Five trends, in addition to enduring cybersecurity challenges, drove change in the strategic
environment in 2023.
1. Evolving Risks to Critical Infrastructure: Nation-state adversaries demonstrated a
growing willingness to use cyber capabilities to compromise and hold at risk critical
infrastructure systems and assets with no inherent espionage value, in order to further
their broader strategic objectives.
2. Ransomware: Ransomware remained a persistent threat to national security, public
safety, and economic prosperity, and ransomware groups continued to develop
sophisticated strategies to evade or circumvent defensive and disruptive measures
designed to frustrate their activities.
3. Supply Chain Exploitation: Complex and interconnected supply chains for software and
other information technology and services enabled malicious actors to compromise
victims at scale.
4. Commercial Spyware: There was a growing market for sophisticated and invasive
cyber-surveillance tools sold to nation-state actors by private vendors to access electronic
devices remotely, monitor and extract their content, and manipulate their components
without the knowledge or consent of the devices’ users.
5. Artificial Intelligence: Artificial intelligence (AI) is one of the most powerful, publicly
accessible technologies of our time, and its continued evolution in 2023 presented
opportunities and challenges for cyber risk management at scale.
Current Efforts
Addressing the challenges and seizing the opportunities presented by the strategic environment
requires a coherent program of action led by the Federal Government and aligned with private
sector efforts. The Office of the National Cyber Director (ONCD) coordinates the
implementation of national cyber policy and strategy, including the NCS, by driving new actions
and uplifting and connecting work underway. This report reflects important contributions to
national cybersecurity made by departments and agencies across the Federal Government.
The National Cybersecurity Strategy Implementation Plan (NCSIP), released in July 2023,
guides Federal efforts to realize the vision of the NCS and is updated on an annual basis. In
NCSIP Version 1, the Federal Government was responsible for completing 36 initiatives by the
second quarter of 2024. As detailed in this report, 33 of these 36 (92%) initiatives were
completed on time and three remain underway. An additional 33 NCSIP Version 1 initiatives
have completion dates over the next two years and are on track.
2024 REPORT
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE
iv