Critical Infrastructure and Public Protection Strategies: Part 2
By Sean Atkinson, Chief Information Security Officer
Critical infrastructure runs through multiple facets of our daily lives, supporting everything from financial transactions to healthcare services. In this blog post, we’ll examine some of the sectors of critical infrastructure and provide tips to help secure each sector.
Financial Services Sector

Tip: If you are a victim, own up to it and make sure it is reported. Learn what to do when you’re a victim of a sector-specific scam.
Food and Agriculture Sector

Tip: Make sure that you are using reputable merchants and that website security safeguards such as HTTPS are in place. This guide will help you be aware of the methods of delivering these scams.
Government Facilities Sector

Tip: For the general voting public, specific security protocols and awareness can assist in making sure your information is kept secure. Be cautious of emails and social media posts about voting or re-registering. Any site that requests or demands that you enter information to register or re-register to vote should be considered suspicious.
Healthcare and Public Health Sector

Tip: Data should be shared on a “need to know” basis. When employees distribute healthcare information, they should ensure:
• that they have permission to send the information, and
• that the recipient is aware of their responsibility to ensure confidentiality is maintained once they receive this information.
CIS Control™ 14 and its sub-controls help users understand data management based on the need to know.
Information Technology Sector

Tip: One item for consideration is the default account and passwords that are supplied with IoT and networking devices. Once installed, users should change the default setting to a higher level of security. The CIS Benchmarks™ provide excellent guidance for many technologies to help ensure that the default credentials are changed.
Nuclear Reactors, Materials and Waste Sector

Tip: Create a formal guide that is trained and tested, or develop red team exercises that issue alerts. Some response activities may be automatically enabled when certain conditions or thresholds are reached.
For individuals, planning might include monitoring for personal breaches and changing passwords regularly. Make sure to check credit scores and have your financial information at hand to respond to any incident.
Transportation Sector

Tip: Keep your devices with you at all times. Make sure that you physically secure the devices. Also secure them logically; apply encryption software to your hard drive as a security precaution. This will maintain the confidentiality of your data. It will also preserve its integrity so it won’t be altered or accessed if it is out of your possession.
Water and Wastewater Systems Sector

This criteria defines initiating a program as the hardest part of minimizing risk and applying appropriate controls. One strong starting point would be the CIS Controls, a prioritized list of security steps that are essential to cyber resilience.
Tip: Personnel may believe they do not have the specialized skills to use cybersecurity controls effectively. This is not the case. Anyone can start with a risk-based approach that takes into account the targets an adversary is most likely to seek. The above URL from the EPA provides a 16-point checklist. When used in combination with the CIS Controls, you can start to build the resilience required to protect our critical infrastructure.
US-Cert Resource – Tips for the Public
Securing our future
Although each critical infrastructure sector has its own unique risks and challenges, many of the technical vulnerabilities are shared. The CIS Benchmarks are configuration guidelines for securing servers, operating systems, software, and more. When applied to a system, the CIS Benchmarks can help reduce cybersecurity risks and protect against attacks.
Check out part 1 of this blog series.
As of June 23, 2025, the MS-ISAC has introduced a fee-based membership. Any potential reference to no-cost MS-ISAC services no longer applies.