OB JEC TIVE 2.1
Understand how attacks really occur — and how to
stop them
Every organization has a finite cybersecurity budget, but the ways to expend such limited
resources are nearly infinite. CISA must inform, guide, and drive adoption of the most
impactful cybersecurity measures by first understanding how attacks occur — not just the initial
access, but how the attacker exploited a web of unsafe technology products and inadequate
security controls to achieve their objective. We will base this understanding on a variety
of sources, including our own visibility into federal civilian executive branch systems, our
partners’ visibility into critical infrastructure systems, insights from the research community,
and incident reporting — voluntary today and supplemented by mandatory reporting under
the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) in future years.
We will focus on understanding how the success achieved by attackers differs by sector or
organizational profile, and whether such differences are caused by factors such as a lack
of resources, information, or expertise that CISA and our partners can help rectify. This
knowledge is a prerequisite for us to proactively drive pro-security decisions and inform and
justify security decisions made by all levels of government and across the private sector.
ENA BL ING MEA SURE
We will develop a robust capacity to analyze information about cybersecurity intrusions and
adversary adaptation, and derive insights into which security measures were, or could have
been, most effective in limiting impact and harm.
MEA SURE OF EFFEC TI V E N E SS
Increase in the percentage of recommendations in CISA’s guidance and directives
that are directly based upon specific data showing how adversaries successfully
execute intrusions and the most effective mitigations to stop them.
C I S A C Y B ER S EC U RI T Y ST R AT EG I C PL A N
14