CISA Shields Up

March 31, 2022

Takeaway: CISA’s Shield Up Guidance Emphasizes Incident Response Planning


With the specter of an expanding war in Europe, the threat of cyber retaliation by Russia, or Russian-sponsored actors, is increased. In response, the Cybersecurity and Infrastructure Security Agency (“CISA”) released its Shields Up Guidance to help organizations and supply chains withstand and prepare for a malicious Russian cyber-attack. The guidance is aligned with previous recommendations from CISA and National Institute of Standards and Technology (“NIST”).

A central theme of the Shields Up Guidance is incident response: putting in place a proper plan in the event of a cybersecurity incident.  Indeed, a strong incident response plan (“IRP”) is a pillar of a viable cybersecurity program, as it encourages accountability and helps promote a culture of security.

To get started, it’s important to identify an organization’s most critical data and infrastructure. Once critical data and infrastructure are identified, the organization can assign roles to people who form the Incident Response Team (“IRT”). The IRT is the standard-bearer for how the organization will defend its critical data assets. The IRT meets regularly to augment and execute on the IRP.  The IRT also assumes responsibility for triaging and responding to an active incident. It is important to define all roles with specificity and to engage in training exercises to ensure that all people understand their responsibility.

A critical responsibility of the IRT is escalating incidents to senior management and the proper external authorities. Under its Shields Up Guidance, CISA makes it clear that organizations should lower the threshold for reporting cyber incidents. That is, even minor incidents that are blocked by security controls should be reported to CISA.

In addition to the internal IRT, organizations will want to identify critical third-party experts to help execute the IRP. The IRT will coordinate with technical experts and legal counsel to ensure that the breach is reported to the proper authorities, the threat is contained and eradicated, and the organization is ready to safely resume operations.

CISA’s Shields Up Guidance provides more information about how to pursue and implement an IRP at https://www.cisa.gov/shields-up.

News & Events

Related News

Pietragallo Expands With Three New Associates
October 21, 2024
Pietragallo Gordon Alfano Bosick & Raspanti, LLP is pleased to announce the addition of three new associates to the firm’s Pittsburgh and Philadelphia Offices. Read More
Pietragallo Elevates Three New Partners for 2024
October 16, 2024
Pietragallo Gordon Alfano Bosick & Raspanti, LLP is pleased to announce the promotion of three lawyers to partnership: Rebecca Johnson Barksdale in Pittsburgh, PA, and Alexander M. Read More
View More News & Events