CyberzSOC

Publication detail
← Back to advisories & guidance

CSI: Security Considerations for Edge Devices: Executive Guidance ↗ source

February 3, 2025 NSA Guidance
Co-sealed by: ASD/ACSC, CCCS, CISA, FBI, NCSC-NZ, NCSC-UK, NSA

Summary

Mitigation strategies for edge Malicious actors are increasingly targeting internet-facing edge devices to gain unauthorised access to networks; therefore, it is vital that organisations prioritise securing edge devices in their environments. Edge devices are critical network components that serve as security boundaries between internal enterprise networks and the internet. The most commonly observed edge devices implemented across enterprise networks include enterprise routers, firewalls, and VPN concentrators. These devices perform essential functions such as managing data traffic, enforcing security policies, and enabling seamless communication across network boundaries. Positioned at the network’s periphery—often referred to as “the edge”—these devices connect an internal, private network and a public, untrusted network like the internet. Failing to secure edge devices is like leaving a door open from the internet to internal networks, potentially allowing malicious actors to gain access to networks – from there, they can access sensitive data and disrupt If organisations have not applied zero trust principles in their environments, malicious actors can use a range of techniques to gain access through network edge devices.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.