NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Cybersecurity Awareness Month 2026: Critical Infrastructure Urged to Adopt Cybersecurity 3Rs

October is Cybersecurity Awareness Month, a global effort to promote online safety and digital security. Launched in 2024 by the National Cybersecurity Alliance and the Cybersecurity and Infrastructure Security Agency (CISA), the aim is to teach individuals and organizations practical steps to improve resilience to cyber threats. The general theme this year is Don’t Make It Easy for Them, which focuses on everyday digital safety habits that everyone should adopt to improve online safety and security, such as using strong, unique passwords, implementing multifactor authentication (MFA), learning to recognize and avoid phishing, and keeping operating systems, software, applications, and devices up to date.

A dual theme of this year’s Cybersecurity Awareness Month is strengthening critical infrastructure cybersecurity. Securing the nation’s critical infrastructure is a top national security priority under the White House March 2026 Cyber Strategy for America. As the United States celebrates the semiquincentennial anniversary of the nation’s founding, a rallying cry has been issued to future-proof the nation’s critical infrastructure and secure it for the next 250 years.

Critical infrastructure relies heavily on internet-connected systems and devices. Internet access improves efficiency, but it also introduces risks, as Internet-exposed systems, software, and devices can potentially be remotely attacked by cybercriminal actors, hacktivists, and hostile nation-states. Financially motivated criminal threat actors attack vulnerable systems and hold systems and data to ransom; hacktivists may target critical infrastructure in response to governmental policies; and nation-state actors steal intellectual property to accelerate their own economic growth and technological dominance, and conduct destructive attacks to further their nations’ political priorities. Critical infrastructure owners and operators need to defend against these attacks and ensure they can recover quickly should an attack succeed.

The 3Rs of Cybersecurity – Reduce, Replace, Recover

This Cybersecurity Awareness Month, critical infrastructure owners and operators have been requested to practice the 3Rs of cybersecurity – Reduce, Replace, Recover – to improve cyber resilience. Critical infrastructure should improve their efforts to reduce the attack surface by ensuring that systems are kept up to date, patches are applied promptly, and obsolete software and devices are upgraded or replaced before they reach end of life. Plans also need to be developed, implemented, maintained, and practiced to ensure operations can be sustained in the event of a cyber incident and that they can recover quickly from a successful attack.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

While the threat landscape is constantly evolving, CISA points out that it isn’t fundamentally changing; rather, it is scaling. Threat actors constantly search for vulnerabilities to exploit, as has been the case for many years; however, vulnerabilities are being discovered in record numbers. Total published Common Vulnerabilities and Exposures (CVE) this year exceeded last year’s total by the end of August 2026.

Artificial intelligence is accelerating the discovery of software vulnerabilities and is helping threat actors to exploit vulnerabilities far more quickly, including mass exploitation through automation. Since defenders can easily get overwhelmed with the sheer number of vulnerabilities that require remediation, the key approach is to patch smarter, not harder. Vulnerabilities need to be assessed, and remediation efforts prioritized, ensuring that the most critical vulnerabilities are addressed first, such as those listed in the Known Exploited Vulnerability (KEV) Catalog.

When software and devices reach end-of-life, security updates and patches come to an end. Continued use of end-of-life software and devices presents threat actors with opportunities to exploit unaddressed vulnerabilities to gain access to networks and sensitive data. Critical infrastructure owners and operators need to know when support will end for their software and devices and plan to upgrade or replace software, firmware, and hardware devices before support comes to an end. This is especially important for any technology devices or software on the boundary of the network that are accessible from the public internet. Guidance on mitigating risk for end-of-life software and devices is available in BOD 26-02.

It is essential that operations can be sustained in the event of a cyber incident and that a rapid and full recovery is possible. Critical infrastructure owners and operators need to fortify their systems and invest in isolation and recovery capabilities. Vital systems must be isolated from harm and must be capable of continuing to operate in an isolated state, while compromised systems are recovered. CI Fortify is an allied initiative designed to ensure that critical infrastructure entities can continue to operate in the event of geopolitical cyber conflict, through the implementation of resilient OT environments capable of surviving extended isolation and cyber compromise.

All Businesses Should Take Steps to Improve Their Security Posture

Critical infrastructure is supported by a diverse range of businesses, and vendors in the supply chain that are directly or indirectly involved with critical infrastructure are often targeted by threat actors, as they are often a weak link in the security chain. This Cybersecurity Awareness Month, CISA is encouraging all businesses to assess their security posture and implement key cybersecurity best practices, starting with basic, high-impact measures to defend their networks and data:

  • Provide phishing education to the workforce
  • Strengthen password requirements
  • Implement multifactor authentication
  • Update business software and patch promptly

With those foundational security requirements in place, businesses should expand their security capabilities by implementing the following measures:

  • Log system activity on all business systems
  • Back up business data
  • Encrypt data at rest and in transit
  • Develop and implement an incident response plan
  • Report all cyber incidents to CISA
  • Prepare for system disruptions

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist