 Five trends, in addition to enduring cybersecurity challenges, drove change in the strategic environment in 2023. 1. Evolving Risks to Critical Infrastructure: Nation-state adversaries demonstrated a growing willingness to use cyber capabilities to compromise and hold at risk critical infrastructure systems and assets with no inherent espionage value, in order to further their broader strategic objectives. 2. Ransomware: Ransomware remained a persistent threat to national security, public safety, and economic prosperity, and ransomware groups continued to develop sophisticated strategies to evade or circumvent defensive and disruptive measures designed to frustrate their activities. 3. Supply Chain Exploitation: Complex and interconnected supply chains for software and other information technology and services enabled malicious actors to compromise victims at scale. 4. Commercial Spyware: There was a growing market for sophisticated and invasive cyber-surveillance tools sold to nation-state actors by private vendors to access electronic devices remotely, monitor and extract their content, and manipulate their components without the knowledge or consent of the devices’ users. 5. Artificial Intelligence: Artificial intelligence (AI) is one of the most powerful, publicly accessible technologies of our time, and its continued evolution in 2023 presented opportunities and challenges for cyber risk management at scale. Current Efforts Addressing the challenges and seizing the opportunities presented by the strategic environment requires a coherent program of action led by the Federal Government and aligned with private sector efforts. The Office of the National Cyber Director (ONCD) coordinates the implementation of national cyber policy and strategy, including the NCS, by driving new actions and uplifting and connecting work underway. This report reflects important contributions to national cybersecurity made by departments and agencies across the Federal Government. The National Cybersecurity Strategy Implementation Plan (NCSIP), released in July 2023, guides Federal efforts to realize the vision of the NCS and is updated on an annual basis. In NCSIP Version 1, the Federal Government was responsible for completing 36 initiatives by the second quarter of 2024. As detailed in this report, 33 of these 36 (92%) initiatives were completed on time and three remain underway. An additional 33 NCSIP Version 1 initiatives have completion dates over the next two years and are on track. 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE iv

Select target paragraph3