Looking for the latest information security and privacy insights from EXTEND? Follow us on LinkedIn.
Dark blue graphic with red padlock and the words privacy, security, and identity.

New Report Highlights Tribal Sector Cybersecurity Threats and Leaders’ Concerns

82% of Tribal Sector organizations use an information security framework.

Yet, the average cybersecurity maturity score among Tribal Sector organizations is only 3.76 on a 1-7 scale – a grade of about 54%.

Report Cover: The 2024 MS-ISAC® Tribal Sector Cybersecurity Report A new report from the Center for Internet Security (CIS) and the Multi-State Information Sharing and Analysis Center (MS-ISAC) highlights these statistics. The report data is based on a recent Nationwide Cybersecurity Review (NCSR) assessment in which 22 Tribal sector organizations participated.

The report outlines the many challenges Tribal sector organizations face when protecting the sensitive information they handle. With large pools of financial, healthcare, legal, personally identifiable information (PII), and other data in their information systems (not to mention those of their third parties), Tribal organizations are a natural target for a wide variety of cybersecurity threats and cyber-crime, including business email compromise, phishing, malware, and ransomware attacks.

Download the complete report here.

Raising Top Tribal Sector Cybersecurity Concerns

Information security leaders and others who participated in the cybersecurity review noted several concerns about their current cyber defense programs. More than half of the review participants stated three concerns at the top of their list that keep them up at night:

  • Lack of documented processes (91% of participants),
  • Increasing threat sophistication (59% of participants), and
  • Insufficient funding (55% of participants).

Perhaps most alarming and what could be an indicator of potential for security incidents, 45% of participants indicated that “we are focused on operations, but we really don’t have a cybersecurity strategy.”

IT tribal sector cybersecurity experts and leaders are brainstorming ways they can work to resolve cybersecurity concerns and determine immediate actions they can take to improve cyber defenses.

The quest to mitigate cyber risks and build confidence in their cybersecurity program is top of mind in the Tribal sector. At the recent 25th annual TribalNet 2024 conference, cybersecurity was a popular topic across the session agenda, where attendees and panelists discussed security awareness best practices, employee engagement, ways leaders can set the stage for a cyber-aware organizational culture, cybersecurity KPIs, building a vulnerability management program, and more.

How can Tribal Sector cybersecurity leaders evaluate their risk and program effectiveness?

Ultimately, improving an organization’s security posture begins with assessing the strength of its cybersecurity program: Its strategy, governance processes, risk management, compliance status, and incident preparedness.

Organizations often look to an experienced team of cybersecurity professionals, such as those at EXTEND Resources, to assess their overall program, identify and analyze security gaps and vulnerabilities, and design an improvement plan. Leveraging independent consultants for this work supports an unbiased review, a transparent report of the current state of their program, and a level of credibility that helps organizations move forward in their improvement plans.

To prepare for such an evaluation, you can start by answering a few high-level self-evaluation questions. Gather your team and consider the questions below.

  • What is our organization’s risk tolerance? Is it documented, and how is it used in our cyber operations?
  • What is our process for identifying risks, and are we confident that our list is complete?
  • How are we prioritizing risk responses and investments? How do we know if our approach is working?
  • What cybersecurity roles have we established? How are we engaging our staff and third-party stakeholders?
  • Have we identified and documented external information systems where our data is stored?
  • Do we have well-tested incident response and disaster recovery plans? Do they incorporate lessons learned?

Stepping Up the Game: Cyber Threats, Responses, and Lessons Learned

The 2024 MS-ISAC® Tribal Sector Cybersecurity Report sounds the alarm about the cybersecurity risks facing Tribal Nations across the U.S. The report shows that these communities must do a better job of protecting themselves from cyberattacks.

The report suggests that Tribal Nations should adopt cybersecurity frameworks and regularly check their defenses. By following these steps, Tribal Nations can better protect their communities from cyber threats.

Download the report to learn the answers to these questions, inform future cybersecurity strategies, and more:

  • How are Tribal organizations responding to specific threats?
  • What lessons did they take away from this report?
  • Where are the most significant and highest-value opportunities to improve Tribal Sector Cybersecurity?

Link to downloadable report.

Read the press release announcing the report.

About EXTEND Resources

EXTEND Resources can help you create a tailored approach to cybersecurity that is unique to the needs of your specific Tribal organization. Our vCISO services leverage a disciplined, integrated cybersecurity risk management approach to assess your cyber risk, identify security gaps, and design a plan to effectively mitigate those risks and enhance the overall security posture — based on your budget and timeline.

About the MS-ISAC

Multi-State Information Sharing and Analysis Center® (MS-ISAC) has been designated by the Cybersecurity & Infrastructure Security Agency (CISA) as the key resource for cyber threat prevention, protection, response, and recovery for all U.S. State, Local, Tribal, and Territorial (SLTT) governments.

About CIS

The Center for Internet Security, Inc. (CIS®) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit, responsible for the CIS Critical Security Controls® and CIS Benchmarks™, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats. Our CIS Hardened Images® provide secure, on-demand, scalable computing environments in the cloud. CIS is home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), the trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial government entities, and the Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®), which supports the rapidly changing cybersecurity needs of U.S. election offices.

Scroll to Top
Skip to content