 Legacy protocols and technical architectures with poor security attributes are deeply embedded across the digital ecosystem, from legacy mobile networks to how we route data across the Internet. The Border Gateway Protocol (BGP), which directs Internet traffic, is susceptible to traffic hijacking and route manipulation. Attackers can also leverage weaknesses in outdated encryption protocols to compromise communications. Emerging digital technologies often present adversaries with new opportunities for malicious exploitation. The development of a viable large-scale quantum computer, for example, promises tremendous economic benefits, potentially creating entirely new industries and revolutionizing our digital ecosystem. However, we have known for decades that quantum computing has the potential to break many widely used cryptographic systems that keep our information safe. In the wrong hands, a sufficiently mature quantum computer would challenge the integrity of the digital ecosystem, threaten sensitive health and personal financial data, and defeat security protocols for most Internet-based financial transactions. Critical infrastructure owners and operators rely on third-party service providers to manage key aspects of their digital operations. The adoption of cloud services, for example, can enable better and more economical cybersecurity outcomes at scale, but cloud migration may also present novel cybersecurity risks. Hybrid deployments, in which organizations use both locally hosted systems and cloud assets, can introduce complex centralized logging and authentication regimes, creating opportunities for malicious actors to evade detection and abuse identity management systems. The 2023 PRC compromise of U.S. government communications demonstrates the necessity of maintaining comprehensive logging. More broadly, as organizations migrate increasing amounts of data and processes to the cloud, this shift introduces new cross-sector dependencies and complicates systemic risk identification and management, particularly where multiple organizations rely on third-party services from the same provider. Our critical infrastructure landscape is characterized by private ownership and operation, which results in interdependencies between public and private sectors and which requires a national cybersecurity posture rooted in public-private action, collaboration, and partnership. The rapidly expanding space industry illustrates how advances in technology create new challenges and opportunities for collaboration to manage shared cyber risk. A growing number of critical infrastructure assets rely upon space-based systems for communications, sensing, navigation, and timing. In the days leading up to Russia’s 2022 invasion of Ukraine, a cyberattack against a U.S. space communications company, ostensibly intended to disrupt Ukrainian telecommunications, also led to outages for computer systems used by thousands of European wind turbines. As the space ecosystem continues to evolve and integrate new commercial participants, the cybersecurity of space systems will be a shared responsibility. America’s cyber workforce continues to grapple with a persistent need for more trained cybersecurity professionals and a better cyber education ecosystem. Getting more Americans involved in the cyber workforce not only strengthens our national cybersecurity outcomes, it also provides access to good-paying, middle-class jobs. We must develop cyber talent through formal and informal cyber education and training systems as a matter of economic development and national security. While U.S. schools, governments, non-profits, and companies have made 2024 REPORT 4 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3