Critical Infrastructure and Public Protection Strategies: Part 1
By Sean Atkinson, Chief Information Security Officer
The Department of Homeland Security (DHS) has defined 16 critical infrastructure sectors in the U.S. IT professionals can utilize best practices to contribute to the overall safety and security of these sectors. Threat analysis should consider the likelihood of a particular group or categorization of cyber adversary.
Once defined, the tactics, techniques, and procedures that are used by such organizations are areas that need to be guarded. But it doesn’t stop there. Even after the most likely adversary is identified, the process should be to utilize best practices to eliminate the threat posed by any threat actor.
Resilience and good cyber hygiene can protect our values, industries, and services. Here are some tips that can be used by both those who work in critical infrastructure and the public.
Chemical Sector
Manufacturers and private owners should be applying cybersecurity best practices to their information systems and industrial control systems. Awareness of the threat and the interdependency of the supply chain of critical services that are supporting other critical services is key.
Tip: “See something, say something.” If something seems out of place or suspicious, use caution and good judgment.
Commercial Facilities Sector

Tip: Be aware of potential threats on point of sale systems. Card readers implanted on legitimate devices can compromise credit card information. Make sure that the card reader is sturdy and nothing is stuck over the top. In some cases, entire units are placed on top of ATMs, retail card readers, and gas pumps to help keep them safe.
Communications Sector

Tip: Keep your machine “clean” with current patches and updated anti-malware software. Making your machine secure helps make sure nefarious programs are not utilizing this resource to exhaustion.
Critical Manufacturing Sector

Tip: Easily stop malware infection by forbidding the use of personal USBs plugged into corporate assets.
Dams Sector

Tip: Don’t utilize the same password across your personal and business accounts. If you do, and the password is compromised by a public portal, it can be used to access a private business portal. The attacker could gain access to more than just your email account. Based on your role within the organization, the hacker could have compromised the methods to affect the dam, its controls, and the safeguards of those who could be at potential risk.
Defense Industrial Base Sector

Tip: Think about ways in which you can be a good cyber citizen. Opening an email that looks enticing can have detrimental consequences. Vigilance is required from all who utilize internet connected technologies.
Emergency Service Sector

Tip: Although what to share online is a personal decision, be cautious. When we overshare we may be putting ourselves or others in jeopardy. Think before you post. “How can this information be used for harm?”
Energy Sector

Tip: Make sure that you apply the rules to your everyday work practice and not another “training” that you already know. Speak up if you have ideas or recommendations on making training more accessible or aligned with your work stream.
Protecting our daily lives
From Critical Manufacturing to Emergency Services, people around the country rely on critical infrastructure for daily tasks like going to work and communicating with friends and family. All of us can take steps to reduce the risks to these essential systems and services. One way to learn more is by downloading the CIS Controls – free, prioritized cybersecurity guidance that helps organizations around the world improve their security posture.
Check out part 2 of this blog series.
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.