How prepared is the defense industrial base for Iranian cyberattacks?
Iranian cyber actors have been targeting the Defense Industrial Base for years, and with Operation Epic Fury underway, the question now isn’t whether they’re coming. It’s whether the security requirements already on the books are actually equipped to stop them.
To answer that question, we mapped 130 real-world cyber techniques used by five known Iranian threat groups against the controls in NIST SP 800-171, the baseline security standard that underpins CMMC requirements. What we found should change how defense contractors think about compliance:
- 68% of known Iranian attack techniques can be mitigated through controls already in the baseline.
- Just four of those controls can mitigate every technique to some degree.
- 100% of Iranian techniques can be detected if you have the right monitoring in place.
Read more at RealClearDefense