 • February 2024: DOJ announced an online operation to disrupt a botnet comprised of thousands of compromised SOHO routers operated by Russia’s military intelligence agency, the GRU. The GRU created this botnet by co-opting criminal hackers’ earlier compromise of SOHO routers with Moobot malware and turning them into a global intelligence collection platform, primarily in support of spearphishing and similar credential harvesting campaigns, including operations targeting Ukraine. This takedown was the third time since Russia’s invasion of Ukraine that the United States stripped the Russian intelligence services of a key tool used to further Russia’s acts of aggression and other malicious activities. Defending Federal Networks In response to significant cyber incidents targeting Federal networks and critical infrastructure, EO 14028 marked a paradigm shift in the Federal Government’s approach to cybersecurity by establishing baseline security measures across Federal systems. NSM-8 further transformed accountability for the cybersecurity of our nation’s most critical systems by clarifying responsibilities for securing NSS. In addition, the Administration crafted a cybersecurity modernization agenda to invest in systems that support collective defense and created the first strategy to adopt Zero Trust Architecture (ZTA) across the Federal civilian enterprise. In 2023, Chief Financial Officer (CFO) Act civilian agencies made progress implementing highimpact cybersecurity practices to improve their cybersecurity posture. These practices include progress on encrypting data both in transit and at rest, deployment of phishing-resistant multifactor authentication (MFA), deployment of end-point detection and response (EDR) services, logging capabilities, and hiring skilled cybersecurity teams. By the first quarter of fiscal year 2024, CFO Act civilian agencies demonstrated the following achievements as measured by quarterly Federal Information System Modernization Act metrics: • Encryption: Progress was reported in encryption of data both at rest and in transit, with multiple CFO Act civilian agencies showing increases of more than 10%. • MFA: There were improvements in the deployment of phishing-resistant MFA across the vast majority of agencies, with ten agencies demonstrating an increase of at least 20% phishing-resistant MFA deployment on agency systems. • EDR: The average percentage of endpoints covered by at least one EDR platform reached 92%. • Logging: Five agencies achieved “advanced” logging capabilities for all High Value Assets. The Office of Management and Budget (OMB) and CISA stood up a working group to drive more effective log collection, which supports incident response activities. • Skilled Cybersecurity Team Hiring: Agencies continued to strengthen skilled cybersecurity team hiring, achieving an average position fill rate of 91%. 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE 17

Select target paragraph3