CISA’s new ransomware vulnerability notification program

The Cybersecurity and Infrastructure Security Agency leverages multiple open-source and internal tools to proactively research and detect vulnerabilities within U.S. critical infrastructure as part of its new Ransomware Vulnerability Warning Pilot, which started on January 30.


On Monday, CISA announced the creation of its RVWP program required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022.

CISA says it can accomplish ransomware-vulnerability warning by leveraging its existing services, data sources, technologies and authorities, including the agency’s Cyber Hygiene Vulnerability Scanning service and its Administrative Subpoena Authority granted under Section 2209 of the Homeland Security Act of 2002, according to theFAQon its website.

“Organizations across all sectors and of all sizes are too frequently impacted by damaging ransomware incidents,” CISA said in the new FAQ.

Most organizations may be unaware that a vulnerability used by ransomware threat actors is present on their network. But damaging intrusions could be avoided by warning critical infrastructure entities, like hospitals and healthcare systems, of detected security vulnerabilities.

Once CISA identifies affected systems, regional cybersecurity personnel notify system owners.

CISA also offers no-cost cybersecurity resources and tools. It recommends that organizations sign up for its no-cost Cyber Hygiene Vulnerability Scanning service and take a self-assessment to determine progress in implementing cybersecurity performance goals.

By building a relationship with a regional CISA cybersecurity advisor, healthcare organizations can participate in additional services, the agency added.


Toimprove the cybersecurity posture of healthcarethe Department of Health and Human Services has recommended enterprise-wide risk analyses and a series of best practices, including vulnerability scans of all systems and devices to reduce the risks of common cyberattacks.

Vulnerability management has been the most important part of cybersecurity for the past 20 years, according to Darren Lacey, vice president and CISO for Johns Hopkins University and Johns Hopkins Medicine.

“We chase down vulnerabilities and, in fact, if you had to say what was the biggest change in cybersecurity over the last 10 years along with the ransomware spike would be the number of publicized vulnerabilities,” he toldHealthcare IT Newsin September.

Ransomware attacks doubledbetween 2020 and 2022, and with cyberattacks getting more innovative in their approaches over time, it behooves all healthcare organizations to make use of all the cybersecurity services CISA, HHS and industry resources offer.


“Many of these incidents are perpetrated by ransomware threat actors using known vulnerabilities,” CISA says in its new RVWP program FAQ. “By urgently fixing these vulnerabilities, organizations can significantly reduce their likelihood of experiencing a ransomware event.”

Andrea Fox is senior editor of Healthcare IT News.

Healthcare IT News is a HIMSS Media publication.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
北 “미국의 적대시 정책 묵과할 수 없다”… 핵실험·ICBM 발사 재개 시사 thumbnail

北 “미국의 적대시 정책 묵과할 수 없다”… 핵실험·ICBM 발사 재개 시사

김정은 북한 조선노동당 총비서. 평양 조선중앙통신=연합뉴스 북한이 2018년 이후 중단했던 핵실험과 대륙간탄도미사일(ICBM) 발사 재개를 검토하겠다고 밝혔다. 미국 조 바이든 대통령의 취임 1주년 기자회견에 맞춰 핵·미사일 모라토리엄(유예) 해제 카드를 내세우며 대미 압박 수위를 높인 것으로 풀이된다. 조선중앙통신은 노동당 중앙위원회가 김정은 총비서가 참석한 가운데 제8기 제6차 정치국 회의를 열어 미국 대응방안을 논의했다고 20일 밝혔다.  통신은 “우리가 선결적으로, 주동적으로 취했던 신뢰…
Read More
Culture: The Newest Currency In Luxury thumbnail

Culture: The Newest Currency In Luxury

With the international trend of moving away from Eurocentrism and embracing greater cultural diversity, the luxury fashion brands are increasingly weaving in unique cultural narratives into their collections As the world keeps evolving to different ideas and ways of living, if there is one thing that stands as the timeless force binding it all together
Read More
Index Of News