Faith-Based Daily Awareness Post 3 September 2026

Faith-Based Security Headlines

These updates are shared to help raise the situational awareness of Faith-Based organizations to best defend against and mitigate the impacts from all-hazards threats including physical security, cybersecurity, and natural disasters.

 

 

Reminder: There will be no DAP Friday September 4th or Monday September 7th. Regular reporting will resume Tuesday September 8th.

 

Iran hackers vow ‘numerous’ U.S. infrastructure attacks in response to strike that hit wedding

 

Iran-linked hacking group APT IRAN reportedly renewed threats against U.S. critical infrastructure after a U.S. missile strike in southern Iran allegedly hit a wedding, killing five people and injuring dozens more. The group claimed its retaliation could include disruptions to drinking water, mobile phone and internet networks, and energy, gas, and electricity infrastructure. The threats follow recent claims by APT IRAN and the IRGC-linked CyberAv3ngers of cyber activity targeting U.S. municipal water systems and warnings of future attacks against the water, energy, and telecommunications sectors. While the group has not provided public evidence of successful follow-on attacks, the messaging underscores the continued risk that geopolitical tensions with Iran could translate into cyber threats against operational technology and critical infrastructure operators in the United States.

 

Analyst Comments: This is a reminder that houses of worship cannot operate normally if essential services such as electricity or water are disrupted. Even when a cyber threat is aimed at utilities or other critical infrastructure rather than directly at faith-based organizations, the impacts can still affect worship services, facility operations, communications, safety systems, and the ability to support congregants and communities.

 

CISA scraps 6 free cybersecurity assessments for critical infrastructure operators

 

CISA is ending six free cybersecurity assessment services for critical infrastructure operators, including:

  • Cyber Resilience Reviews
  • Cyber Resilience Essentials surveys
  • Ransomware Readiness Assessments
  • Incident Management Reviews
  • External Dependencies Management Assessments
  • Cyber Infrastructure Surveys.

 

The agency said it is retiring some legacy questionnaire-based assessments to reduce redundancy and improve its services, but the move comes amid broader concerns about CISA’s reduced workforce and its ability to support infrastructure partners. The assessments previously gave operators access to regional CISA advisers, structured reviews, use of the Cyber Security Evaluation Tool, and reports with recommended security improvements. The decision could leave some organizations with fewer no-cost opportunities to identify vulnerabilities, evaluate resilience, and strengthen cyber preparedness.

 

Analyst Comments: The removal of these free assessment services may make it more difficult for some organizations to identify cyber gaps and improve resilience without added cost or outside support.

 

Houses of worship should still consider having cybersecurity assessments conducted periodically, whether through grants, vendors, nonprofit partners, sector partners, insurers, or other qualified third parties, to help understand vulnerabilities and prioritize practical improvements.

More Security-Focused Content

The FB-ISAO’s sponsor Gate 15 publishes a daily newsletter called the SUN. Curated from their open source intelligence collection process, the SUN informs leaders and analysts with the critical news of the day and provides a holistic look at the current global, all-hazards threat environment. Ahead of the daily news cycle, the SUN allows current situational awareness into the topics that will impact your organization.