Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

CISA acting director Madhu Gottumukkala outlines nine steps to protect against cyber threats

The Cybersecurity and Infrastructure Security Agency (CISA) · September 30, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Madhu Gottumukkala, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), presented practical guidance for individuals and organizations — including software updates, 16-character passwords, multifactor authentication, backups, encryption and reporting incidents to CISA.

Madhu Gottumukkala, acting director of the Cybersecurity and Infrastructure Security Agency (CISA), outlined practical cybersecurity steps in a presentation titled “Nine Ways to Stay Safe Online,” delivered for Cybersecurity Awareness Month. Gottumukkala framed the guidance as aimed at individuals, businesses and government entities, saying CISA “leads the national effort to understand, manage, and reduce risk to the cyber and physical infrastructure that Americans rely on every hour of every day.”

Gottumukkala front-loaded basic behaviors that she called essential for everyone: “Update your software,” “use strong passwords and a password manager,” “turn on multifactor authentication,” and “recognize and report phishing.” She urged installing updates promptly or enabling automatic updates because “updates fix known vulnerabilities.”

On passwords, Gottumukkala recommended long, random and unique credentials, advising the use of passphrases or at least 16-character passwords and endorsing password managers to generate and autofill strong passwords. She added that password managers can help defend against phishing by filling credentials only on legitimate sites.

Gottumukkala also pushed multifactor authentication (MFA) as a second layer of protection, advising its use on email, banking and social media accounts. “The most secure methods include physical security keys and authenticator apps with number matching,” she said.

To spot phishing, she advised skepticism of messages that create urgency, come from suspicious email addresses, or ask for personal information, and instructed recipients to verify, report, and delete suspicious messages rather than click links or open attachments.

For organizations and users who can go beyond basics, Gottumukkala recommended logging and monitoring to detect suspicious access in real time, a robust backup strategy following the 3-2-1 rule (three copies, two types of storage, one copy off-site), and encryption of devices, drives, and backups both at rest and in transit.

She encouraged reporting suspected cyber incidents to CISA, saying that “sharing threat information helps us all stay safer,” and provided the agency reporting page (cisa.gov/report) and a contact email (central@cisa.gov) for questions. Gottumukkala also noted that government entities can obtain no-cost .gov domains via get.gov and pointed listeners to further tools and guidance at cisa.gov/cybersecurity-awareness-month.

The presentation was instructional rather than regulatory: it offered practical steps and resources rather than announcing new rules or formal actions. The guidance is available on CISA’s public websites for organizations and individuals seeking to implement the recommended defenses.