 Utility Advances Cybersecurity Grant and Technical Assistance BIL Program to enhance the cybersecurity posture of electric cooperative, municipal, and small investor-owned utilities. This program helps these smaller utilities protect against, detect, respond to, and recover from cybersecurity threats, and increases their participation in cybersecurity threat information sharing programs. The ongoing clean energy transition presents opportunities to build in security and resilience across the foundations of our national infrastructure and clean energy supply chains. Through implementation of grant programs included in the BIL and IRA, DOE and other Federal partners are enabling grant recipients to procure and implement safer clean energy technologies. The BIL also requires that certain projects funded under the law include a cybersecurity plan to maintain or improve the project’s cybersecurity over its lifecycle. In July 2023, DOE funded eight innovative small businesses that are advancing cybersecurity for distributed energy resources (DERs) and in September announced $39 million of funding for nine new National Laboratory projects to advance the cybersecurity of DERs. Also in September 2023, the DOE Clean Energy Cybersecurity Accelerator graduated its inaugural cohort, focusing on enabling technologies that offer authentication and authorization solutions for industrial control systems. DOE further released an implementation guide for its National Cyber-Informed Engineering Strategy to assist organizations in building cybersecurity into the design of energy infrastructure. In January 2024, DOE also announced a $30 million funding opportunity to support research, development, and demonstration (RD&D) of next generation tools to protect clean energy delivery infrastructure from cyberattacks. The Federal Government is funding RD&D in cutting-edge cybersecurity and resilience technologies. The 2023 Federal Cybersecurity Research and Development Strategic Plan aligns to the NCS and provides Federal agencies with specific guidance on priorities for Federal funding, including human-centered cybersecurity, trustworthiness, cyber resilience, metrics, and RD&D infrastructure. The plan also aligns with an August 2023 joint OMB-OSTP memo outlining multi-agency research and development priorities for the fiscal year 2025 budget, including critical and emerging technology and innovation that can mitigate cybersecurity risk. Through its Secure and Trustworthy Cyberspace program, the NSF is funding research projects focusing on critical infrastructure security and resilience. The Administration is coordinating public and private actions to secure longstanding vulnerabilities in the underlying technical foundations of the Internet. Making the BGP more secure can significantly reduce harm resulting from unsecured Internet routing. In July 2023, the FCC and CISA convened Federal partners, nonprofits, and industry partners, including Internet service providers and cloud content providers, to develop a common understanding of the latest BGP security improvements and coordinate efforts to accelerate them. In October 2023, the President signed EO 14110 on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence to direct whole-of-government efforts to shape the values-aligned development of AI. EO 14110 addresses the various ways by which AI may impact the cybersecurity community. First, to explore ways to use AI to enable more efficient cyber defense activities, EO 14110 establishes an advanced cybersecurity program to develop AI 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE 23

Select target paragraph3