The Russian government is warning its organizations about possible cyberattacks by the United States in “retaliation” for the SolarWinds hack. Last month, SolarWinds revealed that it had suffered a “sophisticated” cyberattack that led to a supply chain attack affecting more than 18,000 of its customers. The U.S. government believes that Russia is behind the attack, aiming to steal cloud data, such as emails and files, from high-profile companies and U.S. government agencies.

White House Press Secretary Jen Psaki said the US could retaliate against the large-scale attack it suffered. Specifically, in her statement to NBC News, she said the following: “We have the right to retaliate in any way we want against any cyberattack carried out by either Russia or any other country.”
While Russia continues to deny US allegations of involvement in the SolarWinds breach, as first reported by ZDNet, Russia's NKTsKI (Russia's National Coordination Center for Computer Incidents) has issued a warning to organizations based in Russia, recommending they improve the security of their networks.

NKTsKI FSB ) and was created to detect, prevent and counter cyberattacks on the country's infrastructure and enterprises.

NKTsKI recommends that organizations based in Russia take the following steps to increase the security of their networks and defend against potential US cyberattacks::
- Update your organization's existing plans and guidelines for dealing with security incidents.
- Inform your employees about potential phishing attacks that use social engineering.
- Check network information security and antivirus protection tools, ensure they are properly configured and functioning on all important network nodes.
- Avoid using third-party DNS servers.
- Use multi-factor authentication (MFA) to gain remote access to your organization's network.
- Identify the list of trusted software for access to the corporate network and limit the use of funds that are not included in it.
- Confirm the correct recording of network and system events in important information infrastructure elements, organize their collection and central storage.
- Make sure you also have the correct data backup frequency for important elements of your information infrastructure.
- Make sure that existing policies for differentiating access rights for devices on the network are correct.
- Restrict access to services on the internal network via a firewall.
- To work with external resources, including the Internet, use terminal access through the organization's internal services.
- Update all users' passwords according to the password policy.
- Provide antivirus protection for incoming and outgoing emails.
- Monitor system security with increased vigilance.
- Make sure you have the necessary updates for your software.
It is worth noting that, in the past, the US has avoided publicly retaliating against other countries that have carried out cyberattacks against it. However, as BleepingComputer reports, any future US retaliation, whether against Russia or another country, may not come to light.
