 Future Outlook The 2024 Report on the Cybersecurity Posture of the United States highlights the breadth and depth of cybersecurity initiatives taking place across the Federal Government to realize the NCS’s vision of a digital ecosystem that is defensible, resilient, and aligned with our values. While the strategic environment will continue to evolve, presenting new technological and governance challenges as well as opportunities, many of the current programs will continue to endure over the coming years. Each step taken toward the Administration’s affirmative vision will strengthen our cybersecurity posture and build economic prosperity for communities across the country. Along with continued implementation of the Federal Government’s current efforts, there are several efforts that will require a specific focus in the coming year. Each of these have resources aligned to them in the fiscal year 2025 President’s Budget request. • Federal agencies with designated responsibilities as an SRMA must continue to enhance their efforts, consistent with U.S. critical infrastructure security and resilience policy and the Homeland Security Act, to enable operational collaboration within their sectors and provide specialized expertise to critical infrastructure owners and operators. • Departments and agencies will continue to implement the NCWES at scale through a diverse array of programs and authorities to strengthen the national cyber workforce, improve cyber education, and address unique challenges facing the Federal cyber workforce. • Implementation of CIRCIA will establish new requirements for covered entities across all critical infrastructure sectors to report certain cybersecurity incidents to the Federal Government. The information contained in these reports will provide new visibility into malicious cyber activity and ransomware, improve our understanding of cross-sectoral risks, and strengthen our collective defense. CISA and other departments and agencies with CIRCIA responsibilities are preparing to receive, process, share, and respond to these new incident reports. • In 2023, DOJ established a new National Security Cyber Section to increase the Department’s capacity to disrupt and respond to malicious cyber activity. The Section will promote Department-wide, intragovernmental, foreign, and private sector partnerships to tackle increasingly sophisticated and aggressive cyber threats by nationstate adversaries and their proxies. • To create a common operating landscape for cybersecurity, CISA is developing a new Cyber Analytics and Data System. This infrastructure will be used to integrate cybersecurity data sets; provide internal tools and capabilities to facilitate the ingestion and integration of data; and orchestrate and automate the analysis of data to support the rapid identification, detection, mitigation, and prevention of malicious cyber activity. 2024 REPORT 28 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3