CISA And NSA Issue New Guidance To Prevent “Persistent” Microsoft Exchange Threats

CISA and the NSA have released a guide to help businesses harden their on-prem Exchange servers.

Published on Oct 31, 2025
Caitlin Harris Written by Caitlin Harris
CISA And NSA Reveal New MS Exchange Server Security Guidance

CISA, the National Security Agency and international partners have issued a new guide to help businesses protect their on-premises Exchange servers against cyberthreats.

Many organizations rely on Microsoft Exchange as their primary method of business communication, making the service an attractive target for cybercriminals. 

The newly published guide includes recommendations to help organizations proactively protect sensitive information and prevent the exploitation of misconfigurations in their Exchange environments.

These include hardening user authentication and access security, implementing strong network encryption, and minimizing application attack surfaces. 

This builds on CISA’s emergency directive 25-02, Mitigate Microsoft Exchange Vulnerability, which was published earlier this year.

The authoring agencies recommend that organizations that have transitioned to Microsoft 365 decommission end-of-life Exchange Servers, such as versions 2016 and 2019, as these versions are now at a “heightened risk of compromise”. 

The additional risk lies in the fact that Microsoft no longer provides bug fixes or security updates for these versions. Despite this, they’re often left to run unmonitored in an organization’s environment long after the business has migrated to another service, such as the latest on-premises version, Microsoft 365, or Exchange Online.

Attackers can then leverage security flaws within these unmonitored, unused versions as a means of compromising an organization’s network. 

“With the threat to Exchange servers remaining persistent, enforcing a prevention posture and adhering to these best practices is crucial for safeguarding our critical communication systems,” said Nick Andersen, Executive Assistant Director for the Cybersecurity Division at CISA.

“This guidance empowers organizations to proactively mitigate threats, protect enterprise assets, and ensure the resilience of their operations.”

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Caitlin Harris
Caitlin Harris Head Of Content

Caitlin Harris is the Head of Content at Expert Insights. As an experienced content writer and editor, Caitlin helps cybersecurity leaders to cut through the noise in the cybersecurity space with expert analysis and insightful recommendations.

Prior to Expert Insights, Caitlin worked at QA Ltd, where she produced award-winning technical training materials, and she has also produced journalistic content over the course of her career.

Caitlin has 8 years of experience in the cybersecurity and technology space, helping technical teams, CISOs, and security professionals find clarity on complex, mission critical topics like security awareness training, backup and recovery, and endpoint protection.

Caitlin also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Cyber Weekly.