Legacy protocols and technical architectures with poor security attributes are deeply
embedded across the digital ecosystem, from legacy mobile networks to how we route data
across the Internet. The Border Gateway Protocol (BGP), which directs Internet traffic, is
susceptible to traffic hijacking and route manipulation. Attackers can also leverage weaknesses
in outdated encryption protocols to compromise communications.
Emerging digital technologies often present adversaries with new opportunities for malicious
exploitation. The development of a viable large-scale quantum computer, for example, promises
tremendous economic benefits, potentially creating entirely new industries and revolutionizing
our digital ecosystem. However, we have known for decades that quantum computing has the
potential to break many widely used cryptographic systems that keep our information safe. In
the wrong hands, a sufficiently mature quantum computer would challenge the integrity of the
digital ecosystem, threaten sensitive health and personal financial data, and defeat security
protocols for most Internet-based financial transactions.
Critical infrastructure owners and operators rely on third-party service providers to manage
key aspects of their digital operations. The adoption of cloud services, for example, can enable
better and more economical cybersecurity outcomes at scale, but cloud migration may also
present novel cybersecurity risks. Hybrid deployments, in which organizations use both locally
hosted systems and cloud assets, can introduce complex centralized logging and authentication
regimes, creating opportunities for malicious actors to evade detection and abuse identity
management systems. The 2023 PRC compromise of U.S. government communications
demonstrates the necessity of maintaining comprehensive logging. More broadly, as
organizations migrate increasing amounts of data and processes to the cloud, this shift introduces
new cross-sector dependencies and complicates systemic risk identification and management,
particularly where multiple organizations rely on third-party services from the same provider.
Our critical infrastructure landscape is characterized by private ownership and operation,
which results in interdependencies between public and private sectors and which requires a
national cybersecurity posture rooted in public-private action, collaboration, and partnership.
The rapidly expanding space industry illustrates how advances in technology create new
challenges and opportunities for collaboration to manage shared cyber risk. A growing number
of critical infrastructure assets rely upon space-based systems for communications, sensing,
navigation, and timing. In the days leading up to Russia’s 2022 invasion of Ukraine, a
cyberattack against a U.S. space communications company, ostensibly intended to disrupt
Ukrainian telecommunications, also led to outages for computer systems used by thousands of
European wind turbines. As the space ecosystem continues to evolve and integrate new
commercial participants, the cybersecurity of space systems will be a shared responsibility.
America’s cyber workforce continues to grapple with a persistent need for more trained
cybersecurity professionals and a better cyber education ecosystem. Getting more Americans
involved in the cyber workforce not only strengthens our national cybersecurity outcomes, it also
provides access to good-paying, middle-class jobs. We must develop cyber talent through
formal and informal cyber education and training systems as a matter of economic development
and national security. While U.S. schools, governments, non-profits, and companies have made
2024 REPORT
4
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE