
WASHINGTON — A comprehensive interagency progress assessment reveals that small and medium-sized critical infrastructure operators have achieved substantial improvements in baseline cyber hygiene by adopting CISA’s Cross-Sector Cybersecurity Performance Goals.
WASHINGTON — Two years after the Cybersecurity and Infrastructure Security Agency released its Cross-Sector Cybersecurity Performance Goals (CPGs), a joint evaluation conducted by CISA and sector risk management agencies indicates that over 65 percent of surveyed small and medium-sized utility operators have implemented the baseline defensive controls.
Unlike sprawling, highly theoretical compliance frameworks like the NIST Cybersecurity Framework, which can overwhelm smaller municipal water authorities or rural electric cooperatives with hundreds of pages of controls, the CPGs were intentionally distilled into a prioritized set of 38 high-impact, actionable practices designed specifically to defeat the most common tactics, techniques, and procedures (TTPs) employed by ransomware crews and nation-state hackers.
Measurable Declines in Initial Compromise Vectors
The federal review highlighted dramatic defensive progress in three foundational areas:
- Eliminating Default Credentials: Over 82 percent of participating operators reported eradicating manufacturer-default administrative passwords across all public-facing industrial control and SCADA equipment.
- Universal Multi-Factor Authentication: A 74 percent increase in the adoption of multi-factor authentication for remote maintenance and engineering access portals.
- Basic Incident Response Exercising: More than 60 percent of small infrastructure operators conducted annual tabletop cyber incident response exercises with local emergency management and FBI field offices.
Tackling the Resource Divide in Rural Utilities
While the adoption rate among mid-tier organizations is encouraging, the evaluation revealed a persistent “cyber resource divide” among small, underfunded municipal entities. Hundreds of rural water treatment districts and regional agricultural cooperatives operate without a single dedicated IT security professional, relying on part-time contractors or legacy equipment that cannot support modern encryption protocols.
To bridge this gap, CISA confirmed that it will expand its State and Local Cybersecurity Grant Program, channeling federal funds directly into subsidized endpoint detection and automated vulnerability scanning services for resource-constrained operators. “Cybersecurity cannot be a luxury good reserved for Fortune 500 banks,” said CISA Director Jen Easterly. “The resilience of our nation is only as strong as our smallest, most vulnerable utility.”