The U.S. Cybersecurity and Infrastructure Security Administration (CISA)has released a list of free cybersecurity services and tools, aimed at helping organizations increase their security capabilities and better defend against cybercriminals.

See also: CISA: Federal agencies must fix Chrome and Magento bugs
While these services are likely to be further enhanced, they can contribute to the maturity of an entity's cybersecurity risk management when combined with core security practices for a robust cybersecurity program.
The list is a combination of services from CISA, open source utilities, and free tools and services from public and private sector organizations.
Before turning to the tools and services compiled by CISA, however, organizations should adopt some of its recommended security practices:
- Apply security updates that fix known vulnerabilities
- Multi-factor authentication (MFA) implementation
- Removing software that is no longer supported (end of life) and replacing systems/software with passwords that are known, default or hardcoded
- Using CISA 's Cyber Hygiene Vulnerability Scanning Service
- Reducing visibility on the public web for sensitive devices and platforms
Once the above measures are implemented, CISA says organizations will be able to move forward with using the free tools and services it has released to improve cybersecurity risk management.
See also: Dutch cybersecurity agency warns of lingering Log4j risks

The organization has grouped resources into four categories, based on the goals that need to be achieved to protect against potential critical threats:
- Reducing the likelihood of a harmful cyber
- Rapid detection of malicious activity
- Effective response to confirmed cases
- Maximizing durability
The list includes 97 tools and services from the open source space, as well as from the CISA repository and various organizations related to the cybersecurity sector: Microsoft, Google, VMware, IBM, Mandiant, Cisco, Secureworks, Cloudflare, Center for Internet Security, CrowdStrike, Tenable, AT&T Cybersecurity, Kali Linux Project, Splunk, SANS and Palo Alto Networks.
Each entry is accompanied by a short description, a link, and an assessment of the skill level required to operate it, which varies between “basic” and “advanced.”.
See also: Cybersecurity should be about employee behavior
CISA emphasizes that the listed tools and services are not guaranteed to be suitable "for any specific use case.".
Although many of the resources listed come from private companies, CISA notes that their selection in no way implies endorsement or favorable support by the organization.
