Israel Issues Urgent Cybersecurity Guidelines for Remote Access Systems

The Israel National Cyber Directorate has released new instructions for organizations to strengthen VPNs, ZTNA systems, and firewalls amid rising cyber threats, as APT groups increasingly target remote access infrastructure as an entry point into network

Israel Issues Urgent Cybersecurity Guidelines for Remote Access Systems

Illustration: Dan Nelson via Pexels.com

The Israel National Cyber Directorate has issued new guidelines for organizations in light of the ongoing state of emergency, emphasizing the need to strengthen the security of remote access equipment to organizational networks, such as VPNs, ZTNA systems, and firewall solutions.

According to the guidelines, such equipment represents a primary target for state-backed and other threat actors, who use it as an initial entry point into organizational networks. The Directorate notes that in recent years there has been an increased use of artificial intelligence tools to rapidly identify and exploit vulnerabilities in these systems. It further warns that these attack methods are not limited to any specific vendor and may be directed at a wide range of organizational communication and network equipment.

Among the immediate instructions issued to organizations are the disabling of management interfaces accessible from the internet (WAN), restricting remote access to predefined trusted IP addresses only, and changing all user passwords, with a particular focus on administrative accounts. Organizations are also urged to ensure the use of strong, non-default passwords.

The Directorate also calls for mandatory multi-factor authentication (2FA), limiting failed login attempts, and considering the replacement of encryption keys in sensitive systems. In addition, it emphasizes the need for continuous software updates and the immediate installation of security patches upon release.

The guidelines further recommend continuous log monitoring and anomaly detection, retaining logs for a period of at least one to three months, and enabling IPS mechanisms where possible. Geographic access restrictions (Geo-Location) are also recommended, alongside tightening user permissions following successful authentication.

The Cyber Directorate stressed that end-of-life (EOL) equipment may contain significant vulnerabilities and recommended evaluating its replacement as soon as possible. It also noted that access to organizational systems should be limited strictly to the services and resources required for operational needs.

Securing remote access infrastructure is no longer just an IT best practice—it is a vital component of national and organizational resilience. State-backed actors are increasingly leveraging artificial intelligence to rapidly expose network vulnerabilities.

This threat is particularly acute given the persistent and evolving nature of the Iranian cyber threat, where state-sponsored advanced persistent threats (APTs) and affiliated hacktivist collectives frequently target internet-facing edge devices, VPNs, and firewall solutions to achieve initial access, execute disruptive wiper operations, or sow psychological terror.