Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CISA, NSA Issue Guidance to Strengthen Microsoft Exchange Server Security

by Arthur McMiler
November 3, 2025
in Cybersecurity, Department of War, DHS, News
Nick Andersen, an official at CISA. Andersen highlighted the value of cybersecurity practices on Microsoft Exchange servers

Nick Andersen, executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency

The Cybersecurity and Infrastructure Security Agency and the National Security Agency, along with global cybersecurity partners, have issued new guidance outlining best practices to secure Microsoft Exchange servers against cyberattacks. 

Table of Contents

    • You might also like
    • DOE Opens Competition for ORISE Management Contract
    • Bipartisan Lawmakers Press House Leadership for Immediate Action on AI Risks
    • Near-Unanimous House Passes Ratepayer Protection Act to Curb Data Center Energy Costs
  • What Are the Roadmap’s Suggested Cybersecurity Steps?
  • Additional Guardrails Through Zero Trust Principles

You might also like

DOE Opens Competition for ORISE Management Contract

Bipartisan Lawmakers Press House Leadership for Immediate Action on AI Risks

Near-Unanimous House Passes Ratepayer Protection Act to Curb Data Center Energy Costs

The release is part of an ongoing collaboration between U.S. and allied cybersecurity agencies to counter evolving threats to critical infrastructure and national security, CISA said Thursday.

CISA, NSA Issue Guidance to Strengthen Microsoft Exchange Server Security

Cyber defense driven by artificial intelligence will be among the topics for discussion at the Potomac Officers Club’s 2025 Homeland Security Summit on Nov. 12. Book your seat now for this Nov. 12 conference, with top representatives from industry and government agencies set to exchange views on building a resilient homeland security enterprise.

The 15-page document, titled Microsoft Exchange Server Security Best Practices, expands on CISA’s earlier Emergency Directive 25-02 and provides technical recommendations for organizations using on-premises Exchange or hybrid environments.

What Are the Roadmap’s Suggested Cybersecurity Steps?

The guidance urges organizations to enforce a prevention posture, emphasizing principles such as least privilege, deny-by-default and timely patching. It calls for maintaining regular security updates and enabling Microsoft’s Emergency Mitigation Service to reduce system vulnerabilities.

It also recommends applying security baselines across Exchange servers, operating systems and mail clients to maintain consistent configurations and quickly identify deviations. Agencies, such as the Defense Information Systems Agency, the Center for Internet Security and Microsoft, have published baseline templates that network administrators can follow.

The document further suggests enabling built-in protections, including Microsoft Defender Antivirus, Antimalware Scan Interface, Attack Surface Reduction, AppLocker and Exchange’s own anti-spam and anti-malware tools.

Additional Guardrails Through Zero Trust Principles

Additional measures—such as restricting administrative access, implementing multifactor authentication, enforcing transport security and adopting zero-trust principles—can further strengthen defenses, according to the guidance. CISA and NSA also warned that some Exchange Server versions have reached end-of-life and urged organizations to take proactive steps to mitigate associated risks.

“With the threat to Exchange servers remaining persistent, enforcing a prevention posture and adhering to these best practices is crucial for safeguarding our critical communication systems,” said Nick Andersen, executive assistant director for CISA’s cybersecurity division. “This guidance empowers organizations to proactively mitigate threats, protect enterprise assets and ensure the resilience of their operations,” the agency official stressed. 

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Hegseth Plans to Shift Pentagon’s Arms Sales Office to Acquisition Leadership

Next Post

Johns Hopkins APL Launches GenWar Lab to Advance AI-Driven Wargaming

Recommended For You

NARA’s John Fitzpatrick Joins National Security Council as Info Security Mgmt Senior Director

by Jane Edwards
July 23, 2026
NARA’s John Fitzpatrick Joins National Security Council as Info Security Mgmt Senior Director

John Fitzpatrick, formerly director of the information security oversight office at the National Archives and Records Administration, has been named senior director for records access and information security...

Read moreDetails

Battelle CCDS Passed 3M Respirator Test; Lou Von Thaer Quoted

by Sarah Sybert
July 17, 2020
Lou Von Thaer

The Battelle Critical Care Decontamination System (CCDS) has passed both filtration efficiency and fit-related evaluations for its 1860 and 8210 3M respirators, Battelle CCDS reported on Thursday. 

Read moreDetails

CISA’s Kirk Lawrence on Secure by Design Framework

by Jane Edwards
June 16, 2025
CISA's Kirk Lawrence on Secure by Design Framework

Kirk Lawrence, program manager for the Secure by Design initiative at the Cybersecurity and Infrastructure Security Agency, said implementing Secure by Design principles is the first step in...

Read moreDetails

NIH Invests in Research Efforts at Morgan State University

by Nichols Martin
August 13, 2019
NIH Invests in Research Efforts at Morgan State University

The National Institutes of Health has awarded a total of $35M in grants to Morgan State University for academic research efforts including training and the establishment of an innovation center....

Read moreDetails

Sean Duffy Named Interim NASA Administrator

by Jane Edwards
July 10, 2025
Transportation Secretary Sean Duffy has been named NASA's interim chief

Reuters reported Wednesday that President Donald Trump appointed Transportation Secretary Sean Duffy as interim NASA administrator."Sean is doing a TREMENDOUS job in handling our Country's Transportation Affairs ......

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Emerging Tech
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence Community
    • DHS
    • Federal Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!