The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have issued a warning to businesses about the risks associated with Tor.

The Tor software, which is managed by the non-profit organization Tor Project, is designed to provide anonymity to users and circumvent censorship.
However, in addition to ordinary users, this software has also attracted the attention of hackers, who use it to cover their tracks when carrying out illegal activities.
Some of the malicious activities carried out by malicious actors include surveillance, system compromise, data extraction, denial of service (DoS) attacks, and ransomware. Additionally, Tor is often used to communicate with a command and control (C&C) server.
Using Tor allows an attacker to hide their identity and hinders rapid recovery from a cyberattack. For this reason, businesses should implement the necessary measures to block and monitor all traffic to and from the Tor network in order to be able to detect any illegal activities.

As security organizations state, each company should be able to understand whether users want the software for legitimate activities and of course take into account the risks it poses.
To detect malicious activity originating from Tor, organizations can use indicator-based or behavioral analysis of network, endpoint, and security logs. SIEM and the like can help in this direction.
CISA themselves from the risks associated with Tor, such as monitoring and analyzing traffic on a network or even completely blocking data entering and exiting public nodes.
