 Initiative Number: 2.5.3 Initiative Title: Investigate ransomware crimes and disrupt the ransomware ecosystem Initiative Description The Department of Justice, leveraging mutual legal assistance channels and domestic legal process, forfeiture proceedings, and criminal charging authorities, will strengthen its capacity to work with Federal, international and private sector partners to plan, coordinate, and execute disruption operations against the ransomware ecosystem, including virtual asset providers that enable money-laundering proceeds and web fora offering initial access credentials or other material support for ransomware activities. NCS Reference Given ransomware’s impact on key critical infrastructure services, the United States will employ all elements of national power to counter the threat along four lines of effort: (1) leveraging international cooperation to disrupt the ransomware ecosystem . . .; (2) investigating ransomware crimes and using law enforcement and other authorities to disrupt ransomware infrastructure and actors; and… (4) addressing the abuse of virtual currency to launder ransomware proceeds. Responsible Agency: DOJ Completion Date: 2Q FY24 Initiative Number: 2.5.4 Initiative Title: Support private sector and state, local, Tribal, and territorial (SLTT) efforts to mitigate ransomware risk Initiative Description The Cybersecurity and Infrastructure Security Agency, in coordination with the JRTF (cochaired by CISA and FBI), SRMAs, and other stakeholders, will offer resources such as training, cybersecurity services, technical assessments, pre-attack planning, and incident response to critical infrastructure organizations, SLTT, and other high-risk targets of ransomware to reduce the likelihood of impact and the scale and duration of impacts when they occur. NCS Reference Given ransomware’s impact on key critical infrastructure services, the United States will employ all elements of national power to counter the threat along four lines of effort... (3) bolstering critical infrastructure resilience to withstand ransomware attacks… The Joint Ransomware Task Force (JRTF) will.... provide support to private sector and SLTT efforts to increase their protections against ransomware. Responsible Agency: CISA Contributing Entities: FBI, SRMAs, USSS, NSC Completion Date: 1Q FY25 NATIONAL CYBERSECURITY STRATEGY IMPLEMENTATION PLAN 27

Select target paragraph3