Cyber Protection Strategies at the Edge

November 30, -0001 Mercury Systems

Traditional cybersecurity methods cannot fully protect edge-based devices. With data and the software supply chain under increasing attack and artificial intelligence and quantum computing intensifying as threats, governments and industry need to expand their guard with a cyber protection approach.

The threats are here. In 2024, for example, news outlets reported that the China-backed hacking group Salt Typhoon penetrated the networks of nine American telecommunications companies, including major cellular network providers Verizon and AT&T. Lax cyber controls and the targeting of edge-based devices such as routers, hardware firewalls and virtual private networks were common factors behind the attacks, according to the U.S. Cybersecurity and Infrastructure Security Agency.

CISA officials also warned that these kinds of targeted attacks on edge devices were increasing:

“State-sponsored cyber threat actors are targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging and military infrastructure networks. While these actors focus on large backbone routers of major telecommunications providers, as well as provider edge and customer edge routers, they also leverage compromised devices and trusted connections to pivot into other networks. These actors often modify routers to maintain persistent, long-term access to networks.”

Cyber threats to edge-based devices pose significant challenges for organizations and governments worldwide that rely on networks, systems and data for critical operations. Protection, however, requires more than just traditional cybersecurity, which is focused on prevention and detection. With a cyber protection approach, which is the combination of cybersecurity and data protection techniques, organizations can ensure systems and devices stay safe, operational, recoverable, and resilient no matter what type of intrusion or attack occurs. Here, we’ll examine key cyber protection strategies to protect and secure devices at the edge.

Key components of cyber protection

Cybersecurity emphasizes protecting networks and computer systems from threats. In contrast, a cyber protection approach takes greater account of the data and all system layers that need protection.

This includes:

Zero-trust security

A zero-trust approach requires all users and devices, inside and outside the network, to be authenticated and verified to gain access. By default, nothing is trusted and breaches are assumed.

Multilayered security

Assets are protected through multiple layers of security, both physical and technical. Examples include employee access cards, anti-tamper technology, firewalls and encryption.

Data encryption and access control

Data is encrypted in transit and at rest, making it accessible only to authorized users and unreadable to people who lack decryption keys.

Vulnerability management and penetration testing

Regular vulnerability assessments and penetration testing will help identify and address system weaknesses.

Incident response planning

A well-defined incident response plan enables quick, effective responses to cyberattacks and includes ways to access backed-up data.

Cybersecurity awareness training

Through regular training, personnel learn to protect data and systems by recognizing and avoiding phishing attacks, social engineering techniques and other cyber threats.

Cyber protection technologies and strategies for edge devices

CISA has warned that edge devices are prime hacker targets, and that end-of-support (EOS) devices that no longer receive updates and patches are a particularly exploitable risk. Protecting these devices with strong settings and configurations is critical for keeping threat actors from stealing data or disrupting or gaining control of operations. To secure edge devices, CISA recommends a six-step framework:

Govern: Identify people responsible for edge device security; create awareness of edge device threats; and refine cybersecurity policy and procedures to ensure proper operation, monitoring and configuration management of edge devices. Edge devices should also be incorporated into enterprise risk management programs.

Identify: Audit networks with an asset inventory that captures all edge devices and their EOS dates. Replace identified EOS devices and software via automated reminders. Procure new or replacement devices developed with security-by-design principles.

Protect: Adopt robust authentication and access management practices, secure all credentials, change default credentials on new devices, apply vendor-recommended secure configurations and promptly apply updates to address known vulnerabilities. Protection also includes segmenting networks so edge devices are isolated from critical systems and adopting least-privilege access controls and zero-trust principles. Other recommended protection methods include disabling services, ports and other risky and unnecessary services; removing internet-exposed management interfaces; adding zero-trust capabilities; and regularly backing up and testing device configurations and firmware.

Detect: Organizations should regularly search for known signals of compromise and threat actor tactics and techniques and establish a baseline for normal network and activity. This aids in monitoring network traffic, device configurations, memory, firmware, terminal logs and remote access protocols for suspicious activity and anomalies. These anomalies include configuring and monitoring net flow to detect lateral movement from edge devices to internal networks. Edge device configurations should also be audited regularly to detect unsanctioned changes such as illicit tunnels; packet capture settings; static routes; unauthorized accounts and authentication methods; cryptography settings changes; and reconfigured remote management or file transfer functionality.

Respond: Consider unexpected activity on edge devices to be high-risk and investigate the following as soon as possible: configuration changes; reboots; modifications of access control lists; account and password changes; tunnels/traffic forwarding and unauthorized packet capture; outbound connections; large data transfers; log clearing; and serialization errors. Promptly respond to suspicious activity and incidents with comprehensive eviction and eradication measures including isolating devices, disabling accounts and services, modifying configurations and blocking malicious traffic. Report all incidents immediately through CISA’s Incident Reporting System.

Recover: Restore compromised systems from the last known safe backup or reset configurations. This may include factory resetting affected devices and securely reimaging them by reinstalling trusted and verified firmware and software.

Preventing downtime and data loss with resistance and resilience

Mercury Systems is the leader in making trusted, secure mission-critical technologies profoundly more accessible to aerospace and defense. Its RelianceOne™ solution protects critical data and applications against disruption, inspection and reverse engineering even if an adversary gains physical or remote access to a system. RelianceOne, designed using a threat model that assumes an attacker will gain root (admin) access to your system, acts as a last line of defense for cyber prevention. Learn more about how Mercury System solutions such as RelianceOne can help maintain your critical data and configurations’ integrity and confidentiality.

 

Previous Article
Cyber hardening support for DoW
Cyber hardening support for DoW

Mercury secures DoD aircraft systems against quantum threats, accelerating ATO timelines to protect critica...

Next Article
Linux Kernal “Copy Fail” Vulnerability: How to Mitigate with RelianceOne™ for Linux
Linux Kernal “Copy Fail” Vulnerability: How to Mitigate with RelianceOne™ for Linux

Discover how the Linux "Copy Fail" vulnerability (CVE-2026-31431) grants root access and why RelianceOne en...