Blog. The End is Just the Beginning of Better Security: Enhanced Vulnerability Management with OpenEoX

Enhanced Vulnerability Management with OpenEoX

By embracing OpenEoX, we as a collective community can proactively eliminate vulnerabilities, safeguard the digital ecosystem at scale, and counter the ever-increasing exploitation speed of threat actors. 

CIRCIA. Cyber Incident Reporting for Critical Infrastructure Act of 2022: Rulemaking Town Hall Meetings

CIRCIA Rulemaking Town Hall Meetings

CISA is holding a series of virtual town hall meetings to allow external stakeholders limited additional opportunity to provide input on refining the scope and burden of the CIRCIA Notice of Proposed Rulemaking (NPR) published in the Federal Register

Now Available: 2025 Year in Review with CISA logo and blue, red, and green box decoration on the boarders of a blue background

CISA’s 2025 Year in Review

Efficiency. Modernization. Resilience. See how CISA focused tightly on our agency’s core mission: protecting America’s critical infrastructure from cyber and physical threats.

Guidance: Barriers to Secure OT Communication: Why Johnny Can't Authenticate with a hand reaching towards a screen with a red lock and computer code behind it

CISA RELEASES GUIDANCE ON BARRIERS TO SECURE OT COMMUNICATION: WHY JOHNNY CAN’T AUTHENTICATE

This guidance outlines key barriers to secure communication and provides actionable recommendations for vendors and asset owners and operators to improve the usability and adoption of secure protocols.

Binding Operational Directive Mitigating Risks from End-of-Support Edge Devices

CISA Directive Focuses on Mitigating Risks from End-of-Support Edge Devices

Federal agencies must take immediate action to inventory, remove, and replace all unsupported edge devices. This guidance is relevant for all organizations seeking to strengthen network security and reduce vulnerabilities.

Super Bowl LX: Strengthening Preparation, Building Resilience, Fostering Partnerships

Super Bowl LX: Strengthening Preparation, Building Resilience, Fostering Partnerships

Together with the NFL, DHS, and local, state, and private-sector partners, CISA coordinated a year-long initiative to protect people, venues, and critical infrastructure to ensure a safe and successful championship game.

JCDC unifies cyber defenders from organizations worldwide. This team proactively gathers, analyzes, and shares actionable cyber risk information to enable synchronized, holistic cybersecurity planning, cyber defense, and response.

StopRansomware.gov is the U.S. Government's official one-stop location for resources to tackle ransomware more effectively.

SAFECOM works to improve emergency communications interoperability across local, regional, tribal, state, territorial, international borders, and with federal government entities.

Additional CISA Resources

abstract cyber space

CISA Resources & Tools

CISA offers an array of free resources and tools, such as technical assistance, exercises, cybersecurity assessments, free training, and more.

Image of an event with speaker and participants

CISA Events

CISA hosts and participates in events throughout the year to engage stakeholders, seek research partners, and communicate with the public to help protect the homeland.

Image

CISA Services Catalog

A single resource that provides you with access to information on services across CISA’s mission areas.

Employees pictured during training session

CISA Training

As part of our continuing mission to reduce cybersecurity and physical security risk, CISA provides a robust offering of cybersecurity and critical infrastructure training opportunities.