Within a very short time, there were several different IP addresses from Russia trying to guess the passwords for root and several other common accounts.
Not too long after, Chinese IP addresses joined the party.
Note that this was before I had finished migrating my domain to the new server (the Russians showed up before I even started the migration). None of my DNS entries pointed to the new server yet. They probably are scanning all Rackspace IP addresses looking for new servers. I would expect that the same happens at other major server providers.
I don't know if CISA is the right approach or not, but we need to do something to defend against this stuff.
If CISA is not the right approach, the opponents need to start suggesting an alternative that addresses the problem better, because otherwise the pressure is going to mount to pass something, and if CISA is the only proposal available that will be the one that passes.