Reviewed and updated in October 2026.
War is not limited to faraway battlefields. Your critical infrastructure is a tempting target for anyone looking to cause disruption or destruction as part of their warfare, and recent armed conflict has shown what state-sponsored actors are capable of. No organization, whatever its size or industry, is safe from such attacks, so now is the time to review your security and make sure you can respond and recover if you are attacked.
In the US, the Cybersecurity and Infrastructure Security Agency (CISA) has published recommendations under its Shields Up campaign on how organizations can protect themselves. In Germany, the Federal Office for Information Security (BSI) publishes comparable guidance. Below are the measures we consider most important.
Zero Trust architecture
In a connected world, everything is reachable by everyone, including your critical infrastructure. A Zero Trust architecture ensures that only authorized users can access what they need. Some measures are simple; how far you take Zero Trust depends on your business and security needs. Here is what you can do today with elements you probably already have in place:
- Allow only managed devices to access corporate resources, so that corporate data is accessed, handled and stored only on devices where security can be enforced through encryption, and on mobile devices, especially BYOD, through app containerization.
- Allow only legitimate, authenticated, authorized and secured remote access to your infrastructure, using Virtual Private Network (VPN) technology combined with Multi-Factor Authentication (MFA). Where possible, use phishing-resistant methods such as FIDO2 security keys or passkeys, and add a behavior-based security solution such as UEBA if available.
- Control all traffic to your organization's services and resources:
- For on-premises resources, review your firewall and proxy configuration and allow only necessary, business-critical traffic.
- For cloud resources, use a Zero Trust Network Access (ZTNA) solution so that only managed, trusted and safe devices can connect. Cloud resources are online by default and therefore reachable by anyone, anywhere.
A more detailed introduction is Zero Trust Architecture in a Nutshell.
Reduce the attack surface
The less there is to attack, the less damage attackers can do:
- Disable any exposed services that are not essential to the business.
- Update all your systems, operating systems and apps alike, and prioritize security patches for known CVEs.
- Use your UEM solution to make sure all endpoints run the latest operating system version. For personal devices, ask employees to update their operating system and apps regularly.
Make sure you can detect intrusions
Detecting an intrusion early lets you stop it before it turns into an attack that causes serious damage:
- Make sure all endpoints, personal and corporate, are protected against malware: preferably with a Mobile Threat Defense (MTD) solution on mobile devices and an Endpoint Protection Platform (EPP) on desktops and servers. The differences are explained in Demystifying Security: EPP, EDR and MTD.
- If you use an Endpoint Detection and Response (EDR) solution, consider raising the logging level so that more attacks and attempts can be caught and acted upon.
Make sure you can respond to intrusions
- Confirm ownership of the cybersecurity response: who does what, and how. Make sure key people are defined and reachable around the clock.
- Give employees clear guidance for the case that their computer or mobile device is compromised: whom to contact, how, and what to do with the device.
Make sure you can recover from an attack
- Back up all critical corporate data and verify that the backups work. Isolate backups and high-availability (HA) and disaster recovery (DR) resources as far as possible.
- Enable HA for mission-critical on-premises resources where available.
- Update your disaster recovery plan if needed, and test it. Do not wait for an attack to find out it does not work. What recovery looks like in practice is covered in Post-Ransomware Recovery: What Do I Do Now?.
Train your employees
Your employees are your first and last line of defense against any attack on your infrastructure.
- Many successful attacks still begin with a phishing email. Even the best anti-spam solution cannot catch every malicious message, so a small but important share still depends on employees not clicking a link or opening an attachment. More on this in Why Training Is Important.
- Have a sound password policy. Current NIST guidance (SP 800-63B-4) favors length over composition rules and advises against forced periodic changes unless there is evidence of compromise. Store passwords securely, for example in a password manager.
Keep reassessing
Reassess your critical infrastructure regularly and look for ways to strengthen it. With a Zero Trust architecture, a reduced attack surface and employees who are trained to respond to and recover from an intrusion, you stand the best chance of keeping your infrastructure safe.
For a broader view of security posture, read our two-part series on the security maturity model (part 1 and part 2) and our overview Cybersecurity Products: What's What.
Want to know where your infrastructure stands and which measures to tackle first? Our endpoint security team will help you weigh the options. Contact us.