 The National Space Council, the National Security Council Cybersecurity Directorate, and ONCD are also coordinating public and private efforts to address unique challenges related to space system cybersecurity. In 2023, ONCD convened a series of regional technical workshops with government and industry space experts to discuss cybersecurity challenges and opportunities. In July, NIST released an updated report on cyber risk management practices related to commercial satellite operations. In October, the National Aeronautics and Space Administration (NASA) issued a best practices guide to address new challenges by increasingly integrated and interconnected space systems. State, local, Tribal and territorial (SLTT) governments are working to elevate their cybersecurity posture. The Bipartisan Infrastructure Law provides $1 billion in funding to boost SLTT capacity to address cybersecurity risks to information systems they own or operate. In 2023, CISA and the Federal Emergency Management Agency made available $375 million through the State and Local Cybersecurity Grant Program and $18 million through the Tribal Cybersecurity Grant Program. The Small Business Administration (SBA) also provides grant funding through the SBA Cybersecurity for Small Business Pilot Program. Federal agencies will continue to partner with SLTT entities and small businesses to share cybersecurity best practices, support cyber response and recovery, and accelerate cybersecurity research and development. Improving Incident Preparedness and Response The Federal Government continues to prioritize providing support to victims of cyber incidents. The Department of Justice (DOJ), FBI, CISA, U.S. Secret Service, and other Federal entities invest significant resources in helping victims after cyber incidents, including investigating cybercriminals to seek justice and prevent crime; employing a global network of cyber threat experts contributing to attribution and analysis; sharing cyber threat information to inform victim response actions; introducing targeted entities to decryption capabilities or other known mitigation tools; and assisting in freezing, seizing, and returning stolen and extorted funds. The FBI’s Internet Crime Complaint Center Recovery Asset Team streamlines communications with financial institutions and FBI field offices to assist with freezing, seizing, and returning funds for victims and had a 71% success rate in 2023. The FBI-led Cryptocurrency Threat Center has worked with law enforcement and intelligence community partners to increase the U.S. Government’s capability to publicly identify stolen cryptocurrency, including virtual assets stolen by DPRK-linked actors. The FBI’s Cyber Action Team and a growing number of Model Cyber Squads being developed across all 56 FBI field offices provide a rapid-response capability that can be deployed within hours to provide investigative support in response to a major incident. CISA Hunt and Incident Response teams support organizations responding to cybersecurity incidents, including by identifying and detecting cyber threats to U.S. critical infrastructure. In 2023, CISA regularly engaged with SRMAs to enhance collaboration with and support to critical infrastructure owners and operators. In addition, the Bipartisan Infrastructure Law established a $100 million Cyber Response and Recovery Fund that CISA can use to support Federal, SLTT, public, and private sector entities in the event of a significant cyber incident. 2024 REPORT ON THE CYBERSECURITY OF THE UNITED STATES POSTURE 13

Select target paragraph3