| 2026-07-15 |
Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers
This guidance outlines best practices for suppliers to design and implement a coordinated vulnerability disclosure (CVD) program to effectively and transparently collaborate with security researchers to report and remediate vulnerabilities.
|
CISA
NCSC-UK
NSA
|
| 2026-01-14 |
Secure Connectivity Principles for Operational Technology
SSeeccuurree CCoonnnneeccttiivviittyy PPrriinncciipplleess ffoorr OOppeerraattiioonnaall TTeecchhnnoollooggyy ((OOTT)) Operational technology (OT) environments - which have long been centred on safety, uptime, and operational continuity - are now more interconnected than ever.
|
ASD/ACSC
BSI
CCCS
FBI
NCSC-NZ
NCSC-UK
|
| 2025-12-15 |
Principles for the Secure Integration of Artificial Intelligence in Operational Technology
CISA | ASD’s ACSC | NSA AISC | FBI | Cyber Centre | BSI | NCSC-NL | NCSC-NZ | NCSC-UK Introduction ................................................................................................................................................................... 3 Important Terminology ....................................................................................................................................... 3 Scope ...................
|
ASD/ACSC
BSI
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-11-19 |
Bulletproof Defense: Mitigating Risks from Bulletproof Hosting Providers
This document was developed through the Joint Ransomware Task Force (JRTF), a U.S. interagency body established by Congress in the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to ensure unity of effort in combating the growing threat of ransomware attacks.
|
ASD/ACSC
CCCS
CISA
DC3
FBI
NCSC-NZ
NCSC-UK
NSA
|
| 2025-11-13 |
#StopRansomware: Akira Ransomware
#StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Prioritize remediating known exploited vulnerabilities. Enable and enforce phishing-resistant multifactor authentication (MFA).
|
CISA
DC3
EC3
FBI
HHS
|
| 2025-09-29 |
Creating and Maintaining a Definitive View of Your Operational Technology (OT) Architecture
It is aimed at cyber security professionals working in organisations that deploy or operate OT across greenfield and brownfield deployments. Integrators and device manufactures can also use these principles to ensure their solutions enable effective asset and configuration management.
|
ASD/ACSC
BSI
CCCS
CISA
FBI
NCSC-NZ
NCSC-UK
|
| 2025-09-03 |
Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity
Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components.
|
ANSSI
ASD/ACSC
BSI
CCCS
CISA
CSA
NCO
NCSC-NZ
NIS
NSA
NUKIB
|
| 2025-08-13 |
Foundations for OT Cybersecurity: Asset Inventory Guidance for Owners and Operators
Using these tools helps owners and operators identify which assets in their environment should be secured and protected, and structure their defenses accordingly to reduce the risk a cybersecurity incident poses to the organization’s mission and service continuity. An asset inventory is an organized, regularly updated list of an organization’s systems, hardware, and software.
|
ASD/ACSC
BSI
CCCS
CISA
DOE
EPA
FBI
NCSC-NZ
NSA
|
| 2025-01-13 |
Secure by Demand: Priority Considerations for Operational Technology Owners and Operators When Selecting Digital Products
Many OT products are not designed and developed with Secure by Design principles1 and commonly have weaknesses, such as weak authentication, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. Cyber threat actors can easily exploit these weaknesses across multiple victims to gain access to control systems.
|
ASD/ACSC
BSI
CCCS
CISA
EPA
FBI
NCSC-NZ
NCSC-UK
NSA
TSA
|
| 2024-04-18 |
CISA and Partners Release Advisory on Akira Ransomware
Today, CISA, the Federal Bureau of Investigation (FBI), Europol’s European Cybercrime Centre (EC3), and the Netherlands’ National Cyber Security Centre (NCSC-NL) released a joint Cybersecurity Advisory (CSA), #StopRansomware: Akira Ransomware , to disseminate known Akira ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as February 2024.
|
CISA
EC3
FBI
|
| 2024-04-18 |
#StopRansomware: Akira Ransomware
#StopRansomware: Akira Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Akira Prioritize remediating known exploited vulnerabilities. Enable and enforce phishing-resistant multifactor authentication (MFA).
|
CISA
DC3
EC3
FBI
HHS
OFAC
|