Cybereason is now LevelBlue. Proven endpoint protection, now with greater scale and expanded capabilities. Learn More

Cybersecurity Awareness Month 2026: Securing the Next 250 Years

This year, the United States of America celebrated their 250th birthday, but Cybersecurity Awareness Month is already looking toward the future with the goal of securing the next 250 years together.

It’s an ambitious theme that leads us all to wonder, “what does it actually take to build security that lasts?”

The Cybersecurity & Infrastructure Security Agency (CISA) 2026 Cybersecurity Awareness Month guidance begins with four familiar practices:

  • Avoid and report phishing
  • Use strong passwords
  • Enable multifactor authentication and use a password manager
  • Keep software updated

Implementing these fundamentals consistently across complex environments remains challenging, particularly where legacy applications, service accounts, acquisitions, and unsupported technologies create exceptions.

But CISA’s broader guidance shifts the conversation toward an increasingly important priority: maintaining critical operations through cyber disruption.

 

For critical infrastructure, cyber risk carries operational consequences

Critical infrastructure rarely gets the luxury of downtime. Energy and water systems, healthcare environments, transportation, communications and other essential services must remain available while their operators contend with cyber threats, legacy technology, and increasingly interconnected environments.

CISA's 2026 recommendations for critical infrastructure capture that challenge in three priorities:

  • Reduce vulnerabilities
  • Replace end-of-support devices
  • Recover quickly to sustain operations

Anticipate threats and protect your business with LevelBlue.

Explore Services

Along with broader recommendations on logging, backups, encryption, incident reporting, response planning, and disruption preparedness, they provide a useful framework for operational cyber resilience.

As LevelBlue’s Director of Hardware/Operational Technology Security, Nolen Johnson, puts it, “[Providers] make all these recommendations like segment your networks, purchase firewalls, replace legacy assets. These are all expensive operations. But the biggest, most important thing utilities can do is set attainable security goals:

  • Start small and assign ownership and accountability of security tasks to specific roles and ensure that everyone knows their specific security responsibilities.
  • Convert all security assessment findings and advisory information into threat intelligence-guided action items.
  • When architecting security think “turtle shell;” focus on hardening all exterior facing access venues to protect that ‘soft’ legacy interior.”

Attainable security is the goal.

 

Reduce vulnerabilities

Critical infrastructure can make remediation difficult. Patching may require downtime, and specialized equipment can involve operational constraints. That makes context essential when deciding what to address first

Vice President of LevelBlue SpiderLabs, Ed Williams, elaborates, “Finding vulnerabilities is one thing. Having the ability to fix, remediate, and validate vulnerabilities is something else. A scanner will happily dump a list on you; the hard part is deciding what actually matters, getting it fixed, and checking it hasn’t crept back in.”

Asset exposure, active exploitation, operational function, and available compensating controls can help security teams identify weaknesses with the greatest potential consequences. The result is vulnerability management grounded in the relationship between technical exposure and operational risk.

 

Replace end-of-support devices

End-of-support technology can create compounding cyber and operational risk for critical infrastructure. As vendor updates and technical support end, options for addressing newly discovered vulnerabilities can narrow. Replacement may require engineering work, compatibility testing, vendor coordination, and carefully planned downtime.

Replacement can also be complex. Specialized devices may support critical physical processes and require engineering work, compatibility testing, vendor coordination and carefully planned downtime. In some environments, a direct replacement may be difficult to find.

LevelBlue Senior Research Manager, Karl Sigler, shared his perspective: “Replacing end-of-support systems can feel overwhelming. Especially given the complexity of modern enterprise networks and global organizations. However, the longer you wait, the more at risk your organization becomes. Start by creating a complete inventory of EoS systems that need replacement, then prioritize your plan around your most valuable and/or at-risk systems.”

A risk-informed modernization roadmap can help organizations determine which systems require the greatest urgency. Factors such as exposure, known vulnerabilities, operational dependencies, segmentation options, available compensating controls and replacement feasibility can guide those decisions. For systems that must remain in service, security teams can use that same context to strengthen protections while planning for eventual replacement.

 

Recover quickly to sustain operations

CISA's recommendations around backups, incident response and disruption preparedness converge on another critical resilience discipline: understanding how recovery will work before an organization depends on it.

“Resilience isn’t proven by having a recovery plan on paper. It’s proven when an incident puts that plan under pressure. Effective recovery starts with understanding what happened, containing the threat, and knowing which systems and dependencies matter most. The organizations that recover well are the ones that have tested those decisions before they have to make them in the middle of a crisis,” said Devon Ackerman, LevelBlue’s Global Head of Digital Forensics and Incident Response (DFIR).

Backup frequency provides only one dimension of that picture. Security leaders also need to consider isolation, integrity, coverage, and restoration time. Backups accessible using compromised credentials may become ransomware targets. Technically recoverable data may take longer to restore than an essential operation can tolerate. Critical SaaS data, configurations, identity systems, and application dependencies may require recovery strategies of their own.

For critical infrastructure, restoration sequencing deserves particular attention. Recovery priorities should reflect operational dependencies across applications, identities, networks, infrastructure, and third parties. Restoring an application may provide limited operational value until its upstream services become available.

Security and operational leaders can therefore evaluate recovery around four questions: What can we restore? How quickly can we restore it? In what sequence? Under which failure conditions?

Testing those assumptions can identify gaps while teams still have the opportunity to address them.

 

Build visibility and protect critical data

Resilience depends in part on understanding what is happening across the environment. Effective logging gives defenders the evidence needed to reconstruct activity across identities, endpoints, networks, cloud environments, and critical systems. Authentication activity, privilege changes, network connections, and changes to critical configurations can help responders establish timelines, determine scope, and identify related activity.

For security leaders, log quality, coverage, protection, and retention all deserve attention. An investigation may depend on telemetry generated weeks or months earlier, and attackers with sufficient access may attempt to disable collection or destroy evidence. Organizations should consider whether responders would have the necessary evidence from their most important systems, retained for an appropriate period, to investigate a consequential incident.

CISA also recommends encrypting data. For enterprise environments, effective encryption requires understanding where sensitive data resides, how it moves through the environment, who can access it, and how encryption keys are protected. Key management is particularly important because access to encryption keys can ultimately determine access to the protected information.

Together, logging and encryption serve different but complementary purposes during an incident: telemetry helps organizations understand activity across the environment, while encryption helps protect sensitive information if unauthorized access occurs.

 

Prepare the organization to act

Technology alone cannot determine how quickly an organization moves through an incident. Response also depends on whether teams understand their responsibilities, have the authority to make consequential decisions, and know how critical operations will continue during disruption.

CISA recommends having an incident response plan and using it. Exercises can test how that plan performs under realistic conditions: Who has authority to isolate a production segment? Who determines when a system can safely return to service? How will teams communicate if normal channels become unavailable? How will security, IT, operations, legal, communications and executive leadership coordinate when their priorities intersect?

The friction those exercises expose can become valuable input for improvement. Unclear decision rights, undocumented dependencies and unrealistic recovery assumptions can be addressed before teams encounter them during an actual incident.

Incident reporting should also be incorporated into response planning. CISA recommends reporting cyber incidents to the agency, so organizations should establish reporting responsibilities, escalation paths, and internal coordination in advance. Timely information sharing can also contribute to broader awareness of active campaigns and related threats.

For critical infrastructure, preparedness extends directly into operational continuity. Organizations should understand how essential services will function while affected technology is contained and restored. Depending on the environment, that may require alternate communications, manual operating procedures or other contingency mechanisms. Exercises should test these processes alongside technical response and recovery plans.

 

Build resilience across the security program

Taken together, CISA's recommendations create an interconnected approach to resilience, where telemetry supports detection and investigation, encryption protects sensitive information, backups enable recovery, incident reporting contributes to shared threat awareness, and established response and continuity plans help organizations act decisively through disruption.

For critical infrastructure, the connections among these capabilities are especially consequential. A cyber incident can quickly affect the physical processes, essential services, businesses, and communities that depend on the organization.

As America looks toward its next 250 years, technologies and threats will continue to change. Organizations can prepare by understanding the systems and dependencies behind their critical services, reducing their most significant exposures, and continually validating their ability to detect, decide, respond and recover.

Securing the next 250 years starts with strong fundamentals. Sustaining critical services requires resilience across the systems and infrastructure society depends on.

About LevelBlue

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

Discover how our specialists can tailor a security program to fit the needs of your organization.

Request a Demo