Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Cybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and ResilienceCybersecurity & Infrastructure Security Agency logo America’s Cyber Security Defense Agency National Coordinator For Critical Infrastructure Security and Resilience
CISA Logo

Search

 

America's Cyber Defense Agency
 
  • Topics
    Cybersecurity Best Practices
    Cyber Threats and Advisories
    Critical Infrastructure Security and Resilience
    Election Security
    Emergency Communications
    Industrial Control Systems
    Information and Communications Technology Supply Chain Security
    Partnerships and Collaboration
    Physical Security
    Risk Management
    How can we help?
    GovernmentEducational InstitutionsIndustryState, Local, Tribal, and TerritorialIndividuals and FamiliesSmall and Medium BusinessesFind Help LocallyFaith-Based CommunityExecutivesHigh-Risk Communities
  • Spotlight
  • Resources & Tools
    All Resources & Tools
    Services
    Programs
    Resources
    Training
    Groups
  • News & Events
    News
    Events
    Cybersecurity Alerts & Advisories
    Directives
    Request a CISA Speaker
    Congressional Testimony
    CISA Conferences
    CISA Live!
  • Careers
    Benefits & Perks
    HireVue Applicant Reasonable Accommodations Process
    Hiring
    Resume & Application Tips
    Students & Recent Graduates
    Veteran and Military Spouses
  • About
    Divisions & Offices
    Regions
    Leadership
    Doing Business with CISA
    Site Links
    CISA GitHub
    CISA Central
    Contact Us
    Subscribe
    Transparency and Accountability
    Policies & Plans

Free Cyber ServicesSecure by design Secure Our WorldShields UpReport A Cyber Issue

Breadcrumb
  1. Home
  2. Topics
  3. Cyber Threats and Advisories
  4. Incident Detection, Response, and Prevention
Share:
An abstract image showing cyber code

Incident Detection, Response, and Prevention

Rapid, effective cyber incident detection, response, and prevention is a critical facet of ensuring our national security.

Cyber Threats and Advisories

  • Malware, Phishing, and Ransomware
  • Shields Ready
  • Shields Up
  • Incident Detection, Response, and Prevention
  • Information Sharing
  • Securing Networks
  • Nation-State Cyber Actors

Overview

Cyber incidents are capable of demonstrable harm to the national security interests, foreign relations, or economy of the United States or to the public confidence, civil liberties, or public health and safety of the American people. Because of this risk, all organizations and even individuals should have clear, executable cyber incident detection, response, and prevention strategies. Cyber attacks are evolving and becoming increasingly complex and hard to detect. By working with all levels of government and the private sector, CISA understands the broad range of cyber vulnerabilities and offers the tools and resources needed to detect, respond to, and prevent cyber incidents accurately and effectively.

CISA’s Role

When cyber incidents occur, CISA provides response efforts to mitigate spread of the attack and secure critical infrastructure components. CISA works in close coordination with other agencies with complementary cyber missions, as well as private sector and other non-federal owners and operators of critical infrastructure, to ensure greater unity of effort and a whole-of-nation response to cyber incidents.

We provide awareness of vulnerabilities, mitigation, and prevention steps to American homes and organizations, and have programs dedicated to helping impacted organizations. We also work to notify relevant stakeholders of elevated risk exposure, conduct incident management operations, provide vulnerability assessments, and directly deploy risk management information, tools, and technical services to mitigate risk, including regulatory enforcement where authorized.

Featured Content

Situational Awareness and Incident Response (SAIR) Program

Obtain products and services that address gaps in the long-term security posture of the federal government using the SAIR program's federal enterprise awareness and incident response capabilities. 

Continuous Diagnostics and Mitigation (CDM) Program

Improve your security posture with CDM program cybersecurity tools, integration services, and dashboards designed to dynamically fortify the cybersecurity of government networks and systems. 

Free Cybersecurity Services & Tools

Proactively reduce exposure to threats and mitigate attack vectors with CISA's free cybersecurity services and tools.

CISA Releases Directive on Reducing the Significant Risk of Known Exploited Vulnerabilities

Learn how to use CISA's Known Exploited Vulnerability (KEV) catalog to protect your organization and build a collective resilience across the cybersecurity community.

CISA in Action

Discover how CISA's incident detection, response, and prevention strategies and recommendations help ensure the security of our nation.

View All Cyber Threats and Advisories News

CISA Update on Treasury Breach

JAN 06, 2025 | PRESS RELEASE

AI Red Teaming: Applying Software TEVV for AI Evaluations

NOV 26, 2024 | BLOG

CISA’s ScubaGear Tool Improves Security for Organizations Using M365 and Surpasses 30,000 Downloads

NOV 13, 2024 | BLOG

Engaging with Security Researchers: Embracing a “See Something, Say Something” Culture

OCT 23, 2024 | BLOG
View All Cyber Threats and Advisories News

Incident Detection, Response, and Prevention Training

CISA offers a variety of trainings to help you and your organization proactively prepare for and rapidly respond to cyber incidents.

View All Cyber Threat and Advisories Training

Strengthen Your Resolve - Understanding DNS Attacks

VIRTUAL/ONLINE
We depend on DNS infrastructure to securely route us to our intended destinations. While this shared infrastructure is incredibly powerful and useful, it also presents a rich attack surface for threat actors. This webinar provides an organizational perspective and topic overview that may be useful to technical specialists.

Incident Response and Awareness Training

CUSTOMIZABLE | VIRTUAL/ONLINE
Awareness webinars are cybersecurity topic overviews for a general audience including managers and business leaders, providing core guidance and best practices to prevent incidents and prepare an effective response if an incident occurs.
Visit CISA Learning
View All Cyber Threat and Advisories Training

Services

CISA services offer tailored expertise and guidance based on your organization's needs and requirements.

View All Incident Detection, Response, and Prevention Services

Cyber Threat Hunt Assessment

INCREASE YOUR RESILIENCE
Contact: justiceitservices@usdoj.gov
This Assessment provides agencies with the ability to proactively search through networks and systems to identify threats that have already bypassed network defenses and established a foothold.
Foundational

Vulnerability Disclosure Policy (VDP) Platform

INCREASE YOUR RESILIENCE
Contact: vdpplatform@mail.cisa.dhs.gov
The VDP Platform enables agencies to receive actionable vulnerability information and collaborate with the public to improve the security of their internet-accessible systems.
Foundational
View All Incident Detection, Response, and Prevention Services

Resources, Tools, and Publications

CISA offers guides, tools, and other resources to support incident detection, response, and prevention.

View All Incident Detection, Response, and Prevention Resources
An icon showing services and programs on a computer

The KEV Catalog

PUBLICATION
A list of Known Exploited Vulnerabilities.
View Files

Incident Reporting System

EXTERNAL
Report computer security incidents directly to CISA using the incident report form. Complete the fields as accurately as possible to help CISA investigate and mitigate the cyber risks.
https://us-cert.cisa.gov/forms/report

Cyber Incident Detection and Notification Planning Templates for Election Security

PUBLICATION
Incident response and notification templates can be tailored to fit the exact needs of each jurisdiction.
Additional Translations Available
Download File (PDF, 865.9 KB)
View All Incident Detection, Response, and Prevention Resources

Report an Incident

Report incidents as defined by NIST Special Publication 800-61 Rev 2, to include:

  • Attempts to gain unauthorized access to a system or its data
  • Unwanted disruption or denial of service
  • Abuse or misuse of a system or data in violation of policy

The definitions and reporting timeframes can be found in the Federal incident notification guidelines. 

Report an Incident
Return to top
  • Topics
  • Spotlight
  • Resources & Tools
  • News & Events
  • Careers
  • About
Cybersecurity & Infrastructure Security Agency
  • Facebook
  • X
  • LinkedIn
  • YouTube
  • Instagram
  • RSS
CISA Central 1-844-Say-CISA SayCISA@cisa.dhs.gov
DHS Seal
CISA.gov
An official website of the U.S. Department of Homeland Security
  • About CISA
  • Budget and Performance
  • DHS.gov
  • FOIA Requests
  • No FEAR Act
  • Office of Inspector General
  • Privacy Policy
  • Subscribe
  • The White House
  • USA.gov
  • Website Feedback