 The Strategic Environment The strategic environment consists of an evolving ecosystem of people, technologies, and institutions, as well as the malicious actors who exploit vulnerabilities in this ecosystem to cause harm. The Office of the Director of National Intelligence’s 2024 Annual Threat Assessment of the U.S. Intelligence Community makes clear that both state and non-state actors continue to pursue cyber capabilities that threaten U.S. national interests in cyberspace and beyond. The PRC, in particular, remains the most active and persistent cyber threat to U.S. Government, private sector, and critical infrastructure networks. Nation-state actors from Russia, Iran, and the Democratic People’s Republic of Korea (DPRK), as well as transnational criminal organizations and other non-state actors, are responsible for a wide range of malicious activity that impacts the United States and our allies and partners. However, the cyber risk landscape is defined by more than these actors and their malicious activities. Threat is only one component of risk, and remedying vulnerabilities in cyberspace, enhancing our resilience, or otherwise mitigating the consequences of successful cyber incidents are more directly within our control. In analyzing the strategic environment, this report considers the combination of adversary capability and intent, the distribution and severity of vulnerabilities in our digital ecosystem, and the processes and policies we deploy to address these challenges. Below, we highlight both enduring cybersecurity challenges and the emergent trends that drove change in the strategic environment this year. Our strategic environment is characterized by growing complexity, interconnectivity, and competition, as critical and emerging technologies further accelerate the pace of change and require us to rapidly reimagine risks and opportunities in a digitally-enabled world. Advanced computing technologies, the convergence of digital and physical systems, and the presence of new actors across our critical infrastructure landscape make for a complex world where risks can be difficult to identify. Sprawling supply chains, widening access to communications networks, and interdependent global infrastructures have led to an increasingly interconnected world. Simultaneously, the strategic environment has become increasingly competitive, as both state and non-state actors pursue their interests using sophisticated cyber capabilities. Geopolitical conflict is increasingly playing out in cyberspace, amplifying risks to U.S. and allied critical infrastructure. Enduring Cybersecurity Challenges Cyber defenders face more adversaries than ever, as a growing number of state-affiliated, criminal, and ideologically-motivated actors launch cyber operations against the United States. These adversaries benefit from longstanding structural asymmetries, including the fact that attackers can begin exploiting vulnerabilities before defenders can develop and deploy patches, and network interdependencies that allow exploitation of victims at scale. Enduring use of insecure practices by the software development community, such as programming in memory unsafe languages, further advantages attackers. Additionally, challenges in attribution enable malicious actors to obfuscate their behavior to avoid consequences. 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE 3

Select target paragraph3