•
February 2024: DOJ announced an online operation to disrupt a botnet comprised of
thousands of compromised SOHO routers operated by Russia’s military intelligence
agency, the GRU. The GRU created this botnet by co-opting criminal hackers’ earlier
compromise of SOHO routers with Moobot malware and turning them into a global
intelligence collection platform, primarily in support of spearphishing and similar
credential harvesting campaigns, including operations targeting Ukraine. This takedown
was the third time since Russia’s invasion of Ukraine that the United States stripped the
Russian intelligence services of a key tool used to further Russia’s acts of aggression and
other malicious activities.
Defending Federal Networks
In response to significant cyber incidents targeting Federal networks and critical infrastructure,
EO 14028 marked a paradigm shift in the Federal Government’s approach to cybersecurity by
establishing baseline security measures across Federal systems. NSM-8 further transformed
accountability for the cybersecurity of our nation’s most critical systems by clarifying
responsibilities for securing NSS. In addition, the Administration crafted a cybersecurity
modernization agenda to invest in systems that support collective defense and created the first
strategy to adopt Zero Trust Architecture (ZTA) across the Federal civilian enterprise.
In 2023, Chief Financial Officer (CFO) Act civilian agencies made progress implementing highimpact cybersecurity practices to improve their cybersecurity posture. These practices include
progress on encrypting data both in transit and at rest, deployment of phishing-resistant multifactor authentication (MFA), deployment of end-point detection and response (EDR) services,
logging capabilities, and hiring skilled cybersecurity teams. By the first quarter of fiscal year
2024, CFO Act civilian agencies demonstrated the following achievements as measured by
quarterly Federal Information System Modernization Act metrics:
•
Encryption: Progress was reported in encryption of data both at rest and in transit, with
multiple CFO Act civilian agencies showing increases of more than 10%.
•
MFA: There were improvements in the deployment of phishing-resistant MFA across the
vast majority of agencies, with ten agencies demonstrating an increase of at least 20%
phishing-resistant MFA deployment on agency systems.
•
EDR: The average percentage of endpoints covered by at least one EDR platform
reached 92%.
•
Logging: Five agencies achieved “advanced” logging capabilities for all High Value
Assets. The Office of Management and Budget (OMB) and CISA stood up a working
group to drive more effective log collection, which supports incident response activities.
•
Skilled Cybersecurity Team Hiring: Agencies continued to strengthen skilled
cybersecurity team hiring, achieving an average position fill rate of 91%.
2024 REPORT
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE
17