Start your day with intelligence. Get The OODA Daily Pulse.
Russia’s invasion of Ukraine could impact organizations both within and beyond the region, including malicious cyber activity against the U.S. homeland, including as a response to the unprecedented economic costs imposed on Russia by the U.S. and our allies and partners. Evolving intelligence indicates that the Russian Government is exploring options for potential cyberattacks. Every organization—large and small—must be prepared to respond to disruptive cyber incidents. As the nation’s cyber defense agency, CISA stands ready to help organizations prepare for, respond to, and mitigate the impact of cyberattacks. When cyber incidents are reported quickly, we can use this information to render assistance and as a warning to prevent other organizations and entities from falling victim to a similar attack. (1)
The advice right now from both CISA and the FBI is that all organizations should significantly lower their threshold for reporting anomalous cyber activity, contacting your FBI field office or CISA directly with an incident report if you in any way feel that you or your organization has identified viable threat activity. Organizations should report anomalous cyber activity and/or cyber incidents 24/7 to [email protected] or (888) 282-0870.
In the current climate created by the viable threat of a Russian cyberattack on the U.S., if you are preparing your organization or your individual household to mitigate risk please see OODA CTO Bob Gourley’s Guide For Business: Final checks for reducing risks in the face of nation-state cyber-attacks based on White House advisory. In the post, Bob itemizes OODA recommendations for:
OODA is here to help. OODA members can contact us by replying to any of our emails or using this form.
Note: CISA will continue to update this webpage as we have further guidance to impart and additional reporting to share. Information contained on this webpage is provided “as-is” for informational purposes only. CISA does not endorse any company, product, or service referenced below.
Russia’s invasion of Ukraine, which has involved cyberattacks on the Ukrainian government and critical infrastructure organizations, may impact entities both within and beyond the region. CISA and CISA Joint Cyber Defense Collaborative (JCDC) partners are responding to ongoing, disruptive cyber activities in connection with Russia’s attack by documenting information on Russian threat actors, ransomware, destructive malware, distributed denial of service (DDoS) attacks, and Shields Up protective measures. A collection of technical resources is provided below for users and organizations to reference to stay up to date on the latest cyber threat activity in Ukraine.
In addition to reviewing the activities, see CISA’s Shields Up webpage for steps to reduce future risk against these threats in the U.S. homeland.
Shields UP! is the result of private-sector collaboration through the newly formed DHS CISA Joint Cyber Defense Collaborative (JCDC).
Following are some of the most up to date technical guidance links from JCDC organizations:
Preparing for Cyber Attacks: The CISA Online Resource Hub
CISA, FBI Issue Joint Cybersecurity Advisory for SATCOM Ecosystem Following Viasat Cyberattack
CISA Insights Bulletin Urges U.S. Preparation for Data Wiping Attacks
Log4Shell Update from CISA Director Easterly and DHS CISA JCDC Company Updates
C-Suite Guide: Improving Cybersecurity Posture Before Russia Invades Ukraine
At Black Hat 2021, CISA Director Jen Easterly launches CISA JCDC (Joint Cyber Defense Collaborative)
It should go without saying that tracking threats are critical to inform your actions. This includes reading our OODA Daily Pulse, which will give you insights into the nature of the threat and risks to business operations.
Now more than ever, organizations need to apply rigorous thought to business risks and opportunities. In doing so it is useful to understand the concepts embodied in the terms Black Swan and Gray Rhino. See: Potential Future Opportunities, Risks and Mitigation Strategies in the Age of Continuous Crisis
The OODA leadership and analysts have decades of experience in understanding and mitigating cybersecurity threats and apply this real world practitioner knowledge in our research and reporting. This page on the site is a repository of the best of our actionable research as well as a news stream of our daily reporting on cybersecurity threats and mitigation measures. See: Cybersecurity Sensemaking
OODA’s leadership and analysts have decades of direct experience helping organizations improve their ability to make sense of their current environment and assess the best courses of action for success going forward. This includes helping establish competitive intelligence and corporate intelligence capabilities. Our special series on the Intelligent Enterprise highlights research and reports that can accelerate any organization along their journey to optimized intelligence. See: Corporate Sensemaking
In 2020, we launched the OODAcast video and podcast series designed to provide you with insightful analysis and intelligence to inform your decision making process. We do this through a series of expert interviews and topical videos highlighting global technologies such as cybersecurity, AI, quantum computing along with discussions on global risk and opportunity issues. See: The OODAcast