In response to significant incidents and malicious cyber activity, Cybersecurity
Advisories (CSA) provide critical infrastructure owners and operators and other entities with
timely guidance to detect and respond to threats. Coordinating the development of these CSAs
across the Federal Government and with international allies and partners improves support to
victims. In May 2023, NSA, CISA, FBI, DOE, and international partners released a CSA
detailing the tactics, techniques, and procedures (TTPs) of the PRC-sponsored Volt Typhoon
actor, and later provided joint guidance for organizations to identify and mitigate these TTPs.
The Cyber Safety Review Board (CSRB) reviews and assesses significant cyber incidents and
makes recommendations for public and private sector organizations to prevent similar incidents
from taking place. In August 2023, the CSRB released its analysis of the Lapsus$ threat actor
group, highlighting the group’s exploitation of systemic ecosystem weaknesses to victimize
organizations across the country. This report led to subsequent, ongoing efforts by CISA and
DHS to ensure that necessary security features are provided to customers without additional cost.
The CSRB’s third report, released in April 2024, focuses on the malicious targeting of cloud
computing environments and makes recommendations for strengthening identity management
and authentication in the cloud. The structured analysis performed by the CSRB plays a crucial
role in identifying and sharing lessons learned from significant cyber incidents and developing
actionable mitigations.
CISA is committed to updating the National Cyber Incident Response Plan (NCIRP) by the end
of 2024. The NCIRP outlines our national approach to handling significant cyber incidents,
including defining key roles and responsibilities for Federal agencies, private sector entities, and
SLTT entities, in accordance with Presidential Policy Directive 41, United States Cyber Incident
Coordination. The cyber threat landscape and the cyber defense ecosystem have evolved
significantly since the NCIRP was originally published in 2016. The updated NCIRP will
provide a modern, agile, flexible framework to enable coordinated national incident response
across the Federal Government, private sector, and other key partners.
Disrupting and Degrading Adversary Activity
The United States remains postured to use all instruments of national power to defend our
interests in cyberspace and to disrupt and dismantle cyber threat actors. To counter ransomware
and other forms of cybercrime, the Administration is pursuing new measures to improve the
integrated use of diplomatic, information, military, financial, intelligence, and law enforcement
capabilities, and to engage non-Federal and international partners in these activities. Disruption
alone cannot defeat ransomware or other forms of malicious cyber activity, but it can have a
meaningful impact on the problem.
In September 2023, the DoD finalized its 2023 Department of Defense Cyber Strategy, which
highlights the use of cyberspace operations through its policy of defending forward to actively
disrupt malicious cyber activity before it can affect the United States and its interests. In March
2024, DoD released the Defense Industrial Base Cybersecurity Strategy to provide an actionable
framework for sustaining a more resilient Joint Force and defense ecosystem. In 2023, U.S.
Cyber Command’s Cyber National Mission Force deployed 22 times to 17 countries to conduct
2024 REPORT
14
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE