Safeguard
Tag

critical-infrastructure

Safeguard articles tagged "critical-infrastructure" — guides, analysis, and best practices for software supply chain and application security.

31 articles

Compliance

TSA Surface Transportation Cyber NPRM: From Directives to Rule

TSA's November 2024 Enhancing Surface Cyber Risk Management NPRM would formalize what pipeline and rail SDs already require. Operators should prepare now.

Apr 15, 20266 min read
Regulatory Compliance

Oracle Critical Control Baseline: Regulatory Impact

Oracle's February 2025 Critical Control Baseline for critical infrastructure customers reshapes SCRM obligations. Here's what legal and security teams must know.

Apr 10, 20265 min read
Regulatory Compliance

NIS2 Directive Supply Chain Obligations in 2026

NIS2 has been in force across the EU since October 2024, and member state enforcement is now operating in earnest. The supply chain obligations are the ones most organizations underestimated.

Apr 8, 20265 min read
Incident Analysis

American Water Cyberattack: Largest U.S. Utility Forced Offline

American Water Works discovered unauthorised network access on October 3, 2024, shutting down its MyWater customer portal and billing systems serving 14 million people across 24 states.

Mar 30, 20266 min read
Threat Intelligence

Qilin Ransomware Group: Dissecting a Rising Threat Actor

Qilin has rapidly become one of the most active ransomware operations, targeting healthcare, manufacturing, and critical infrastructure. A technical breakdown of their methods.

Mar 28, 20265 min read
Incident Analysis

Port of Seattle Rhysida: Airport Ransomware and the Public-Sector Tail

On August 24, 2024, Rhysida ransomware took down Port of Seattle systems including Sea-Tac airport check-in, baggage, and the Port website. The Port refused a $6 million ransom. We unpack the case.

Mar 17, 20267 min read
Threat Intelligence

Fog Ransomware: Why Schools and Universities Are Under Siege

Fog ransomware has carved a niche by targeting educational institutions — organizations with tight budgets, thin security teams, and massive attack surfaces. Here is how they operate.

Mar 14, 20266 min read
Industry Analysis

Volt Typhoon: Living-Off-the-Land and Supply Chain

The PRC-linked pre-positioning group that scared DHS and the NSA into a public warning, and what it means for supply chain defenders.

Mar 11, 20266 min read
Compliance

CIRCIA Final Rule: Reporting Thresholds and Covered Entities

CISA pushed the CIRCIA final rule to May 2026. We unpack the dual-track threshold structure, the 72-hour and 24-hour timers, and what the 300,000-entity scope means.

Mar 11, 20266 min read
Ransomware

Rhysida Ransomware: Systematic Targeting of Government and Critical Infrastructure

Rhysida ransomware distinguished itself through deliberate targeting of government agencies, education institutions, and healthcare organizations across multiple countries.

Mar 5, 20267 min read
Regulatory Compliance

Utilities Sector NERC CIP Software Supply Chain

NERC CIP-013 turned software supply chain into a regulated obligation for the bulk electric system. A practical look at what utilities are actually doing.

Feb 27, 20267 min read
Industry Analysis

Critical Infrastructure Software Supply Chain

How the 16 critical infrastructure sectors are absorbing software supply chain obligations under PPD-21, NSM-22, and CISA's emerging frameworks.

Feb 24, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

critical-infrastructure (Page 2) — Safeguard Blog