The directive targets firewalls, routers, and VPNs that are no longer receiving vendor patches, as nation-state actors shift their tactics from endpoints to infrastructure.
Most security incidents happen in the gap between knowing what matters and actually implementing security controls ...