CISA Launches RVWP, a New Ransomware Warning Pilot Program Designed for Critical Infrastructure Entities

The News: The U.S. Cybersecurity & Infrastructure Security Agency (CISA) recently unveiled the Ransomware Vulnerability Warning Pilot (RVWP) program designed to help critical infrastructure entities protect their information systems from ransomware attacks. The RVWP program intends to alert agencies of attack surface vulnerabilities that could be used by ransomware threat actors so security teams are able to mitigate bugs as soon as possible. See more from CISA here.

CISA Launches RVWP, a New Ransomware Warning Pilot Program Designed for Critical Infrastructure Entities

Analyst Take: The move by CISA to launch RVWP, a new ransomware warning pilot program for critical infrastructure entities is news many organizations should be excited about.

According to Comparitech, ransomware attacks on U.S. government organizations cost over $70 billion from 2018 to October 2022. Between 2018 and October 2022, 330 individual ransomware attacks were carried out against U.S. government organizations, potentially impacting more than 230 million people and costing an estimated $70 billion in downtime alone. Threatpost research found unpatched vulnerabilities spurred 82% of cyberattacks during the first half of 2022 and sadly, these attacks were largely preventable. These targeted exploits, however, are attractive to cybercriminals and remain a prevalent target for critical infrastructure.

This is why the announcement by the CISA of the launch of the RVWP program is great news in the fight against ransomware attacks. CISA’s RVWP program is designed to help critical infrastructure entities protect their information systems from ransomware attacks. This is key, as many organizations are not even aware that a vulnerability used by ransomware threat actors is present on their network, which is where the value prop of the RVWP lies. CISA’s RVWP program intends to alert agencies of attack surface vulnerabilities that could potentially be used by ransomware criminals, so security teams are able to mitigate bugs as soon as possible.

CISA’s RVWP program should provide much-needed assist to organizations like hospitals, school districts, utilities, and government entities, to name just a few, who are often somewhat challenged by the availability of adequate resources and/or skilled tech talent to help with risk mitigation, and even mitigation as fundamental as identifying unpatched systems and endpoint vulnerabilities.

The healthcare industry is particularly vulnerable with a heavy reliance on medical devices that are built on legacy systems or operating on products in end-of-life stages leading to complex device security patch management challenges. School districts and government entities at the local level are likewise challenged by legacy operating systems and a lack of IT knowledge to help navigate what are increasingly complex times as instances of ransomware rapidly increase. The good news — for the healthcare sector anyway — is that the FDA, which establishes medical device security requirements for manufacturers, now requires manufacturers to make sure new devices are designed with security in mind, also known as security by design principles.

CISA’s RVWP program was created in response to the Cyber Incident Reporting for Critical Infrastructure Act, or CIRCIA, a 2022 law that required CISA to “develop and implement regulations requiring covered entities to report covered cyber incidents and ransomware payments” to the agency.

How Will it Work?

Through CISA’s RVWP program, the organization will leverage its existing services, data sources, technologies, and authorities to proactively identify systems that contain security vulnerabilities most commonly associated with ransomware attacks.

This includes CISA’s Cyber Hygiene Vulnerability Scanning service and the Administrative Subpoena Authority granted to CISA under Section 2209 of the Homeland Security Act of 2002. Once CISA identifies affected systems, CISA regional cybersecurity personnel will notify system owners of their security vulnerabilities enabling timely mitigation before damaging intrusions occur. Regional personnel may also provide both assistance and resources to mitigate the vulnerability,

According to CISA, notifications will provide critical information about systems identified as vulnerable, including the device model and manufacturer, IP address being used, how the vulnerability was detected, along with advice and guidance on mitigating the vulnerability. This is exciting news and a move I believe should provide a significant assist to organizations battling vulnerabilities as a whole and working to mitigate risk.

Sounds great, but will it work? As to be expected, CISA has been very involved in testing the RVWP program, kicking it off by notifying 93 organizations identified as running instances of Microsoft Exchange Service with a vulnerability called “ProxyNotShell,” which has been widely exploited by ransomware actors. This initial round of notifications demonstrated the effectiveness of this model in enabling timely risk reduction as CISA further scales the RVWP program to additional vulnerabilities and organizations.

Want to learn more about this pilot program and perhaps get your company involved in CISA’s RVWP program? Interested organizations can email [email protected] to explore getting involved.

Wrapping up, ransomware cost an estimated $70 billion in downtime alone in 330 individual ransomware attacks carried out against U.S. government organizations between 2018 and October 2022, potentially impacting more than 230 million people. The launch of CISA’s RVWP program, designed to proactively warn critical infrastructure entities of unpatched vulnerabilities leaving them at risk of a ransomware attack is a big step forward by the federal government, providing not only a significant assist, but also some much-needed good news in the fight against ransomware.

Disclosure: The Futurum Group is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of The Futurum Group as a whole.

Other insights from The Futurum Group:

Tanium Converge 2022 Recap: Converged Endpoint Management, the Convergence of ITOps and Security, and Highlighting Key Partnerships

Splunk is Championing Careers in IT and Cybersecurity

Decentralized Storage in the Battle Against Ransomware

Author Information

Shelly Kramer is a serial entrepreneur with a technology-centric focus. She has worked alongside some of the world’s largest brands to embrace disruption and spur innovation, understand and address the realities of the connected customer, and help navigate the process of digital transformation.

Related Insights
IBM Q2 FY 2026: Software Growth Continues as Mainframe Purchases Slow
July 27, 2026

IBM Q2 FY 2026: Software Growth Continues as Mainframe Purchases Slow

Futurum Research analyzes IBM’s Q2 FY 2026 earnings, focusing on software mix, mainframe timing, AI demand, and revised FY 2026 guidance....
So This Is How AIs Attack- Observations From the OpenAI & Hugging Face Incident
July 24, 2026

So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident

Fernando Montenegro and Mitch Ashley, VPs at Futurum, read the OpenAI and Hugging Face agentic incident as a live test of enterprise readiness to detect and contain AI agents that...
ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth
July 23, 2026

ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth

Futurum Research analyzes ServiceNow Q2 FY 2026 earnings, focusing on AI Control Tower adoption, security expansion, and workflow demand....
Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment
July 23, 2026

Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment

Futurum Research analyzes Alphabet’s Q2 FY 2026 earnings, focusing on cloud AI demand, Gemini adoption, Search monetization, and rising AI infrastructure spending....
Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?
July 23, 2026

Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?

Mend.io's security team identified 199 malicious RubyGems and achieved complete takedown within hours, intercepting a cryptomining campaign before execution and demonstrating the critical importance of continuous open-source monitoring....
Hugging Face Breach: A Wake-Up Call for AI Agent Security
July 23, 2026

Hugging Face Breach: A Wake-Up Call for AI Agent Security

The Hugging Face breach reveals how autonomous AI agents exploit code flaws to harvest credentials and move laterally at machine speed. Enterprise leaders now recognize identity security as urgent, with...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.