OB JEC TIVE 2.1 Understand how attacks really occur — and how to stop them Every organization has a finite cybersecurity budget, but the ways to expend such limited resources are nearly infinite. CISA must inform, guide, and drive adoption of the most impactful cybersecurity measures by first understanding how attacks occur — not just the initial access, but how the attacker exploited a web of unsafe technology products and inadequate security controls to achieve their objective. We will base this understanding on a variety of sources, including our own visibility into federal civilian executive branch systems, our partners’ visibility into critical infrastructure systems, insights from the research community, and incident reporting — voluntary today and supplemented by mandatory reporting under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) in future years. We will focus on understanding how the success achieved by attackers differs by sector or organizational profile, and whether such differences are caused by factors such as a lack of resources, information, or expertise that CISA and our partners can help rectify. This knowledge is a prerequisite for us to proactively drive pro-security decisions and inform and justify security decisions made by all levels of government and across the private sector. ENA BL ING MEA SURE We will develop a robust capacity to analyze information about cybersecurity intrusions and adversary adaptation, and derive insights into which security measures were, or could have been, most effective in limiting impact and harm. MEA SURE OF EFFEC TI V E N E SS Increase in the percentage of recommendations in CISA’s guidance and directives that are directly based upon specific data showing how adversaries successfully execute intrusions and the most effective mitigations to stop them. C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N 14

Select target paragraph3