretending to be Apple
April 14, 2025

Scam robocalls pretending to be Apple

We've received reports that customers are receiving calls from a company claiming to be Apple informing them that their Apple ID has been compromised. The culprits are calling random numbers, mainly in the United States. If you follow their prompts to "secure your account" you'll be transferred to a call center in India who will then try to get as much personal information from you as possible; they will try to get your credit card information to charge a fee to secure the compromised account.