Cybersecurity Dive January 14, 2025
The federal agency said the number of critical infrastructure organizations enrolled in its vulnerability scanning program nearly doubled since 2022.
Dive Brief:
- The Cybersecurity and Infrastructure Security Agency trumpeted progress across its efforts to decrease critical infrastructure organization’s exposure to actively exploited CVEs and cut remediation times in a Friday report.
- The number of critical infrastructure organizations enrolled in CISA’s vulnerability scanning service nearly doubled over a two-year period to 7,791 organizations at the end of August 2024. CISA added 1,199 vulnerabilities to its known exploited vulnerabilities catalog through the same period.
- During the two-year period of analysis, critical infrastructure organizations enrolled in CISA’s vulnerability scanning service reduced average remediation times from 60 days to 30 days.
Dive...