US Federal Agencies Must Remove Vulnerable Edge Devices, CISA Warns

These devices, which do not receive vendor support, face a ‘substantial and constant’ threat of exploitation, the agency said.
US Federal Agencies Must Remove Vulnerable Edge Devices, CISA Warns
Cooling vent fans on the roof next to generators on the lower level of a Digital Realty data center in Ashburn, Va., on Nov. 12, 2025. Andrew Caballero-Reynolds/AFP via Getty Images
|Updated:

All federal government agencies must take steps to minimize risks posed by cyber threat actors to “edge” devices in their networks that are not currently supported by vendors, the Cybersecurity and Infrastructure Security Agency (CISA) said in a Feb. 5 directive. This includes decommissioning such components.

The binding operational directive (BOD) issued by CISA is “a compulsory direction to federal, executive branch, departments and agencies,” according to the directive, and is intended to protect federal information systems and data.