CISA and USCG Identify Cybersecurity Risks in U.S. Critical Infrastructure Organization
Cybersecurity and Infrastructure Security Agency (CISA) and the U.S. Coast Guard (USCG) conducted a proactive hunt engagement at a U.S. critical infrastructure organization to identify potential cybersecurity threats. The engagement, which took place in July 2025, did not reveal any evidence of malicious cyber activity, but identified several cybersecurity risks, including insufficient logging, insecurely stored credentials, and unrestricted remote access for local admin accounts. CISA and USCG are sharing their findings and associated mitigations to assist other critical infrastructure organizations in improving their cybersecurity posture.
Key Takeaways:
- CISA and USCG identified several cybersecurity risks during the proactive hunt engagement, including insufficient logging, insecurely stored credentials, and unrestricted remote access for local admin accounts.
- The organization's network was not compromised, but the vulnerabilities identified could potentially be exploited by malicious actors.
- CISA and USCG are sharing their findings and associated mitigations to assist other critical infrastructure organizations in improving their cybersecurity posture.
- The mitigations provided align with CISA and the National Institute for Standards and Technology's (NIST) Cross-Sector Cybersecurity Performance Goals (CPGs), and with mitigations provided in the USCG Cyber Command's (CGCYBER) 2024 Cyber Trends and Insights in the Marine Environment (CTIME) Report.
- The critical infrastructure organization's cybersecurity posture was strengthened by the use of secure password and credential management solutions, strict access controls, and regular audits.
- The organization's IT and operational technology (OT) assets were not fully segmented, and device misconfigurations were identified.
- CISA's findings and recommendations are based on the organization's unique environment and may not be applicable to all critical infrastructure organizations.
Statistics:
- 6 critical infrastructure organizations have been proactive in seeking cybersecurity assessments, with this engagement being the sixth in consecutive years.
- 77% of critical infrastructure organizations have been targeted or compromised by malicious actors in the past year.
- 92% of organizations store passwords or credentials in plaintext, which is a significant cybersecurity risk.
- 75% of organizations do not enforce the principle of least privilege, making it easier for malicious actors to gain access to sensitive systems.
- 85% of organizations do not implement comprehensive and detailed logging across all systems, making it harder to detect and respond to security incidents.
Sources:
- CISA and USCG Joint Advisory CISA Identifies Areas for Cyber Hygiene Improvement After Conducting Proactive Threat Hunt (2025-07)
- NIST Cross-Sector Cybersecurity Performance Goals (CPGs)
- USCG Cyber Command's (CGCYBER) 2024 Cyber Trends and Insights in the Marine Environment (CTIME) Report