The Cybersecurity and Infrastructure Security Agency along with international agencies May 14 released guidance for high-risk nonprofit and other resource-constrained community organizations to assist in understanding and mitigating cyberthreats. The guide provides several recommendations for organizations to follow, which include: keeping software updated on user devices and IT infrastructure; implementing phishing-resistant multifactor authentication; account auditing and disabling those that are unused or unnecessary; selecting vendors with due diligence; implementing basic cybersecurity training; and developing and exercising incident response and recovery plans.

"Although this guide is not specific to health care, it provides an excellent overview of current cyber threats, foundational cybersecurity practices and available free resources to help implement these practices," said John Riggi, AHA's national advisor for cybersecurity and risk. "This guide, along with the Department of Health and Human Services’ Cybersecurity Performance Goals, can help resource-challenged hospitals prioritize cybersecurity practices and develop a roadmap for implementation."

For more information on this or other cyber and risk issues contact Riggi at jriggi@aha.org. For the latest cyber and risk information and resources visit www.aha.org/cybersecurity.

Headline
The White House issued an executive order March 6 to combat cybercrimes by threat groups. The order highlights how such groups can receive willing or…
Headline
The Administration for Strategic Preparedness and Response has released a new cybersecurity module for organizations to conduct risk assessments. The free…
Perspective
Public
As the world has learned in recent years, today’s conflicts are fought with many weapons, and cyber warfare is an integral part of the arsenal.As of this…
Headline
The FBI is reminding critical infrastructure organizations to implement mitigations from a June 2025 fact sheet on potential actions by Iranian-affiliated…
Headline
The Cybersecurity and Infrastructure Security Agency Feb. 26 released a report that updates findings from last year on RESURGE malware used to gain covert…
Headline
U.S. and international agencies Feb. 25 released guidance on protecting Cisco Software-defined Wide-area Networking systems from exploitation by malicious…