HomeSecurityCISA orders federal agencies to replace EOS network devices

CISA orders federal agencies to replace EOS network devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has taken a major step to strengthen the security of federal networksby issuing a new binding operational directive. The directive requires government agencies to identify and remove network edge devices that are no longer supported by their manufacturers and have stopped receiving security updates.

CISA

CISA warns that such devices, which are at the end of their lifecycle (End of Support – EOS), constitute one of the most dangerous "blind spots" for cyber defense, as they remain active within critical infrastructures without being protected by new patches.

Why EOS devices are considered so dangerous

Unsupported network devices – such as routers, firewalls, and switches – leave federal systems exposed to modern exploits that exploit newly discovered security vulnerabilities.

See also: CISA adds SolarWinds WHD vulnerability to KEV List

According to CISA, the threat is immediate and ongoing. As it notes, organizations that continue to use EOS edge devices face “disproportionate and unacceptable risks.” The agency says it is already aware of extensive campaigns by advanced threat actors who are systematically targeting such equipment.

The problem is that these devices no longer receive official updates from the manufacturer, which means that even if a critical vulnerability, there is no way to fix it.

CISA orders federal agencies to replace EOS network devices

What does the new BOD 26-02 directive provide?

The new Binding Operational Directive 26-02 obliges federal agencies to disable hardware and software that has reached EOS status, in order to prevent its exploitation by cybercriminals or state-sponsored groups.

The directive is not limited to the disposal of old devices, but requires a comprehensive equipment lifecycle management strategy.

See also: CISA: VMware vCenter vulnerability in KEV Catalog

Compliance timeline: From inventory to replacement

CISA sets clear deadlines:

  • Immediate action for devices that are still supported by vendors but running EOS software, where updates are available.
  • Within three months, services must complete an inventory of all devices included in the CISA EOS list.
  • Organizations have 12 months to deactivate devices that had already reached end of support before the directive was issued.
  • Within 18 months, all EOS edge devices must be replaced with equipment that is actively supported and receives security updates.
  • Finally, within 24 months, continuous discovery and monitoring processes must be created to promptly identify devices approaching the end of support.

Although it concerns the US, the message is global

Although the requirements of BOD 26-02 directly apply only to FCEB services, CISA calls on all organizations, public and private, to follow the same practices.

See also: CISA withdraws 10 Emergency Directives

The reality is that attacks on edge devices have increased dramatically, as they are the "gateway" to corporate networks and often remain neglected for years.

CISA orders federal agencies to replace EOS network devices

Previous CISA initiatives and the war on ransomware

This is not the first time CISA has taken action. In June 2023, it issued BOD 23-02, requiring federal agencies to secure misconfigured or internet-exposed management interfaces.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In addition, the service has announced a Ransomware Vulnerability Warning Pilot (RVWP), through which it notifies critical infrastructures when vulnerable devices are detected on their networks.

Lifecycle management as a new priority

The new CISA guidance clearly shows that cybersecurity is not just about antivirus and firewalls, but also about the proper management of the equipment itself. “Old” devices without support are today one of the easiest targets for large-scale attacks.

The message is clear: if a device is not updated, it should not be on the network.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS