TODO: Your Name Security engineer writing about critical infrastructure, surveillance, and the people they fail.

How to read a CISA advisory without overclaiming

An advisory tells you less than the coverage of it usually implies. A short guide to what these documents assert, what they only suggest, and where the seams are.

  • method
  • attribution

A joint advisory is a consensus document written by several agencies with different equities, and it shows. The gap between what one of these actually asserts and what the coverage says it asserts is where most bad infrastructure reporting lives. A few habits close it.

Separate the observed from the assessed

Advisories are careful with verbs, and the care is meaningful. “Observed” and “identified” describe things an agency saw in incident response data. “Assess” carries a confidence judgement. “May” and “could” often describe capability rather than anything witnessed in the wild.

When a piece of coverage turns an assessment into a flat statement of fact, the error usually entered right there. Quote the verb.

Attribution in an advisory is not attribution by the government

An advisory describing activity as “associated with” or “affiliated with” a state is doing something narrower than a formal, public attribution — which tends to arrive later, through an indictment, a sanctions designation, or a statement from a named official.

Private-sector attribution is narrower still. A vendor sees its own telemetry: its customers, its sensors, its incident response engagements. That can be excellent evidence and it is also a partial view, shaped by who buys the product. Neither is worthless and neither is confirmation. Say which one you have.

Read the mitigations backwards

The mitigations section is the most quietly informative part of the document. If it recommends removing a device from the public internet, that tells you the affected population was reachable from the public internet. If the advice is about default and shared credentials, that’s what the responders kept finding.

If there’s no patch in the list — only segmentation, monitoring, and manual fallback — the vendor has no fix, and the story is about the installed base and the replacement budget, not about a bug.

Check the KEV entry and the dates

If the CVE is in the Known Exploited Vulnerabilities catalog, the date it was added bounds when exploitation was confirmed. Compare that to the disclosure date and the vendor’s advisory date. That interval — sometimes years — is very often the actual story: not that a flaw existed, but how long it stayed exploitable in the field after everyone involved knew.

Find who the document is written for

Advisories are aimed at operators with a security team. A significant share of the affected fleet — small water and wastewater utilities especially — has no security team, no maintenance window, and no capital budget. “Apply the vendor update” is a different instruction depending on who receives it.

Reporting the mitigation list without reporting who can actually execute it gets the story backwards.

The habit that matters most

Go to the advisory itself and read all of it, including the technical appendix and the revision history. Aggregator summaries drop hedges, compress confidence language, and inherit each other’s mistakes. Reading the primary document is the entire difference between journalism and repackaging.

← All writing