medium-sized utilities. CISA established the Ransomware Vulnerability Warning Pilot (RVMP)
program as authorized by CIRCIA to identify commonly exploited vulnerabilities related to
ransomware activity, and warn critical infrastructure entities so that they can mitigate the risk. In
2023, this program notified critical infrastructure owners and operators of 1,754 vulnerable
devices. And, in November 2023, CISA launched a voluntary pilot program to provide
organizations in the healthcare, water and wastewater, and education sectors with cybersecurity
shared services.
SRMAs further enable the Federal Government to support and engage with critical infrastructure
owners and operators at scale. In 2023, the Department of Health and Human Services (HHS)
released a new strategy for healthcare cybersecurity; updated its Health Industry Cybersecurity
Practices Guide in collaboration with the Health Sector Coordinating Council; launched the Risk
Identification and Site Criticality Tool version 2.0; and partnered with CISA to develop sectorspecific CPGs. The Environmental Protection Agency (EPA) released a new cybersecurity risk
assessment resource for water and wastewater systems and, in partnership with CISA and the
Federal Bureau of Investigation (FBI), developed an incident response guide for the sector. The
Treasury Department established the Cloud Executive Steering Group to enhance cooperation
between regulators and financial services organizations to address benefits and challenges
associated with cloud adoption. DOE, through the Cyber Testing for Resilient Industrial Control
Systems (CyTRICS) program, has established new partnerships with key private sector
organizations to strengthen the cybersecurity of priority energy system component software,
hardware, and firmware.
The Federal Government is focused on supplementing SRMAs’ traditional strengths in
information sharing and stakeholder engagement with more robust capabilities for operational
collaboration with the private sector, including planning, exercises, and incident response. The
National Security Agency (NSA) collaborates with private sector partners to defend National
Security Systems (NSS), U.S. military assets, and the DIB against cyber threats. The NSA’s
Cybersecurity Collaboration Center (CCC) provides a scalable, intelligence-driven mechanism
for public-private collaboration with the DIB and their service providers, totaling over 750
partnerships in 2023 and further enabling collaborative defense against malicious cyber activity
that threatens other critical infrastructure sectors. The CCC continues to expand its cybersecurity
support to the DIB, including through providing Protective Domain Name System, Attack
Surface Management, and threat intelligence collaboration services.
In response to cyberattacks affecting U.S. school systems, the White House convened a forum to
coordinate public and private measures to strengthen the cybersecurity of K-12 schools. The
Department of Education established a Government Coordinating Council (GCC) to enhance
communication among education subsector stakeholders and improve cybersecurity resilience
efforts. The FBI continues to engage with school districts across the country through its 56 field
offices to enable on-the-ground cyber threat response services. CISA is providing additional
resources to support the education subsector, including developing subsector-specific guidance
in partnership with the Department of Education and providing tailored assessments, exercise
support, and training to K-12 stakeholders.
2024 REPORT
12
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE